What are the key differences between BIMI certificate vendors Entrust and DigiCert?
Published 16 Jul 2025
Updated 26 Jul 2026
13 min read
Summarize with

Updated on 26 Jul 2026: We updated this comparison for Entrust's completed public CA exit, DigiCert's current pricing, and today's BIMI buying requirements.
The key difference is no longer price. Entrust sold its public certificate business and discontinued Public Trust CA services in Entrust Certificate Services on September 9, 2025. DigiCert remains listed as a Mark Verifying Authority on the BIMI issuer list, while Entrust is not. For a new BIMI Verified Mark Certificate purchase, DigiCert is the active option of these two vendors. Historically, both issued certificates that could support a validated brand logo in participating mailbox providers, but that historical comparison no longer describes current procurement.
Treat the decision as an issuer-trust and migration decision first, then a procurement decision. An old Entrust quote should now be treated as stale unless the seller identifies a different current issuing MVA, certificate chain, mailbox acceptance, and renewal owner in writing. A low price has no value if the resulting certificate is not accepted by the mailbox providers you need.
The vendor choice also does not replace the BIMI prerequisites. You still need DMARC enforcement, authenticated mail flow, a BIMI-ready SVG Tiny PS logo, a public HTTPS location for the logo and certificate, and reporting that identifies sources that pass or fail. Suped's product is relevant because BIMI depends on the same authentication foundation that DMARC monitoring exposes every day.
The short answer
Decision rule
If the shortlist contains only DigiCert and Entrust, choose DigiCert for a new BIMI certificate. Entrust is no longer an active public certificate issuer. If a reseller presents an Entrust-branded quote, require it to identify the actual current MVA, certificate chain, mailbox acceptance, and renewal path before approval.
In the early BIMI market, a valid VMC from either vendor connected a registered trademark, a validated organization, approved domains, and a BIMI TXT record. When both chains were accepted, the logo display was controlled by the receiving mailbox provider rather than the vendor name.
That old comparison is now historical. Browser root programs distrusted newly issued Entrust public TLS certificates after their respective cutoff dates, and Apple's trust change also covered Entrust-rooted BIMI VMCs. Entrust then sold its public certificate business and ended issuance through its ECS platform. Existing Entrust VMCs did not all stop on one date, but each deployment now needs an expiration, chain, mailbox-display, and replacement check.
- Current status: DigiCert remains on the public BIMI MVA list; Entrust does not.
- New purchases: DigiCert is an active issuer, while Entrust's public CA issuance has ended.
- Legacy certificates: Check expiration, issuer chain, revocation status, and display at each target mailbox provider.
- Inbox result: An accepted certificate validates the mark, but the mailbox provider still decides whether and how to show it.

DigiCert CertCentral Verified Mark Certificate ordering workflow.
What changed since the early BIMI market
BIMI started with a small issuer market, and early buyers often saw the decision as a choice between two similar certificate authorities. The question was reasonable: if Entrust cost about $500 less than DigiCert, what exactly did the extra money buy? At that time, the answer was often process and commercial terms rather than inbox behavior.
The current market is different. Entrust announced the sale of its public certificate business in January 2025 and discontinued Public Trust CA services in ECS on September 9, 2025. The current BIMI issuer list includes DigiCert but not Entrust. The BIMI Group also states that inclusion on its issuer page does not guarantee acceptance everywhere, because each mailbox provider decides which MVA certificates it accepts.
The Entrust migration context explains why teams with Entrust VMCs began planning replacements. The browser distrust actions are relevant trust history, but they are not identical to mailbox-provider BIMI policy. Apple explicitly applied its change to Entrust-rooted BIMI VMCs, so Apple Mail display needs its own test.
Earlier comparison
- Outcome: A trusted VMC from either vendor used the same BIMI record pattern.
- Price: Quotes and partner discounts often drove the decision.
- Process: Both vendors performed organization, domain, logo, and applicant validation.
- Risk: Provider acceptance was often treated as a background requirement.
Current comparison
- Outcome: DigiCert is active; Entrust is now a legacy deployment and migration question.
- Price: Compare current annual pricing, included domains, logos, hosting, and renewal.
- Process: DigiCert documents current VMC and CMC validation through CertCentral.
- Risk: Legacy Entrust certificates need replacement planning before expiration.
Vendor differences that actually matter
A BIMI certificate vendor does not make weak DMARC strong, fix broken SPF, improve sender reputation, or force Gmail to show a logo. The MVA validates the organization, domain control, applicant identity, and right to use the mark. It then issues a certificate that binds the logo to the approved identity and domains. The receiving mailbox provider decides whether to display the logo.
|
|
|
|
|---|---|---|---|
Issuer status | Currently listed | Not listed; issuance ended | Verify the current MVA |
New purchase | Available | Not an active option | Reject stale Entrust quotes |
Validation | Current documented workflow | Historical only | Prepare identity and mark evidence |
Hosting | Logo and certificate hosting offered | Check legacy file ownership | Test both HTTPS URLs |
Renewal | 12-month subscription | Plan replacement | Assign an owner before expiry |
Practical comparison for a current BIMI buying decision.
