Suped

What are the key differences between BIMI certificate vendors Entrust and DigiCert?

Published 16 Jul 2025
Updated 28 Sep 2026
14 min read
Summarize with
Entrust vs DigiCert BIMI VMC certificate vendor comparison.
Updated on 28 Sep 2026: We corrected the Entrust transition dates and refreshed DigiCert pricing, then tightened the BIMI deployment checks.
The key difference is no longer price. Entrust ended VMC issuance on May 12, 2025, sold its public certificate business, and discontinued Public Trust CA services in Entrust Certificate Services on September 9, 2025. DigiCert remains listed as a Mark Verifying Authority on the BIMI issuer list, while Entrust is not. For a new BIMI Verified Mark Certificate purchase, DigiCert is the active option of these two vendors. Historically, both issued certificates that could support a validated brand logo in participating mailbox providers, but that historical comparison no longer describes current procurement.
Treat the decision as an issuer-trust and migration decision first, then a procurement decision. An old Entrust quote should now be treated as stale unless the seller identifies a different current issuing MVA, certificate chain, mailbox acceptance, and renewal owner in writing. A low price has no value if the resulting certificate is not accepted by the mailbox providers you need.
The vendor choice also does not replace the BIMI prerequisites. You still need DMARC enforcement, authenticated mail flow, a BIMI-ready SVG Tiny PS logo, a public HTTPS location for the logo and certificate, and reporting that identifies sources that pass or fail. Suped's product is relevant because BIMI depends on the same authentication foundation that DMARC monitoring exposes every day.

The short answer

Decision rule
If the shortlist contains only DigiCert and Entrust, choose DigiCert for a new BIMI certificate. Entrust is no longer an active public certificate issuer. If a reseller presents an Entrust-branded quote, require it to identify the actual current MVA, certificate chain, mailbox acceptance, and renewal path before approval.
In the early BIMI market, a valid VMC from either vendor connected a registered trademark, a validated organization, approved domains, and a BIMI TXT record. When both chains were accepted, the logo display was controlled by the receiving mailbox provider rather than the vendor name.
That old comparison is now historical. Apple stopped validating affected Entrust-rooted BIMI VMCs issued after November 15, 2024, while certificates issued on or before that date were expected to work until their natural expiration. Entrust then sold its public certificate business and ended VMC issuance through ECS. Each legacy deployment now needs an expiration, chain, mailbox-display, and replacement check.
  1. Current status: DigiCert remains on the public BIMI MVA list; Entrust does not.
  2. New purchases: DigiCert is an active issuer, while Entrust's public CA issuance has ended.
  3. Legacy certificates: Check expiration, issuer chain, revocation status, and display at each target mailbox provider.
  4. Inbox result: An accepted certificate validates the mark, but the mailbox provider still decides whether and how to show it.
DigiCert CertCentral Verified Mark Certificate ordering workflow.
DigiCert CertCentral Verified Mark Certificate ordering workflow.

What changed since the early BIMI market

BIMI started with a small issuer market, and early buyers often saw the decision as a choice between two similar certificate authorities. The question was reasonable: if Entrust cost about $500 less than DigiCert, what exactly did the extra money buy? At that time, the answer was often process and commercial terms rather than inbox behavior.
The current market is different. Entrust announced the sale of its public certificate business in January 2025, stopped VMC issuance on May 12, 2025, and discontinued Public Trust CA services in ECS on September 9, 2025. Existing Entrust VMCs remained valid through their expiration dates, but they cannot be renewed through Entrust. The current BIMI issuer list includes DigiCert but not Entrust. The BIMI Group also states that inclusion on its issuer page does not guarantee acceptance everywhere, because each mailbox provider decides which MVA certificates it accepts.
The Entrust migration context explains why teams with Entrust VMCs began planning replacements. General browser distrust actions concern public TLS trust, while Apple's change explicitly covered the affected Entrust-rooted BIMI VMCs issued after its cutoff. Test Apple Mail separately and inspect the deployed certificate rather than assuming every legacy certificate failed on the same day.
Earlier comparison
  1. Outcome: A trusted VMC from either vendor used the same BIMI record pattern.
  2. Price: Quotes and partner discounts often drove the decision.
  3. Process: Both vendors performed organization, domain, logo, and applicant validation.
  4. Risk: Provider acceptance was often treated as a background requirement.
Current comparison
  1. Outcome: DigiCert is active; Entrust is now a legacy deployment and migration question.
  2. Price: Compare current annual pricing, included domains, logos, hosting, and renewal.
  3. Process: DigiCert documents current VMC and CMC validation through CertCentral.
  4. Risk: Legacy Entrust certificates need replacement planning before expiration.

