Independent desk · email tools, deliverability, newsletters 22 September 2026
Permissions & Deliverability · 14 August 2026

Gmail Blue Checkmarks: Why Are Major Brands Letting Them Expire?

Gmail Blue Checkmarks: Why Are Major Brands Letting Them Expire?

Here’s something I wasn’t expecting to find when we started digging through Email Detective’s authentication data: a surprising number of well-known brands have let the certificates behind their Gmail blue checkmarks expire.

We’re talking about companies like Wells Fargo, Booking.com, Capital One, T-Mobile and Adidas.

For me, the case of banks and financial companies is particularly perplexing. These are exactly the kinds of brands whose customers are routinely targeted by phishing emails. You’d imagine that anything helping recipients distinguish a genuine email from a fake one would be worth holding onto.

So what’s going on?

Are companies simply forgetting to renew them? Are certificate renewals getting lost somewhere between the email, IT, security and procurement teams?

Or is there another possibility: some brands tried the Gmail blue checkmark, but decided it wasn’t actually valuable enough to keep paying for?

That’s the question our data got me thinking about.

First, where does the blue checkmark come from?

How the blue verified checkmark is displayed next to sender names in Gmail

If you’ve ever seen a company logo accompanied by a blue checkmark in Gmail, there’s quite a bit happening behind the scenes.

It starts with BIMI, or Brand Indicators for Message Identification.

BIMI allows brands to display their logo alongside their authenticated emails (in supported email clients like Gmail, Yahoo Mail and Apple Mail). Before you can use it, though, you need your email authentication in good shape, particularly DMARC with an enforced policy.

Then there are Mark Certificates.

A Verified Mark Certificate (VMC) verifies a qualifying registered trademark. One of its most visible benefits is that it can give the sender a blue verified checkmark in Gmail.

There’s also the newer Common Mark Certificate (CMC), which makes BIMI available to more companies because the logo doesn’t necessarily have to be a registered trademark. However, CMCs don’t currently provide Gmail’s blue checkmark.

And these certificates aren’t free. DigiCert, which is by far the biggest certificate provider in our dataset, currently charges $1,416 for a 12-month Mark Certificate subscription.

So we’re not talking about a setting somebody turns on once and forgets about forever. There’s a cost, there’s some administration involved and, sooner or later, somebody has to make the decision to renew it.

Apparently, quite a few companies don’t.

14% of the certificates we found have expired

Email Detective (our Chrome extension which identifies the email platform and authentication setup behind the emails in users’ inboxes) has now analysed BIMI certificates belonging to over 1,200 brands.

Of those, 175 (14%) are currently expired.

DigiCert dominates the certificates we’ve found. Of the certificates where we could identify the issuer, around 90% came from DigiCert. And we found 110 expired DigiCert certificates.

Some of the brands on the list surprised me. Booking.com’s certificate expired in July 2026. Wells Fargo’s expired later that same month. T-Mobile’s had expired a few weeks earlier.

There are also expired certificates belonging to Capital One, Adidas, Dashlane, Brex, Paytm, Trading 212, OpenTable and REI, among others.

Now, I want to be careful here. An expired certificate doesn’t necessarily mean somebody at Wells Fargo forgot to click the renew button. In fact, there could be plenty of other explanations.

The company might be changing its BIMI setup. It could be moving to another provider. There might be an internal delay. The certificate we’ve detected might relate to a particular domain or sending setup rather than every email the company sends.

So I wouldn’t look at this data and declare that all these companies have abandoned BIMI. But I do think it raises a fair question:

If the blue checkmark is genuinely valuable to brands, why are so many certificates being allowed to lapse at all?

The banking examples are particularly interesting

I keep coming back to the financial brands because they feel like the strongest use case for this technology.

Most of us have received a fake bank email at some point, which is exactly one of the arguments behind the importance of VMCs. A verified logo gives the recipient another visual signal that the message really came from the organization it claims to come from.

Of course, the blue checkmark isn’t what actually stops someone from spoofing the bank’s domain. SPF, DKIM and especially DMARC are much more important for that.

So if a bank’s VMC expires, it doesn’t suddenly mean its emails are unauthenticated or that anyone can impersonate its domain.

Still, if there’s one industry where I’d expect that additional trust signal to be considered worthwhile, banking would be pretty high up the list. Which makes seeing Wells Fargo and Capital One among the expired certificates particularly interesting.

Then there’s the Entrust story

This is where things get even more interesting.

