Can One VMC Cover Multiple Domains and Subdomains?
One VMC covers one logo, but it can protect several domains and subdomains. Here is how coverage works, and when you genuinely need a second certificate.
One VMC covers one logo, and that single certificate can cover multiple domains and subdomains. What forces a second certificate is a second logo, not a second domain.
That distinction is the thing to hold on to. Brands often assume certificate cost scales with the number of domains they send from, and budget accordingly. Usually it does not.
The rule in one line
A VMC is issued against a trademarked logo, and it lists the domains it is valid for. So:
- Five domains, one logo: one certificate.
- One domain, two distinct brand logos: two certificates.
- A parent brand and a sub-brand with its own registered mark: two certificates.
The certificate is anchored to the mark. Domains are attributes of it.
Subdomains
Subdomains are the most common case, and the most common source of confusion, because two separate mechanisms are at work.
The first is DNS. BIMI records are published per hostname with a selector, so news.yourdomain.com looks for its BIMI record at default._bimi.news.yourdomain.com. A record on the organizational domain does not automatically apply to a subdomain. Each sending subdomain that should display a logo needs its own record, and each of those records can point at the same logo and the same certificate.
The second is DMARC. Subdomains inherit the parent DMARC policy unless an sp= tag says otherwise. If your organizational domain is at p=reject but carries sp=none, your subdomains are not at enforcement, and a logo will not display on their mail no matter how correct the BIMI record is. This is the failure we find most often on multi-subdomain setups, and it is covered further in why DMARC enforcement is mandatory.
So the work per subdomain is small, but it is not zero, and skipping it is why one stream shows a logo while another does not.
Separate domains under one brand
Plenty of brands send from more than one registrable domain. A .com for the main business, a .co.uk or .de for a regional operation, a dedicated domain for transactional mail, an older domain kept for continuity after a rename.
If all of them send mail under the same trademarked logo, one certificate can cover them. Each domain still needs its own complete setup underneath: its own SPF and DKIM, its own DMARC record at enforcement, and its own BIMI record. The certificate is shared. The authentication work is per domain, because each domain is independently spoofable and has to be independently protected.
Worth being realistic about effort here. The certificate is one line item. Bringing four domains to DMARC enforcement is four discovery exercises, and that is where the actual time goes.
When you genuinely need more than one
Four situations, in our experience.
Different logos. A group operating two visually distinct brands needs a certificate for each, and each logo needs its own registered trademark. This is the main driver.
Regional logo variants. If a market uses a modified version of the mark, that variant is a different logo. It needs its own registration and its own certificate. Brands with localized lockups sometimes discover this late.
Different legal entities. The certificate is issued to the organization that holds the trademark. If two entities in a group each hold their own marks and send their own mail, that is two certificates, because the applicant differs.
A sub-brand with its own mark. Same logic. A separately trademarked sub-brand is a separate certificate, even though it sits inside the same company.
The logo has to match, every time
Whatever the domain arrangement, the logo displayed has to match the registered trademark exactly. Adding domains to a certificate does not relax that.
This is where multi-brand groups run into trouble. A shared certificate is tempting, and then one business unit wants its own variation of the mark on its own mail. That variation needs its own registration and its own certificate. There is no mechanism for approximate matching. We go into the trademark side in is a registered trademark required.
Planning it sensibly
If you send from several domains, decide two things before starting.
First, which domains actually need a logo. Not every domain does. A domain used only for internal systems or for receiving mail does not need a certificate entry, and including it just adds authentication work you do not need. Meanwhile, domains you own but never send from should still get a restrictive DMARC policy, which is a separate exercise from BIMI and a good idea regardless.
Second, whether your brand architecture is one logo or several. This decides certificate count, trademark work and cost, and it is a brand question rather than a technical one. It is worth resolving before anyone requests a quote.
How we scope it
Signume scopes this at the start, because getting it wrong is expensive in both directions. Buying separate certificates for domains that could share one wastes budget every year at renewal. Assuming one certificate covers a second brand's logo wastes months.
We map which domains and subdomains send mail, which logo each of them uses, which legal entity holds each mark, and what each domain's DMARC position is today. From that we tell you how many certificates you actually need and what the per-domain work looks like, for EU and UK brands, before you commit to anything.
Renewals matter here too. A VMC runs for roughly 397 days, and when it lapses every domain on it loses its logo at once. Consolidating onto fewer certificates makes that easier to manage, which is another reason to get the structure right early.
Frequently asked questions
Can one VMC cover multiple domains? Yes. A single VMC covers one logo and can list multiple domains. Each domain still needs its own SPF, DKIM, DMARC at enforcement and its own BIMI record.
Does a VMC automatically cover my subdomains?
No. Each sending subdomain needs its own BIMI record, and it must be at DMARC enforcement, which means checking that an sp= tag on the parent domain is not set to none.
When do I need a second VMC? When you have a second logo. Different brands, regional logo variants, separately trademarked sub-brands and different legal entities holding the marks all require their own certificate.
Do I need a separate trademark for each logo? Yes. Every logo covered by a VMC must be a registered trademark in its own right, and the file submitted has to match the registered mark exactly.
What happens at renewal across multiple domains? A VMC lasts about 397 days. If it expires, every domain covered by that certificate loses its logo at the same time, so renewal should be tracked centrally rather than per domain.
Related guides
BIMI vs VMC: What Is the Difference?
BIMI is the standard that tells inboxes where to find your logo. A VMC is the certificate that proves the logo is yours. Here is how the two fit together.
What Is a VMC (Verified Mark Certificate) and How Do You Get One?
A Verified Mark Certificate puts your trademarked logo, and Gmail's blue checkmark, in the inbox. Here's what a VMC is, what it requires, and how to get one.
BIMI, VMC & CMC: Which Email Providers Show Your Logo (and the Checkmark)?
Not every inbox treats BIMI the same. Here's which providers show your brand logo, which add Gmail's blue checkmark, and which show nothing at all in 2026.