Vendor differences that actually matter

A BIMI certificate vendor does not make weak DMARC strong, fix broken SPF, improve sender reputation, or force Gmail to show a logo. The MVA validates the organization, domain control, applicant identity, and right to use the mark. It then issues a certificate that binds the logo to the approved identity and domains. The receiving mailbox provider decides whether to display the logo.

Area

DigiCert

Entrust

What to do

Issuer status
Currently listed
Not listed; issuance ended
Verify the current MVA
New purchase
Available
Not an active option
Reject stale Entrust quotes
Validation
Current documented workflow
Historical only
Prepare identity and mark evidence
Hosting
Logo and certificate hosting offered
Check legacy file ownership
Test both HTTPS URLs
Renewal
12-month subscription
Plan replacement
Assign an owner before expiry
Practical comparison for a current BIMI buying decision.
DigiCert's practical advantage in this two-vendor comparison is current issuance continuity. The DigiCert VMC page documents VMC and Common Mark Certificate ordering, hosting, renewal, and DMARC enforcement. A VMC covers a registered trademark or qualifying government mark and can enable Gmail's verified checkmark. A CMC supports a prior-use mark used for at least 12 months or a modified registered mark, but it does not provide Gmail's VMC checkmark.
Entrust's historical advantages were often price and an existing partner relationship. Those are no longer reasons to start a new Entrust order because Entrust's public CA services have ended. If a reseller still uses Entrust branding, ask which current MVA issues the certificate, which root and intermediate are used, who hosts the files, and who owns renewal.
BIMI readiness thresholds
A mark certificate order should start only after the organizational domain and subdomains reach DMARC enforcement at 100 percent and authentication is stable.
Not ready
No logo path
DMARC is missing or has policy none without stable reports.
Monitoring
Fix sources
Reports are active, but unauthenticated sources still need work.
Eligible
Start order
DMARC is at quarantine or reject with pct=100 and core mail streams pass.
Operational
Monitor
BIMI DNS, SVG, HTTPS hosting, and certificate renewals have owners.

Pricing and certificate scope

DigiCert currently publishes $1,752 for a VMC and $1,416 for a CMC, each as a 12-month auto-renewing subscription with prices subject to change. Its order page prices email-domain scope separately, so confirm that a quote covers every required base domain, logo, and hosting arrangement. Entrust no longer has a comparable current new-issuance price. Any old Entrust amount, including a quote that is about $500 lower, is historical and should not be used as the baseline for a current purchase.
  1. One logo: Plan one mark certificate for each distinct logo or wordmark that needs validation.
  2. Subdomains: A listed base domain can cover its subdomains when they use the same logo, so avoid paying to list them separately without a clear need.
  3. Other base domains: List each separate sending domain that will use the mark and confirm any added-domain charge.
  4. Validation time: DigiCert can often issue on the same day after all required documentation is verified, but preparation and response delays extend the process.
  5. Renewal cost: Mark certificates have a maximum validity of 397 days, so budget for annual renewal and revalidation rather than comparing only the first invoice.
The fastest way to make the quote comparable is to give the vendor a domain-and-logo inventory. Record each base domain, inherited subdomain, BIMI selector, logo, trademark status, and desired mailbox coverage. This exposes whether a price covers the same deployment or only one certificate for one mark.

