Start here if your logo vanished
You are probably reading this because your brand logo stopped showing next to your emails in Gmail or Apple Mail, and something you found pointed at Entrust. Here is the short version. If your mark certificate was issued by Entrust, it is not degraded or at risk. It is finished.
Before you buy anything, run these checks. They take about ten minutes and they tell you exactly where you stand.
- Look up your BIMI record: `dig +short default._bimi.yourdomain.com TXT`. On Windows, `nslookup -type=TXT default._bimi.yourdomain.com`. You are looking for the `a=` tag, which holds the URL of your certificate file.
- Read who issued that certificate: `curl -s https://yourdomain.com/your-vmc.pem | openssl x509 -noout -issuer -enddate`. If the issuer line says Entrust, you have your answer, and the expiry date will confirm it.
- Check DMARC as well: `dig +short _dmarc.yourdomain.com TXT`. BIMI requires `p=quarantine` or `p=reject` with `pct=100`. If someone rolled your policy back to `p=none`, that alone would hide your logo.
- Get a second opinion from the free BIMI Validator at bimigroup.org/bimi-generator, which checks your BIMI record format and whether your DMARC policy is at enforcement. It does not check the SVG or the certificate, so check those separately.
Your email still delivers
What actually happened to Entrust
A certificate authority, or CA, is a company that browsers, operating systems and mailbox providers agree to trust. When a CA signs a certificate saying this logo belongs to this company, everyone downstream accepts the claim because they trust the signer. Entrust was one of the oldest of these companies. It lost that agreement.
The dated sequence, from the parties' own publications:
- 27 June 2024. Google's Chrome Security Team published its decision to distrust Entrust. Chrome stopped trusting Entrust TLS certificates whose Signed Certificate Timestamp is dated after 11 November 2024.
- 15 November 2024. Apple's cutoff took effect, and Apple went further than Google did.
- 30 November 2024. Mozilla applied its own distrust-after date to the Entrust roots in Firefox.
- 29 January 2025. Sectigo announced it had acquired Entrust's public certificate business. Entrust framed the sale as sharpening its focus on quantum-ready cryptographic data security.
- 12 May 2025. Entrust Certificate Services stopped issuing Verified Mark Certificates and S/MIME certificates.
- 25 September 2025. Sectigo announced the customer migration off Entrust Certificate Services was complete.
Why Apple's decision is the one that killed the logos
Apple publishes a support document called Changes to Certification Authorities and certificates. Its Entrust entry carries an effective date of 15 November 2024 and lists ten roots. Five Entrust roots are marked as impacted for TLS, S/MIME and Timestamping, and four AffirmTrust roots for TLS and Timestamping. The tenth is the one that matters here: Entrust Verified Mark Root Certification Authority - VMCR1, with its impacted usage listed as Brand Indicator for Message Identification (BIMI).
That single line answers the question people are searching. Google's published decision covered TLS, the certificates that secure websites. Apple extended the same judgment to the root Entrust used for email brand verification, and named BIMI explicitly. Entrust also came off the BIMI Group's list of approved mark certificate issuers in mid 2025, after it stopped issuing.
Be precise about the reason if you are explaining this internally. Entrust was not breached. This was a certificate authority compliance dispute, argued in public over several years on the CA/Browser Forum and Mozilla policy lists. Root program operators concluded the incident history did not meet their bar. That is a governance judgment, and it is theirs to make.
There is no Entrust mark certificate left to rescue
Mark certificates have a maximum validity of 397 days, a little over thirteen months. Entrust issued its last one on 12 May 2025. Add 397 days and the final possible Entrust mark certificate expired in mid June 2026.
So there is nothing to migrate and nothing to renew. A published count of the public Certificate Transparency logs put the number of active Entrust mark certificates at zero as of 2 July 2026. If your BIMI record still points at an Entrust certificate today, your logo has not been showing for months.
Nobody tells you when this happens
Who can issue your replacement
The BIMI Group publishes the current list of Mark Verifying Authorities at bimigroup.org/vmc-issuers. As of today it names three: DigiCert, GlobalSign and SSL.com. All three issue both Verified Mark Certificates and Common Mark Certificates.