DigiCert's practical advantage in this two-vendor comparison is current issuance continuity. The DigiCert VMC page documents VMC and Common Mark Certificate ordering, hosting, renewal, and DMARC enforcement. A VMC covers a registered trademark or qualifying government mark and can enable Gmail's verified checkmark. A CMC supports qualifying prior-use or modified registered marks, but it does not provide Gmail's VMC checkmark.
Entrust's historical advantages were often price and an existing partner relationship. Those are no longer reasons to start a new Entrust order because Entrust's public CA services have ended. If a reseller still uses Entrust branding, ask which current MVA issues the certificate, which root and intermediate are used, who hosts the files, and who owns renewal.
BIMI readiness thresholds
A mark certificate order should start only after the sending domain reaches enforcement and stable authentication.
Not ready
No logo path
DMARC is missing or has policy none without stable reports.
Monitoring
Fix sources
Reports are active, but unauthenticated sources still need work.
Eligible
Start order
DMARC is at quarantine or reject and core mail streams pass.
Operational
Monitor
BIMI DNS, SVG, HTTPS hosting, and certificate renewals have owners.
Pricing and certificate scope
DigiCert currently publishes a $1,416 price for a 12-month auto-renewing mark certificate subscription, with prices subject to change. Entrust no longer has a comparable current new-issuance price. Any old Entrust amount, including a quote that is about $500 lower, is historical and should not be used as the baseline for a current purchase.
- One logo: Plan one mark certificate for each distinct logo or wordmark that needs validation.
- Subdomains: A listed base domain can cover its subdomains, so avoid paying to list them separately without a clear need.
- Other base domains: List each separate sending domain that will use the mark and confirm any added-domain charge.
- Validation time: DigiCert says validation can take one business day to more than a week, depending on preparation and response time.
- Renewal cost: Budget for annual renewal and revalidation rather than comparing only the first invoice.
The fastest way to make the quote comparable is to give the vendor a domain-and-logo inventory. Record each base domain, inherited subdomain, BIMI selector, logo, trademark status, and desired mailbox coverage. This exposes whether a price covers the same deployment or only one certificate for one mark.
How to compare Entrust and DigiCert
The useful question is not "which vendor has a nicer certificate?" A VMC works only when the full chain works. For new orders, the comparison ends quickly because Entrust no longer issues public certificates. For an existing Entrust deployment, use operational questions that legal, marketing, security, and DNS owners can answer before replacement work begins.
- Issuer status: Confirm that the MVA remains listed and that target mailbox providers accept its certificate chain.
- Validation burden: Prepare domain control, logo evidence, organization records, applicant identity checks, and authorized approver access.
- File hosting: Decide whether the MVA hosts the validated SVG and PEM files or your team owns stable HTTPS hosting.
- Renewal path: Document pricing, revalidation, replacement timing, and the person responsible for annual renewal.
- Fallback plan: Know how quickly DNS owners can update the BIMI TXT record if a certificate URL or issuer changes.

BIMI certificate vendor selection flow from DMARC enforcement to publishing.
Price caveat
Compare the same certificate type, number of logos, base domains, hosting arrangement, support level, and renewal term. A historical Entrust discount is not a current alternative, and a DigiCert list price can differ from a negotiated quote.
If procurement needs a clean answer, choose DigiCert when the shortlist contains only DigiCert and Entrust. If the paperwork says Entrust, pause and identify the actual current issuer before approval. The BIMI certificate providers guide has a broader provider checklist.
DNS and validation checks before you buy
BIMI buying problems often begin before the MVA is involved. A team orders a certificate, then discovers that DMARC is not enforced, the mark does not qualify for the selected certificate type, the logo is not in SVG Tiny PS format, or a legitimate sender fails DMARC alignment. Fix those items first.
Minimum DMARC posture for BIMIdns
_dmarc.example.com TXT "v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc@example.com"
For many teams, the hardest part is reaching enforcement without breaking legitimate mail. Use a DMARC checker to confirm the record syntax, then use aggregate reports to find sources that do not pass with the visible From domain. If DNS ownership is spread across teams, hosted DMARC can simplify policy staging because day-to-day policy changes happen in the platform instead of repeated DNS edits.
?
What's your domain score?
Deep-scan SPF, DKIM & DMARC records for email deliverability and security issues.
The BIMI TXT record points to the logo and certificate. The exact URLs depend on whether the MVA hosts the files or your team hosts them. Both files need stable public HTTPS access, and the published SVG must exactly match the logo validated inside the certificate.
