How can I check if a domain uses Entrust or Digicert for BIMI, and should I avoid Entrust?

Summary

To determine if a domain uses Entrust or DigiCert for BIMI, you can manually inspect the certificate details from the BIMI record using tools like OpenSSL or utilize online BIMI checkers such as aboutmy.email. It's important to verify the issuer against approved VMC issuer lists and to monitor news regarding the trustworthiness and compliance of these CAs, especially Entrust, as major email providers' decisions can impact certificate validity. Google's Chrome team views Entrust as violating CA requirements, although there are no root issues directly affecting BIMI. For those prioritizing security, avoiding Entrust in the near future might be prudent. Implementing BIMI with VMCs from trusted CAs enhances email security and brand visibility, provided that correct DNS records are set up. DigiCert is considered a safe choice, and understanding vendor switching costs is advisable.

Key findings

  • Multiple Verification Methods: You can manually inspect certificates via OpenSSL or use online BIMI checkers to determine the issuer.
  • Issuer Approval Lists: The BIMI Group and other sources provide lists of approved VMC issuers.
  • Google's Distrust of Entrust: Google's Chrome team has concerns about Entrust's compliance with CA requirements.
  • VMC Benefits: Implementing BIMI with a valid VMC enhances brand security, trust, and logo visibility in email.

Key considerations

  • Entrust Risk: Carefully consider the potential risks associated with Entrust based on Google's concerns, although no immediate root issues affect BIMI directly.
  • Vendor Switching Preparedness: Understand the costs and processes involved in switching VMC vendors.
  • DNS Configuration: Ensure correct DNS record configuration for proper BIMI implementation.
  • Staying Informed: Monitor news and compliance reports related to VMC issuers like Entrust.
  • DigiCert as Alternative: DigiCert is viewed as a solid alternative to Entrust for VMC issuance.

What email marketers say
10Marketer opinions

To check if a domain uses Entrust or Digicert for BIMI, you can manually inspect the certificate by fetching it from the BIMI record using tools like OpenSSL or online BIMI checkers. Verify the issuer details against a list of approved VMC issuers, such as those provided by the BIMI Group. It's important to monitor news regarding the trustworthiness and compliance of VMC issuers like Entrust, as decisions by email providers can impact certificate validity. Implementing BIMI with VMCs from trusted CAs enhances email security and brand visibility.

Key opinions

  • Manual Certificate Inspection: Certificates can be manually inspected using OpenSSL or online BIMI checkers to verify the issuer.
  • VMC Issuer Verification: Verify the VMC issuer against approved lists to ensure compliance.
  • Email Provider Compliance: VMC compatibility should be verified with specific email provider requirements.
  • BIMI Implementation Benefits: BIMI with VMCs enhances email security, brand visibility, and trust.

Key considerations

  • Entrust Monitoring: Monitor news and announcements regarding the trustworthiness and compliance of Entrust and other VMC issuers.
  • Certificate Authority Trust: Ensure the VMC is issued by a trusted certificate authority to maintain validity and brand security.
  • DNS Record Setup: Ensure correct DNS records are set up to authenticate the brand's logo properly.
  • Compatibility Check: Verify the VMC issuer and its compatibility with email providers to ensure it is working as expected.
Marketer view

Email marketer from EmailToolTester clarifies that BIMI relies on having a valid VMC issued by a trusted certificate authority and setting up the correct DNS records to authenticate the brand's logo and ensure it is displayed in email inboxes.

September 2024 - EmailToolTester
Marketer view

Email marketer from OnlyMyEmail recommends that to check a BIMI record for the VMC, it is recommended to inspect the DNS records of the domain and check the URL to see if it is valid.

November 2024 - OnlyMyEmail
Marketer view

Email marketer from BIMI Group provides a list of approved VMC (Verified Mark Certificate) issuers. The BIMI Group recommends that email senders choose from the approved VMC list for BIMI implementation.

May 2024 - BIMI Group
Marketer view

Email marketer from Stack Overflow explains that you can verify the issuer of the Verified Mark Certificate (VMC) by checking the certificate details after fetching it from the BIMI record. You can use tools like OpenSSL to inspect the certificate.

January 2023 - Stack Overflow
Marketer view

Marketer from Email Geeks shares that you can manually get the certificate and inspect it, using `openssl x509 -in certificate.crt -text -noout` or finding a website to do it for you.

March 2024 - Email Geeks
Marketer view

Email marketer from Reddit shares that DigiCert and Entrust are common choices for VMC issuers, but one should verify compatibility with the email provider's requirements. Also should keep up to date with any news of distrust of the certificate authorities.

August 2023 - Reddit
Marketer view

Email marketer from Mailhardener advises monitoring news and announcements regarding the trustworthiness and compliance of different VMC issuers like Entrust, as decisions from major email providers can impact the validity of certificates.