How to compare Entrust and DigiCert

The useful question is not "which vendor has a nicer certificate?" A VMC works only when the full chain works. For new orders, the comparison ends quickly because Entrust no longer issues public certificates. For an existing Entrust deployment, use operational questions that legal, marketing, security, and DNS owners can answer before replacement work begins.
  1. Issuer status: Confirm that the MVA remains listed and that target mailbox providers accept its certificate chain.
  2. Validation burden: Prepare domain control, logo evidence, organization records, applicant identity checks, and authorized approver access.
  3. File hosting: Decide whether the MVA hosts the validated SVG and PEM files or your team owns stable HTTPS hosting.
  4. Renewal path: Document pricing, revalidation, replacement timing, and the person responsible for annual renewal.
  5. Fallback plan: Know how quickly DNS owners can update the BIMI TXT record if a certificate URL or issuer changes.
BIMI certificate vendor selection flow from DMARC enforcement to publishing.
BIMI certificate vendor selection flow from DMARC enforcement to publishing.
Price caveat
Compare the same certificate type, number of logos, base domains, hosting arrangement, support level, and renewal term. A historical Entrust discount is not a current alternative, and a DigiCert list price can differ from a negotiated quote.
If procurement needs a clean answer, choose DigiCert when the shortlist contains only DigiCert and Entrust. If the paperwork says Entrust, pause and identify the actual current issuer before approval. The BIMI certificate providers guide has a broader provider checklist.

DNS and validation checks before you buy

BIMI buying problems often begin before the MVA is involved. A team orders a certificate, then discovers that DMARC is not enforced, the mark does not qualify for the selected certificate type, the logo is not in SVG Tiny PS format, or a legitimate sender fails DMARC alignment. Fix those items first.
Minimum DMARC posture for BIMIdns
_dmarc.example.com TXT "v=DMARC1; p=quarantine; sp=quarantine; pct=100; rua=mailto:dmarc@example.com"
For many teams, the hardest part is reaching enforcement without breaking legitimate mail. Use a DMARC checker to confirm the record syntax, then use aggregate reports to find sources that do not pass with the visible From domain. If DNS ownership is spread across teams, hosted DMARC can simplify policy staging because day-to-day policy changes happen in the platform instead of repeated DNS edits.
?

What's your domain score?

Deep-scan SPF, DKIM & DMARC records for email deliverability and security issues.

The BIMI TXT record points to the logo and certificate. The exact URLs depend on whether the MVA hosts the files or your team hosts them. Both files need stable public HTTPS access, and the published SVG must exactly match the logo validated inside the certificate.
Example BIMI recorddns
default._bimi.example.com TXT "v=BIMI1; l=https://assets.example.com/bimi.svg; a=https://assets.example.com/vmc.pem;"
If you already have a BIMI record and need to identify the certificate issuer, extract the certificate URL from the a= tag and inspect the certificate issuer, validity dates, and chain. This is useful when inherited DNS records have unclear ownership. The VMC versus CMC checks page explains how the certificate types differ.
Inspect a BIMI certificate issuerbash
dig +short default._bimi.example.com TXT curl -s "$PEM_URL" | openssl x509 -noout -issuer -dates