Entrust used to issue Verified Mark Certificates, but it sold its public certificate business to Sectigo and stopped issuing new VMCs in May 2025.

Existing certificates continued working until they expired, but customers who wanted to continue using a VMC eventually needed to migrate.

Entrust customers suddenly had some additional friction. Rather than renewing a certificate, they actively had to move.

In our data, all 65 Entrust VMCs we identified have now expired – which in itself isn’t surprising, as Entrust obviously stopped issuing them.

What I find much more interesting is that we’re still seeing brands publishing expired Entrust certificates. Among them are names such as Binance, Hyatt, OKX, Monday.com, Just Eat, Deezer and JustGiving.

Some of the brands we’ve identified with expired Entrust certificates

That gives us something close to a natural experiment: When brands were forced to take action to keep their VMC, how many actually bothered?

I wouldn’t claim that every company still showing an expired Entrust certificate made a conscious decision to abandon its VMC. We simply don’t have enough information to say that.

But I’d love to know the answer. Because it gets to the bigger issue here: How much value do companies really place on that blue checkmark?

Maybe measuring the value is the real problem

I can see the appeal of VMCs. Your logo stands out in the inbox. Your brand looks more professional. Recipients get another indication that the email is genuinely yours.

And for heavily impersonated brands (such as banks, crypto companies, ecommerce businesses, and travel companies), that extra trust signal sounds useful.

But if I were the person signing off the renewal invoice, I’d probably have another question:

What exactly did we get for our $1,400 last year?

That might be much harder to answer, and I’d need some hard data to help me do so:

  • Did more people open our emails because of the logo?
  • Did more people click?
  • Were customers less likely to fall for phishing emails?
  • Did recipients trust us more?
  • Would any of those things have happened anyway because we already had BIMI without the blue checkmark?

There is some evidence that verified logos work. A 2025 DigiCert-commissioned study of 5,000 consumers found that 57% felt more confident an email was legitimate when the brand’s official logo appeared, while 64% said they would be more likely to click or act on it. Earlier research from Red Sift and Entrust also found significant improvements in opens, brand recall and purchase intent when logos were displayed.

But here’s the catch: most of this research measures the effect of showing a logo, rather than the incremental value of the blue checkmark itself. And brands can now use the much cheaper Common Mark Certificate to display their logo in Gmail (without the blue checkmark).

So how much extra trust or engagement does the checkmark actually buy you? I haven’t found good research that answers that yet.

Businesses have a lot of things competing for their security and marketing budgets. So perhaps the real challenge for VMCs isn’t getting companies to try them. It’s convincing those companies to renew them a year later.

(Who knows – maybe Elon Musk’s “buyable” blue checkmarks on Twitter gave them a bad rep everywhere else!)

Is the renewal process too difficult?

There’s another possibility worth exploring. One user told me their recertification took seven months, largely due to communication and validation issues. Validation normally takes between 1-2 weeks, so that’s clearly an extreme case.

But it highlights another potential drawback of VMCs: certificates expire roughly every year, while renewal still involves organization, trademark and identity validation. If that process gets held up (e.g. due to changes to company information, trademarks or logos), even a brand that fully intends to keep its blue checkmark can temporarily lose it.

So perhaps some of these brands haven’t decided to abandon their VMC at all. Maybe the process just requires too much human validation every year, especially at larger companies, where responsibility can be spread across marketing, IT, security, legal and procurement.

I’d love to hear from brands that have actually used one

Our data can tell us which certificates exist and which ones have expired, but it can’t tell us what happened in the meeting where someone decided whether to renew one.

That’s the part I’d really like to understand.

If your company has implemented a VMC, have you been able to measure any benefit from it?

And perhaps the more revealing question: If your certificate expired tomorrow, would you pay to renew it?

If the answer is yes, I’d love to know what made it worthwhile.

If the answer is no, I’d be even more interested to hear why. Let me know (either way!) in the comments below.

We’ll be releasing plenty more findings like this

We discovered this while working through a much larger dataset for our upcoming annual EmailTooltester report.

Email Detective now tracks email authentication across thousands of brands, including SPF, DKIM, DMARC, BIMI, Mark Certificates and other indicators of how companies are setting up their email infrastructure.

And one of the things I like most about having this data is that occasionally it throws up questions we weren’t actually looking for.

We’ll be sharing plenty more findings from the dataset in our upcoming annual report. To be notified when it gets released, make sure you’re signed up to our newsletter.