There is a trap worth knowing about. Sectigo, which bought Entrust's public certificate business, sells a product called a Verified Mark Certificate and publishes a price for it. Sectigo is not on the BIMI Group's issuer list. Certificates do appear in the transparency logs under its name, and there are credible reports that it fulfils new orders through DigiCert. That may work out fine. It may not, because mailbox providers decide what to honour based on the root a certificate chains to, not on who invoiced you. Before paying anyone not on that list, ask in writing which root the certificate will chain to, and check that root against the list yourself.
The BIMI Group is blunt about the limits of its own page. It states that inclusion on the list does not guarantee that a mailbox provider will honour your certificate. Buying from a listed issuer removes one risk, not all of them.
The replacement path, in order
Do these in sequence. Skipping ahead is how applications get rejected and money gets wasted.
- Get DMARC to enforcement and confirm it. The BIMI implementation guide requires `p=quarantine` or `p=reject` on the organisational domain and on subdomains via `sp=`, with `pct=100`. A policy of none, or a percentage below 100, disqualifies you. No CA will issue until this is true. Rushing enforcement while legitimate mail still fails alignment is how businesses lose invoices and password resets, so verify your aggregate reports first.
- Decide between a VMC and a CMC. A VMC needs a live trademark registration for the logo at an intellectual property office the CA accepts, and the accepted offices are region specific. A Common Mark Certificate needs no registration and instead evidences prior use of the logo, generally twelve months or more. For a lot of small businesses, the CMC is the honest answer.
- Rebuild the logo file properly. It must be SVG Tiny Portable/Secure, square, with a solid background rather than transparency, and under 32 KB. It also has to match the registered mark. Colour changes, rearranged elements and design details that were not in the trademark filing are common rejection reasons.
- Order from DigiCert, GlobalSign or SSL.com. Expect verification to take weeks rather than days. List pricing runs into four figures a year. Resellers discount heavily. We paid roughly $780 a year for our own GlobalSign VMC through a reseller.
- Host the new .pem file and repoint the `a=` tag in your `default._bimi` TXT record at it. Leave `l=` pointing at your SVG. Then revalidate and check a real inbox, not a preview tool.
- Handle Apple separately. Apple Mail can show a logo through BIMI, and Apple also runs Branded Mail, which requires no certificate at all. You upload the logo and Apple verifies the business. That programme now sits inside Apple Business, which replaced Apple Business Connect, Business Manager and Business Essentials on 14 April 2026.
What a mark certificate does not do
Two things get oversold around this, and we would rather lose the sale than repeat them.
A mark certificate does not stop impersonation. It stops one narrow kind of it. With DMARC at enforcement, nobody can send mail claiming to come from your exact domain and have it land. That is real and worth having. It does nothing about someone registering a lookalike domain, standing up a fake page, or running ads under your name. Those need takedown requests, which are the platform's decision to make and can be refused.
A mark certificate also does not guarantee your logo appears. Each mailbox provider applies its own criteria on top of the certificate, including sender reputation. You are buying eligibility, not an outcome.
And if a customer or supplier has already lost money to mail pretending to be you, that comes first. Their bank, immediately, then a report at ic3.gov if they are in the United States. Certificate work is prevention. It recovers nothing.
When we would tell you not to buy one
Some readers should close this page and spend the money elsewhere. You are one of them if any of the following is true.
- You have no registered trademark and no appetite for the time and cost of getting one. Look at a Common Mark Certificate, or at nothing.
- Your DMARC is not at enforcement and your mail flow is complicated. Fix authentication first. It carries almost all of the security benefit on its own. The logo is the visible part, not the useful part.
- You send very little email. The return on a four-figure annual certificate comes from recognition across volume. Without volume there is little to recognise.
- Someone quoted you a renewal on an Entrust certificate. Nobody can renew one. Ask which root it will chain to, and treat a vague answer as the answer.