January 2024 - Mailhardener
Marketer view

Marketer from Email Geeks shares Google's statement on Entrust VMCs and that they are currently working internally to assess the situation, with the intent of choosing a path that takes into account the relevant use cases in Gmail while upholding the safety and security of its users.

September 2021 - Email Geeks
Marketer view

Email marketer from VMC Authority shares that using a VMC improves brand trust, customer engagement, and email security, suggesting that organizations obtain VMCs from reputable CAs to leverage these benefits.

March 2021 - VMC Authority
Marketer view

Email marketer from Proofpoint emphasizes that BIMI enhances email security and brand visibility, recommending organizations implement BIMI with VMCs from trusted CAs to protect their brand reputation.

April 2023 - Proofpoint

What the experts say
6Expert opinions

To check if a domain uses Entrust or Digicert for BIMI, tools like aboutmy.email can pull the BIMI data, including the certificate issuer. Alternatively, dig and curl commands can be used to manually extract the issuer information. While there may be other reasons to distrust Entrust, no root issues directly affect BIMI, but Google's Chrome team views Entrust as violating CA requirements. As such, it is suggested that anyone concerned about security should avoid them in the near future. Understanding the costs and processes involved in switching vendors is important, and choosing DigiCert is unlikely to face criticism.

Key opinions

  • Tool Availability: Tools like aboutmy.email can extract BIMI data, including the certificate issuer.
  • Manual Extraction: dig and curl commands can be used to manually extract issuer information from BIMI records.
  • Google's Distrust: Google's Chrome team views Entrust as violating CA requirements.
  • No Root Issues for BIMI: There are no root issues directly affecting Entrust's use for BIMI, although other reasons for distrust exist.

Key considerations

  • Security Concerns: Those concerned about security should consider avoiding Entrust in the near future due to Google's distrust and past behavior.
  • Vendor Switching: Understand the costs and processes involved in switching VMC vendors.
  • DigiCert as Safe Choice: Choosing DigiCert for VMCs is unlikely to face criticism.
Expert view

Expert from Email Geeks shares that aboutmy.email will pull the BIMI data, including the cert issuer and that most BIMI-specific tools would too.

November 2022 - Email Geeks
Expert view

Expert from Email Geeks explains that Google's Chrome team views Encert as intentionally violating CA requirements and breaking rules, leading to the potential "certificate authority death penalty".

August 2021 - Email Geeks
Expert view

Expert from Email Geeks shares his belief that Encert will improve but suggests that anyone concerned about security should avoid them in the near future.

August 2021 - Email Geeks
Expert view

Expert from Word to the Wise responds that there are no trusted root issues with Entrust and BIMI, however there are other good reasons to distrust them, but it is very unlikely to affect BIMI.

August 2022 - Word to the Wise
Expert view

Expert from Email Geeks suggests everyone should understand the process and costs involved in switching vendors. He also states that nobody will be criticised for choosing DigiCert.

June 2021 - Email Geeks
Expert view

Expert from Email Geeks explains how to use dig and curl commands to extract the issuer information from a BIMI record. He provides the commands and explains that default is the BIMI selector.

April 2021 - Email Geeks

What the documentation says
3Technical articles

DigiCert, Entrust, and Sectigo all provide Verified Mark Certificates (VMCs) that are essential for BIMI implementation. These certificates, issued by recognized Certificate Authorities, enable organizations to display their logos in email inboxes. Each provider adheres to BIMI standards, with each documentation explaining the process of acquiring and implementing a VMC.

Key findings

  • VMC Essential for BIMI: A Verified Mark Certificate (VMC) is necessary for BIMI implementation.
  • Recognized Certificate Authorities: VMCs must be issued by a recognized Certificate Authority.
  • Logo Display: VMCs allow organizations to display their logos in email inboxes.

Key considerations

  • Standard Adherence: Ensure that the chosen VMC provider adheres to BIMI standards.
  • Acquisition Process: Understand the specific steps to acquire and implement a VMC from each provider.
  • Provider Options: Consider options from multiple providers like DigiCert, Entrust, and Sectigo.
Technical article

Documentation from Sectigo explains that a VMC (Verified Mark Certificate) is essential for BIMI implementation and outlines the steps to acquire and implement a VMC to display brand logos in supporting email clients.

August 2024 - Sectigo
Technical article

Documentation from Entrust describes their VMC (Verified Mark Certificate) offering for BIMI, emphasizing that their certificates help organizations display their logos in email inboxes. The Entrust Documentation explains their approach to providing VMCs and how they align with BIMI standards.

December 2024 - Entrust
Technical article

Documentation from DigiCert outlines the requirements for a Verified Mark Certificate (VMC), stating that it must be issued by a recognized Certificate Authority and meet specific standards to be valid for BIMI.

June 2022 - DigiCert