Where Suped fits in the BIMI workflow

Suped is not a VMC or CMC issuer. A current MVA issues the certificate. Suped's product handles the authentication work around the purchase: DMARC aggregate reporting, SPF and DKIM alignment checks, policy staging, issue detection, and multi-domain reporting.
Suped DMARC dashboard showing email volume, authentication health, and source breakdown
Suped turns raw DMARC reports into sending sources, alignment failures, and remediation steps. That workflow helps a team reach enforcement before ordering a certificate and separate authentication failures from certificate, SVG, hosting, or mailbox-caching problems after publication.
  1. Before buying: Use Suped to inventory legitimate senders and fix SPF or DKIM alignment gaps.
  2. During rollout: Stage DMARC policy changes and watch failure rates before moving to enforcement.
  3. After publishing: Monitor authentication health so a DMARC regression is not mistaken for an issuer problem.
  4. Across clients: Use Suped's multi-tenant view to track BIMI readiness and certificate dates by domain.
When a logo does not appear after certificate issuance, separate certificate issues from authentication issues. Check DNS syntax, HTTPS access, an exact SVG match, DMARC policy, SPF and DKIM alignment, certificate validity, then mailbox-provider timing. A domain health checker helps catch the DNS and authentication basics before support escalation.

Entrust migration risk

The expensive BIMI mistake is planning against the old trust model. A team with an existing Entrust VMC should check the certificate expiration and issuer chain, confirm current display in target mailbox providers, and order a replacement from a current MVA before the legacy certificate expires. Existing Entrust VMCs were allowed to remain valid through expiration, but Entrust no longer provides the renewal path.
Apple-specific trust changes matter for teams that depend on Apple Mail display. The Apple Entrust alternatives page explains that migration concern. Do not wait for expiration week because organization, domain, logo, and authorized representative validation can take longer when records are incomplete.
Migration checklist
  1. Inventory: List each BIMI selector, logo URL, certificate URL, issuer, and expiration date.
  2. Acceptance: Confirm display in the mailbox providers that matter to recipients.
  3. Replacement: Order through a current MVA early enough for identity, domain, and mark validation.
  4. DNS change: Lower TTL before migration and update the BIMI record after both new files pass HTTPS checks.
For a new project, remove Entrust from the issuer shortlist. If Entrust branding appears in legacy procurement material, confirm whether it refers to an old certificate or a reseller relationship with a different current issuer. The contract and BIMI record should identify who is accountable for issuance, hosting, support, and renewal.

Views from the trenches

Best practices
Confirm current MVA status before purchase; mailbox acceptance can still vary by provider.
Get annual pricing in writing, including domains, hosting, revalidation, and support.
Keep BIMI DNS ownership clear so certificate URL changes do not wait on a handoff.
Common pitfalls
Treating a legacy Entrust quote as current creates a failed procurement and migration path.
Assuming an issued VMC guarantees Gmail display hides DMARC and SVG readiness issues.
Publishing BIMI before sender alignment is stable makes troubleshooting slower later.
Expert tips
Inspect the PEM issuer and dates directly when inherited BIMI records lack an owner.
Lower BIMI TXT TTL before certificate migration so cached data clears more quickly.
Separate certificate validation tasks from DMARC remediation tasks in the project plan.
Marketer from Email Geeks says the visible result of an accepted VMC is essentially the same, while the purchase and validation workflow varies by issuer.
2026-01-14 - Email Geeks
Marketer from Email Geeks says a legacy Entrust relationship does not remove the need to identify a current issuer and plan certificate replacement.
2026-01-21 - Email Geeks

Which vendor to choose now

For a new BIMI certificate decision limited to DigiCert and Entrust, DigiCert is the practical choice because it remains an active MVA and Entrust's public certificate issuance has ended. Current issuer status, mailbox acceptance, deployment scope, renewal ownership, and support matter more than an old price difference.
If you already have an Entrust VMC, inspect the deployed certificate and schedule replacement before expiration. If you are starting fresh, buy from a current MVA and spend more project time on DMARC enforcement and logo eligibility than on vendor branding. The certificate is the final part of the BIMI deployment, not its authentication foundation.
Suped's role is to keep that foundation measurable. Use Suped to monitor DMARC policy, identify failing sources, check SPF and DKIM alignment with the visible From domain, stage enforcement changes, and alert the team when authentication problems threaten BIMI eligibility.

Frequently asked questions

DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing