In November 2024, Google announced that Chrome would stop trusting new TLS/SSL certificates issued by Entrust, citing a pattern of compliance failures and mis-issuances spanning several years. Mozilla Firefox followed with an equivalent public distrust decision. Because BIMI’s Verified Mark Certificate (VMC) and Common Mark Certificate (CMC) infrastructure relies on publicly-trusted Certificate Authority roots, this browser distrust effectively ended Entrust’s ability to issue new BIMI certificates. Entrust’s last BIMI certificate was issued in May 2025. As of the July 2026 dataset snapshot, only 0 Entrust BIMI certificates remain active globally — all expire by December 2026 with no renewal path. Existing holders must migrate to DigiCert, GlobalSign, or Sectigo before their certificate’s expiry date to avoid losing their verified inbox logo.
Before you start
Three Things to Confirm Before Starting the Migration
The migration process is straightforward. What causes delays is missing information at the point of application. Confirm these three things before proceeding to the step-by-step guide:
-
1
Your certificate’s exact expiry date (Not After)
Find it in your Entrust portal, in the certificate PEM file, or by running a BIMI DNS lookup on your sending domain. You need this to set your migration start date and urgency level.
-
2
Your trademark registration status (for VMC) or prior use evidence (for CMC)
The new CA will independently verify your trademark or prior use claim. Have the registration certificate or prior use documentation ready. This is where most migrations stall — the documentation is harder to locate quickly than expected.
-
3
Your current BIMI SVG logo file URL and the current BIMI DNS TXT record
You will need to update the DNS record with the new certificate’s PEM URL after migration. Having the current record structure ready makes the DNS update step take minutes rather than requiring additional research.
The 6 steps
Step-by-Step Migration Process
Your Entrust BIMI certificate has a Not After date printed in the certificate details. Find it using one of these methods:
- Entrust portal: Log in and view your certificate details — the Not After date is displayed in the certificate information panel.
- BIMI DNS lookup tool: Search for any public BIMI checker and enter your sending domain. The tool will display your certificate details including the expiry date.
- From your PEM file: If you have the certificate PEM file, open it in any text editor — the Not After date is readable in the certificate header block.
Once you have the date: if it is within 90 days, start the migration immediately. If it is 90–180 days away, schedule the migration start. If it is more than 180 days away, add a calendar reminder at the 90-day mark and proceed when that date arrives.
Three CAs are currently issuing BIMI certificates with full mailbox provider support: DigiCert, GlobalSign, and Sectigo (via SSL Corporation). Compare them on the dimensions that matter to your organisation:
All three CAs are recognised by Gmail, Yahoo Mail, and Apple Mail. CA choice does not affect the inbox experience for recipients. It affects pricing, support process, and operational relationship. VMCcerts is a partner of all three and can facilitate the application with any of them.
This is the step that most delays migrations. The new CA validates your right to use the logo independently — they do not accept Entrust’s prior validation. Prepare the following before submitting the application:
- VMC path — trademark certificate: A copy of the granted trademark registration from USPTO, EUIPO, UKIPO, JPO, or another major jurisdiction. The trademark must be granted (not pending). It must cover the specific logo form used in your BIMI deployment.
- CMC path — prior use evidence: Documentation showing the logo has been in commercial use — website screenshots with dates, marketing materials, product packaging images. The evidence should demonstrate consistent use over a reasonable period.
- SVG logo file: Your current BIMI-compliant SVG file (Tiny P/S format). If the logo has changed since the original deployment, confirm the new version is BIMI-compliant before submitting.
- Sending domain confirmation: The domain you want the certificate issued for — this must match the From address domain of the emails where you want the BIMI logo to display.
Apply directly through the chosen CA’s portal or through VMCcerts. The application process requires the documentation prepared in Step 3 and basic organisational information. CA processing time after submission is typically 1–5 business days, with most completions in 2–3 business days when documentation is complete.
Your Entrust certificate remains valid until its expiry date. Keep it active throughout the migration process. Only after you have received the new certificate, updated your DNS record, and validated the display should you consider closing the Entrust account.
When your new certificate is issued, the CA provides a PEM file and a hosted PEM URL. Update your BIMI DNS TXT record to replace the Entrust PEM URL with the new CA’s URL. The record format does not change — only the a= value.
default._bimi.yourdomain.com IN TXT “v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://entrust-pem-url.com/cert.pem”
; Updated record (new CA — only the a= value changes)
default._bimi.yourdomain.com IN TXT “v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://new-ca-pem-url.com/cert.pem”
; Note: the l= SVG URL does not change — same logo file, new certificate only
After updating the DNS record, allow 24–48 hours for propagation before validating. Using a BIMI DNS checker too soon after the update may return cached results.
Confirm the migration is working correctly with these three checks:
- BIMI DNS checker: Run your domain through a free BIMI lookup tool. Confirm the record resolves, the certificate is valid, the SVG URL returns a 200 response, and the certificate authority shows as the new CA (not Entrust).
- Send a test email: Send a test email from your production sending domain to a Gmail or Yahoo Mail account. Open the email and confirm the verified logo appears in the sender slot.
- Check the certificate expiry date: Confirm the new certificate’s Not After date is displayed in the DNS lookup result. Add it to your calendar as a renewal reminder at the 90-day mark.
Migration timeline
Recommended Timeline by Expiry Distance
FAQ
Migration Questions
Will there be any logo gap during the migration?
Do I need to create a new SVG file for the new CA?
Can I migrate mid-certificate-year, or do I have to wait for expiry?
We have multiple Entrust certificates across different domains — how do we manage bulk migration?
Read next
Related Resources
author = {VMCcerts Research},
title = {Entrust BIMI Certificate Migration: The Complete Guide 2026},
institution = {VMCcerts},
year = {2026},
url = {https://vmccerts.com/research/entrust-migration-complete-guide-2026},
note = {Dataset: VMCcerts BIMI Dataset v2026.2. Snapshot: 2026-07-02.}
}
AU – VMCcerts Research
TI – Entrust BIMI Certificate Migration: The Complete Guide 2026
PY – 2026
PB – VMCcerts
UR – https://vmccerts.com/research/entrust-migration-complete-guide-2026
ER –