Example BIMI recorddns
default._bimi.example.com TXT "v=BIMI1; l=https://assets.example.com/bimi.svg;" "a=https://assets.example.com/vmc.pem;"
If you already have a BIMI record and need to identify the certificate issuer, extract the certificate URL from the a= tag and inspect the certificate issuer, validity dates, and chain. This is useful when inherited DNS records have unclear ownership. The VMC versus CMC checks page explains how the certificate types differ.
Inspect a BIMI certificate issuerbash
dig +short default._bimi.example.com TXT curl -s "$PEM_URL" | openssl x509 -noout -issuer -dates
Where Suped fits in the BIMI workflow
Suped is not a VMC or CMC issuer. A current MVA issues the certificate. Suped's product handles the authentication work around the purchase: DMARC aggregate reporting, SPF and DKIM alignment checks, policy staging, issue detection, and multi-domain reporting.
Suped DMARC dashboard showing email volume, authentication health, and source breakdown
Suped turns raw DMARC reports into sending sources, alignment failures, and remediation steps. That workflow helps a team reach enforcement before ordering a certificate and separate authentication failures from certificate, SVG, hosting, or mailbox-caching problems after publication.
- Before buying: Use Suped to inventory legitimate senders and fix SPF or DKIM alignment gaps.
- During rollout: Stage DMARC policy changes and watch failure rates before moving to enforcement.
- After publishing: Monitor authentication health so a DMARC regression is not mistaken for an issuer problem.
- Across clients: Use Suped's multi-tenant view to track BIMI readiness and certificate dates by domain.
When a logo does not appear after certificate issuance, separate certificate issues from authentication issues. Check DNS syntax, HTTPS access, an exact SVG match, DMARC policy, SPF and DKIM alignment, certificate validity, then mailbox-provider timing. A domain health checker helps catch the DNS and authentication basics before support escalation.
Entrust migration risk
The expensive BIMI mistake is planning against the old trust model. A team with an existing Entrust VMC should check the certificate expiration and issuer chain, confirm current display in target mailbox providers, and order a replacement from a current MVA before the legacy certificate expires.
Apple-specific trust changes matter for teams that depend on Apple Mail display. The Apple Entrust alternatives page explains that migration concern. Do not wait for expiration week because organization, domain, logo, and authorized representative validation can take more than a week when records are incomplete.
Migration checklist
- Inventory: List each BIMI selector, logo URL, certificate URL, issuer, and expiration date.
- Acceptance: Confirm display in the mailbox providers that matter to recipients.
- Replacement: Order through a current MVA early enough for identity, domain, and mark validation.
- DNS change: Lower TTL before migration and update the BIMI record after both new files pass HTTPS checks.
For a new project, remove Entrust from the issuer shortlist. If Entrust branding appears in legacy procurement material, confirm whether it refers to an old certificate or a reseller relationship with a different current issuer. The contract and BIMI record should identify who is accountable for issuance, hosting, support, and renewal.
Views from the trenches
Best practices
Confirm current MVA status before purchase; mailbox acceptance can still vary by provider.
Get annual pricing in writing, including domains, hosting, revalidation, and support.
Keep BIMI DNS ownership clear so certificate URL changes do not wait on a handoff.
Common pitfalls
Treating a legacy Entrust quote as current creates a failed procurement and migration path.
Assuming an issued VMC guarantees Gmail display hides DMARC and SVG readiness issues.
Publishing BIMI before sender alignment is stable makes troubleshooting slower later.
Expert tips
Inspect the PEM issuer and dates directly when inherited BIMI records lack an owner.
Lower BIMI TXT TTL before certificate migration so cached data clears more quickly.
Separate certificate validation tasks from DMARC remediation tasks in the project plan.
Marketer from Email Geeks says the visible result of an accepted VMC is essentially the same, while the purchase and validation workflow varies by issuer.
2026-01-14 - Email Geeks
Marketer from Email Geeks says a legacy Entrust relationship does not remove the need to identify a current issuer and plan certificate replacement.
2026-01-21 - Email Geeks
The practical choice
For a new BIMI certificate decision limited to DigiCert and Entrust, DigiCert is the practical choice because it remains an active MVA and Entrust's public certificate issuance has ended. Current issuer status, mailbox acceptance, deployment scope, renewal ownership, and support matter more than an old price difference.
If you already have an Entrust VMC, inspect the deployed certificate and schedule replacement before expiration. If you are starting fresh, buy from a current MVA and spend more project time on DMARC enforcement and logo eligibility than on vendor branding. The certificate is the final part of the BIMI deployment, not its authentication foundation.
Suped's role is to keep that foundation measurable. Use Suped to monitor DMARC policy, identify failing sources, check SPF and DKIM alignment with the visible From domain, stage enforcement changes, and alert the team when authentication problems threaten BIMI eligibility.

