Suped

How can I check if a domain uses Entrust or Digicert for BIMI, and should I avoid Entrust?

Summary

Checking which Certificate Authority (CA) a domain uses for its BIMI (Brand Indicators for Message Identification) Verified Mark Certificate (VMC) is crucial, especially given recent concerns surrounding Entrust. While only the purchaser definitively knows, there are several technical methods and online tools available to ascertain this information publicly. The industry is currently navigating how Google's announced distrust of Entrust's public TLS certificates will affect its VMCs for BIMI, prompting a closer look at vendor choices like DigiCert.

What email marketers say

Email marketers are keenly aware of the impact brand visibility has on engagement, making BIMI a high-interest area. The community discussion often revolves around practical ways to implement and troubleshoot BIMI, including checking VMC issuers. Recent news about Entrust has prompted marketers to assess potential disruptions to their carefully crafted brand presence in the inbox.

Marketer view

Marketer from Email Geeks suggests that marketers are always looking for straightforward methods to verify their BIMI setup. This includes checking which Certificate Authority (CA) issued their Verified Mark Certificate (VMC).

02 Jul 2024 - Email Geeks

Marketer view

Marketer from Hashed Out by The SSL Store™ indicates that since DigiCert and Entrust are the primary CAs for Mark Certificates, understanding which one a domain uses is key for proper BIMI implementation. Updates to these certificates are ongoing, requiring senders to stay informed.

02 Jul 2024 - Hashed Out by The SSL Store™

What the experts say

Industry experts closely monitor the technical specifications and operational integrity of Certificate Authorities. The discussion surrounding Entrust's VMCs highlights a critical juncture where compliance and trust directly impact the efficacy of emerging email authentication standards like BIMI. Experts provide deep insights into how certificate issuance and trust chains function, and what the recent developments mean for BIMI adoption and email security.

Expert view

Expert from Email Geeks, Steve, explains that the issuer of a BIMI VMC can be identified by first pulling the URL from the BIMI DNS TXT record and then using curl and openssl to inspect the certificate's issuer field.

02 Jul 2024 - Email Geeks

Expert view

Expert from Spam Resource suggests that the broader distrust of a Certificate Authority (CA) can have ripple effects beyond specific certificate types. This indicates the importance of a CA's overall reputation and compliance with industry standards for all services they provide.

02 Jul 2024 - Spam Resource

What the documentation says

Official documentation from organizations like the BIMI Group and Certificate Authorities provides the foundational rules and guidelines for implementing BIMI, including details on VMCs. These documents outline the technical requirements, the role of Certificate Authorities, and the processes for validating VMCs. Understanding these guidelines is essential for proper BIMI setup and troubleshooting.

Technical article

Documentation from the BIMI Group highlights that to prevent unauthorized logo usage, a Mark Verifying Authority (MVA) such as Entrust Datacard is tasked with validating the authenticity and authorization of logos intended for BIMI display.

02 Jul 2024 - BIMI Group

Technical article

Documentation from GoDMARC Knowledge Base explains that the process of obtaining a BIMI VMC Certificate involves selecting a Certificate Authority like DigiCert or Entrust and submitting specific details including the domain name and proof of trademark registration.

02 Jul 2024 - GoDMARC Knowledge Base

11 resources

Start improving your email deliverability today

Get started