Why did Gmail decide to have a verification badge?
Since 2021, Gmail has used a verification system called BIMI (Brand Indicators for Message Identification).
BIMI works as an email standard in which it is possible to add a brand logo to submissions from that domain. Thus, whoever receives the message knows that the sender is genuine.
According to Google, the main advantages of using BIMI are:
- authentication of sent messages, which prevents hackers from taking action on the domain;
- brand recognition, with the company’s logo present in each message;
- credibility, because recipients are sure that the email is legitimate.
Therefore, the new blue verification badge adds another layer of protection to the Gmail user, now with a visual proof that the sender is trustworthy.
Even with these improvements, some folks can’t help but feel skeptical. After all, every time a new badge or seal gets introduced, scammers usually aren’t too far behind, figuring out creative ways to fake legitimacy. Email phishing has gotten more sophisticated over the years; it’s not always the obvious misspelled words and clunky designs anymore. In 2025, security researchers from Proofpoint highlighted how attackers impersonated brands by taking advantage of weak DMARC settings—getting pretty close to the “real thing,” at least on the surface. So, yeah, maybe this badge helps, but it’s not a magic shield.
And, there’s also that tricky human factor. You can layer all the best tech solutions on top, but it takes only a distracted click or a hasty response to let something bad slip through. There’s a sense that putting so much focus on a little blue checkmark could give people a false sense of invulnerability—like assuming nothing shady can ever sneak in again. History says otherwise. Basically, the badge is a decent nudge in the right direction, but it shouldn’t replace a healthy dose of caution when opening emails.
How to get the Gmail Verification Badge?

To have the blue checkmark, the user administrator must have an account configured according to BIMI, adding the brand logo to authenticated emails.
Sounds simple, but this process involves setting up email protocol records for the domain and other security steps. This gives the account the VMC (Verified Mark Certificate).
Is Gmail’s Verification Checkmark Really Trustworthy?
So far you have understood that it is not just any Gmail account that can have the blue checkmark. Security authentication, trademark registration, and admin access to the account are required.
The question is whether the checkmark will really bring confidence to users, since other giants besides Twitter have adopted the “paid verified” model: Meta, for example, also fixed a payment to acquire the blue seal.
The verified profile was created by Twitter in 2009 with the aim of providing an easy and quick way to identify whether a profile is genuine or not. It’s a way to prevent imposter accounts from impersonating other people on the social network. Later, other networks adopted verification, such as Instagram, Pinterest and Youtube.
Although each social network or platform has its own criteria for account verification, the blue checkmark is in the imagination of internet users a synonym for credibility. That trust is in check with increasingly frequent paid verification.
Despite being reliable, considering the entire verification process I described here, it is curious that Google opted for this type of veracity attestation in Gmail after the controversial decision of the blue bird network. In the end, on Twitter, that blue checkmark no longer means legitimacy. In addition to not attesting that the account is who it claims to be, it still does not mean that the person or organization is reliable in the information it discloses.
Time will tell how well this strategy will work for Google.
For the end user, the usual recommendation remains: pay attention to the security and privacy policies of the social networks you use and follow best practices to identify if a piece of information is false, which is also part of the internet security package.