4431
Entrust certs to migrate
21.9% of all BIMI certificates
498
Expiring in 2026
Active migration wave now
4–6 wks
Planned migration time
90 days buffer recommended
0 days
Grace period on expiry
Logo disappears immediately

Why Entrust Exited the CA Market

In November 2024, Google announced that Chrome would stop trusting new TLS/SSL certificates issued by Entrust, citing a pattern of compliance failures and mis-issuances spanning several years. Mozilla Firefox followed with an equivalent public distrust decision. Because BIMI’s Verified Mark Certificate (VMC) and Common Mark Certificate (CMC) infrastructure relies on publicly-trusted Certificate Authority roots, this browser distrust effectively ended Entrust’s ability to issue new BIMI certificates. Entrust’s last BIMI certificate was issued in May 2025. As of the July 2026 dataset snapshot, only 0 Entrust BIMI certificates remain active globally — all expire by December 2026 with no renewal path. Existing holders must migrate to DigiCert, GlobalSign, or Sectigo before their certificate’s expiry date to avoid losing their verified inbox logo.

Before you start

Three Things to Confirm Before Starting the Migration

The migration process is straightforward. What causes delays is missing information at the point of application. Confirm these three things before proceeding to the step-by-step guide:

  • 1

    Your certificate’s exact expiry date (Not After)

    Find it in your Entrust portal, in the certificate PEM file, or by running a BIMI DNS lookup on your sending domain. You need this to set your migration start date and urgency level.

  • 2

    Your trademark registration status (for VMC) or prior use evidence (for CMC)

    The new CA will independently verify your trademark or prior use claim. Have the registration certificate or prior use documentation ready. This is where most migrations stall — the documentation is harder to locate quickly than expected.

  • 3

    Your current BIMI SVG logo file URL and the current BIMI DNS TXT record

    You will need to update the DNS record with the new certificate’s PEM URL after migration. Having the current record structure ready makes the DNS update step take minutes rather than requiring additional research.

The 6 steps

Step-by-Step Migration Process

1
Step
Locate and record your certificate expiry date
Time: 5–15 minutes

Your Entrust BIMI certificate has a Not After date printed in the certificate details. Find it using one of these methods:

  • Entrust portal: Log in and view your certificate details — the Not After date is displayed in the certificate information panel.
  • BIMI DNS lookup tool: Search for any public BIMI checker and enter your sending domain. The tool will display your certificate details including the expiry date.
  • From your PEM file: If you have the certificate PEM file, open it in any text editor — the Not After date is readable in the certificate header block.

Once you have the date: if it is within 90 days, start the migration immediately. If it is 90–180 days away, schedule the migration start. If it is more than 180 days away, add a calendar reminder at the 90-day mark and proceed when that date arrives.

2
Step
Choose your new Certificate Authority
Time: 30–60 minutes to evaluate and decide

Three CAs are currently issuing BIMI certificates with full mailbox provider support: DigiCert, GlobalSign, and Sectigo (via SSL Corporation). Compare them on the dimensions that matter to your organisation:

Growing fast
Market shareGrowing — strong in EU/JP
Track record2024–2025 market entry
SupportRegional support teams
Best forExisting GlobalSign TLS customers
Value option
Market shareGrowing from low base
Track record2025–2026 market entry
SupportStandard
Best forExisting Sectigo TLS customers

All three CAs are recognised by Gmail, Yahoo Mail, and Apple Mail. CA choice does not affect the inbox experience for recipients. It affects pricing, support process, and operational relationship. VMCcerts is a partner of all three and can facilitate the application with any of them.

3
Step
Prepare your documentation
Time: 1–3 days (depending on documentation readiness)

This is the step that most delays migrations. The new CA validates your right to use the logo independently — they do not accept Entrust’s prior validation. Prepare the following before submitting the application:

  • VMC path — trademark certificate: A copy of the granted trademark registration from USPTO, EUIPO, UKIPO, JPO, or another major jurisdiction. The trademark must be granted (not pending). It must cover the specific logo form used in your BIMI deployment.
  • CMC path — prior use evidence: Documentation showing the logo has been in commercial use — website screenshots with dates, marketing materials, product packaging images. The evidence should demonstrate consistent use over a reasonable period.
  • SVG logo file: Your current BIMI-compliant SVG file (Tiny P/S format). If the logo has changed since the original deployment, confirm the new version is BIMI-compliant before submitting.
  • Sending domain confirmation: The domain you want the certificate issued for — this must match the From address domain of the emails where you want the BIMI logo to display.
4
Step
Submit the certificate application
Time: 30 minutes to submit · 1–5 business days for CA processing

Apply directly through the chosen CA’s portal or through VMCcerts. The application process requires the documentation prepared in Step 3 and basic organisational information. CA processing time after submission is typically 1–5 business days, with most completions in 2–3 business days when documentation is complete.

Do not cancel your Entrust certificate before the new certificate is issued

Your Entrust certificate remains valid until its expiry date. Keep it active throughout the migration process. Only after you have received the new certificate, updated your DNS record, and validated the display should you consider closing the Entrust account.

