Certificates are certificates are certificates.
They're 1KB files full of random numbers. What you use them for shouldn't alter their price... which ought to be zero.
The facts that a handful of near-monopolistic CAs have managed to control protocols, set standards, and generally funnel money into their coffers that need not have been spent at all is one of the worst examples of naked capitalistic greed I have ever seen.
Rent seeking, pure and simple.
> Thousands and thousands of dollars for a BIMI certificate is just ludicrous.
VMCs are between 800 and 1500 USD
> Certificates are certificates are certificates.
The x509 certificate is, but the process to verify your ownership of the supplied 'mark' (your logo) is not.
The VMC issuing procedure is very involved, it requires the CA to confirm with your local trademark office that your company owns the trademark. For VMC the CA is also required to verify (by phone) that the person who requested the VMC does indeed work for the company, they are also required to verify that the person who requested to certificate is allowed by the organization to do so.
The CAs are actually doing work here, there are real costs.
FWIW: Digicert currently sells VMC for a discounted price of 800USD, which they claim is not even economically viable. Without the discount expect VMCs to be ~1500USD.
Your argument is essentially identical to the arguments usually made to explain why EV certificates are expensive, and nobody is buying those.
And then clicking 'renew' once per year?
How could you possibly charge less than a thousand dollars for that...
Again, the 'renew' click is not why this is expensive. It's just a cryptographic function that signs a bunch of data, Lets Encrypt has long proven that certificates can be created free-of-charge. However, having a human verifying that everything checks out is the expensive part. Having that human work in an environment, following procedures that passes public audits is expensive. None of the trademark offices is going to do your trademark validations for free. No-one is going to staff a call-centre for free.
You are right about the technical part of creating a certificate being trivially easy, but I believe you truly underestimate the costs of running a CA that is capable of delivering VMCs.
Maybe that some company can do it for less than the current prices, I don't know. Competition will show that eventually. But if you truly think that you can do it for less than the current CAs, then start a CA yourself and start competing.
So you provide the CA with an trademark ID number that they can look up and they verify that you represent the company that owns the trademark. It's like 10 minutes on top of the existing EV process, but it's more than double the price.
Per domain.
One of my customers has dozens of domain names!
The domain names are in the AN section of the cert. You can have as many as you want in there (as long as they share the same logo)
Please be aware that the BIMI standard is far from finished. There are some serious documentation ambiguities that pose a risk to how well BIMI might function, and how email providers will adopt the technology. Obviously, the CAs are now pushing hard for BIMI, since VMCs are a new source of recurring business for them.
In my personal opinion I think that BIMI is pushed to early, which could leave brands attempting to adopt BIMI disappointed. Obtaining a VMC is quite involved (and expensive) for small businesses, and the potential benefits are (currently) quite small, as not many email service providers support BIMI.
Don't get me wrong though, I think BIMI has a great goal of pushing the DMARC adoption rate (remember, you must implement strict DMARC for BIMI to work). I just don't see BIMI offering any reliable brand exposure for the coming years. Only time will tell I guess.
What does this provide in contrast to DKIM? Perhaps there are logistical problems with DKIM, but I wouldn't know. I wonder why it isn't more widely spread in the first place. The receiver can determine the requirement, which is the best solution imho.
For Google it seems to be more of a marketing issue than security. Furthermore provider could track domain requests. That isn't just suspicious, this is almost malicious. There is a reason mail clients don't display pictures outright.
I hope my mail client will never support this.
It does pass the checks though [1], but does not really work because of the missing certificate which you can for example get at DigiCert [2] once your trademark has been approved..
The domains I configured it for are: antwise.com and vimalin.com so you can see at [1] how it looks like when it is supposed to work.
[1] https://bimigroup.org/bimi-generator/
[2] https://www.digicert.com/tls-ssl/verified-mark-certificates