The cheap version of this
Working with us
We are JWC Apps, based in San Diego. We built this stack on our own business before selling it to anyone: DMARC at enforcement, a GlobalSign Verified Mark Certificate, BIMI live in Gmail, and Meta Verified on a 52,000 follower Instagram account. We work only through official channels, we never take passwords, government ID documents or card numbers, and when we do not believe a case can succeed we will say so and decline rather than take the fee. If you are holding a dead Entrust certificate and want the replacement run end to end, that is work we do.
Common questions
Why is Apple distrusting Entrust CA?
Apple's support document Changes to Certification Authorities and certificates gives an effective date of 15 November 2024 for ten Entrust and AffirmTrust roots. The reason given across the root programs was a pattern of publicly disclosed compliance incidents and unmet commitments to improve, not a security breach. Apple went further than Chrome and Firefox by also listing the Entrust Verified Mark Root Certification Authority - VMCR1 as impacted for BIMI, which is what removed brand logos backed by Entrust certificates.
Does my Entrust VMC still work anywhere?
No. Mark certificates have a maximum validity of 397 days, and Entrust stopped issuing them on 12 May 2025, so the last one expired in mid June 2026. A published count of the Certificate Transparency logs recorded zero active Entrust mark certificates as of 2 July 2026. There is nothing left to migrate.
Who can issue a VMC now that Entrust is gone?
The BIMI Group's Mark Certificate Issuers page currently lists three: DigiCert, GlobalSign and SSL.com. All three issue both Verified Mark Certificates and Common Mark Certificates. The BIMI Group notes that inclusion on the list does not guarantee any given mailbox provider will honour a certificate.
Can I buy a VMC from Sectigo, since it bought Entrust's certificate business?
Sectigo does sell a product called a Verified Mark Certificate, but it is not on the BIMI Group's issuer list, and there are reports it fulfils new orders through DigiCert. Mailbox providers judge the root a certificate chains to, not the seller. Ask in writing which root your certificate will chain to and check that root against the BIMI Group list before paying.
Do I have to redo my trademark or logo file when I switch certificate authority?
You do not need a new trademark, but the new CA will run its own validation from scratch. Expect to resubmit the trademark registration details and the logo file. The logo must be SVG Tiny Portable/Secure, square, on a solid background, under 32 KB, and it must match the registered mark closely. Colour changes and elements not in the original filing are common rejection reasons.
How long does replacing a mark certificate take?
Plan for weeks rather than days. DMARC has to be at enforcement before a CA will issue, and getting there safely on a complex mail flow is often the longest part. Once documentation is verified, issuance itself can be quick, but the verification queue and any logo rework are not.
Sources checked
- https://support.apple.com/en-us/121668
- https://security.googleblog.com/2024/06/sustaining-digital-certificate-security.html
- https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/jCvkhBjg9Yw
- https://www.entrust.com/company/newsroom/entrust-sells-public-certificate-business-to-sectigo
- https://www.sectigo.com/resource-library/sectigo-completes-entrust-migration
- https://bimigroup.org/vmc-issuers/
- https://bimigroup.org/implementation-guide/
- https://bimigroup.org/bimi-generator/
- https://knowledge.workspace.google.com/admin/security/set-up-bimi
- https://developer.apple.com/support/bimi
- https://www.apple.com/newsroom/2026/03/introducing-apple-business-a-new-all-in-one-platform-for-businesses-of-all-sizes/
- https://www.digicert.com/tls-ssl/verified-mark-certificates
- https://www.globalsign.com/en/mark-certificate
- https://www.ssl.com/guide/vmc-complete-guide-for-validation-trademark-requirements-logo-specifications-and-bimi-dns-setup/
- https://www.digicert.com/blog/how-apples-entrust-root-distrust-impacts-brand-and-email-trust
- https://www.wordtothewise.com/2024/12/stop-using-entrust-for-your-bimi-certificates/
- https://vmccerts.com/research/certificate-authority
- https://www.ic3.gov/
Related service
Verified Mark Certificates and BIMI
BIMI puts your logo beside your name in Gmail, Apple Mail, and Yahoo. Getting it right means a certificate, a very specific SVG, and email authentication that already passes.