5
Step
Update your BIMI DNS TXT record
Time: 15 minutes · Plus 24–48 hours DNS propagation

When your new certificate is issued, the CA provides a PEM file and a hosted PEM URL. Update your BIMI DNS TXT record to replace the Entrust PEM URL with the new CA’s URL. The record format does not change — only the a= value.

; Current record (Entrust)
default._bimi.yourdomain.com IN TXT “v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://entrust-pem-url.com/cert.pem”
; Updated record (new CA — only the a= value changes)
default._bimi.yourdomain.com IN TXT “v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://new-ca-pem-url.com/cert.pem”
; Note: the l= SVG URL does not change — same logo file, new certificate only

After updating the DNS record, allow 24–48 hours for propagation before validating. Using a BIMI DNS checker too soon after the update may return cached results.

6
Step
Validate the deployment
Time: 15 minutes · After DNS propagation completes

Confirm the migration is working correctly with these three checks:

  • BIMI DNS checker: Run your domain through a free BIMI lookup tool. Confirm the record resolves, the certificate is valid, the SVG URL returns a 200 response, and the certificate authority shows as the new CA (not Entrust).
  • Send a test email: Send a test email from your production sending domain to a Gmail or Yahoo Mail account. Open the email and confirm the verified logo appears in the sender slot.
  • Check the certificate expiry date: Confirm the new certificate’s Not After date is displayed in the DNS lookup result. Add it to your calendar as a renewal reminder at the 90-day mark.

Migration timeline

Recommended Timeline by Expiry Distance

Expiring <30 days
Start immediately — contact VMCcerts today
Expedited processing available. Risk of logo gap is high. Same-week application submission required.
Expiring 30–60 days
Start this week — document preparation is critical path
Begin documentation gathering immediately. Submit application within 10 days. CA processing + DNS propagation requires remaining buffer.
Expiring 60–90 days
Start within 2 weeks
Comfortable timeline but no slack for documentation delays. Submit within 3 weeks of today.
Expiring 90–180 days
Schedule the migration — execute at 90-day mark
Add calendar reminder now. Gather documentation proactively. Begin at the 90-day mark.
Expiring 180+ days
Set calendar reminder — no action needed yet
Set reminder at 90-day mark. Confirm documentation availability now so no delays when the time comes.

FAQ

Migration Questions

Will there be any logo gap during the migration?

A planned migration with a 60–90 day buffer should have zero logo gap. Your Entrust certificate remains valid until its expiry date. The new certificate is issued and the DNS record is updated before the Entrust certificate expires. The only scenario that creates a logo gap is an emergency migration after an unexpected expiry — which is entirely avoidable with advance planning.

Do I need to create a new SVG file for the new CA?

No. Your existing BIMI-compliant SVG file is CA-agnostic. The logo file URL in your DNS record (the l= parameter) does not change. Only the certificate PEM URL (the a= parameter) changes when you migrate. As long as your SVG file is still at the same URL and still meets the Tiny P/S specification, it carries forward to the new certificate without modification.

Can I migrate mid-certificate-year, or do I have to wait for expiry?

You can migrate at any time — you do not need to wait for expiry. An early migration means issuing a new certificate before the Entrust one expires. You update the DNS record to point to the new certificate, and both certificates are technically valid simultaneously for a brief period. The mailbox provider will use the certificate referenced in your DNS record, so the switch happens as soon as DNS propagates after the record update. There is no fee rebate for unused Entrust certificate time — this is a commercial decision about whether the operational simplicity of migrating early outweighs the cost of overlapping certificates.

We have multiple Entrust certificates across different domains — how do we manage bulk migration?

For multi-domain portfolios, the migration process is identical for each domain but benefits from coordination: stagger the application submissions to avoid documentation bottlenecks, choose a single new CA for all domains to simplify ongoing management, and build an expiry register documenting the new Not After dates for each domain immediately after migration. VMCcerts provides portfolio migration management for organisations with 3 or more Entrust certificates to migrate.
Let VMCcerts manage your Entrust migration
VMCcerts handles the complete migration process — documentation review, CA application, DNS update coordination, and validation. Partner of DigiCert, GlobalSign, and Sectigo. Single-domain and portfolio migration available.
Cite This Report



VMCcerts Research. (2026). Entrust BIMI Certificate Migration: The Complete Guide 2026 [Research Report]. VMCcerts. https://vmccerts.com/research/entrust-migration-complete-guide-2026
VMCcerts Research. “Entrust BIMI Certificate Migration: The Complete Guide 2026.” VMCcerts, 2026, https://vmccerts.com/research/entrust-migration-complete-guide-2026.
@techreport{vmccerts2026EntrustMigration,
author = {VMCcerts Research},
title = {Entrust BIMI Certificate Migration: The Complete Guide 2026},
institution = {VMCcerts},
year = {2026},
url = {https://vmccerts.com/research/entrust-migration-complete-guide-2026},
note = {Dataset: VMCcerts BIMI Dataset v2026.2. Snapshot: 2026-07-02.}
}
TY – RPRT
AU – VMCcerts Research
TI – Entrust BIMI Certificate Migration: The Complete Guide 2026
PY – 2026
PB – VMCcerts
UR – https://vmccerts.com/research/entrust-migration-complete-guide-2026
ER –