DigiCert S/MIME Email Certificates — from 8,90 € a Year
Signing and encryption of mail from DigiCert: the recipient sees that the message really came from your address and was not altered on the way
Buy an email certificate for 8,90 €
An S/MIME certificate signs and encrypts email: the recipient sees that the message really came from your address and was not altered on the way, and the contents of an encrypted message can be read by the addressee alone. It is issued for a mailbox address, not for a domain — the authority sends a message with a link, and following that link confirms the mailbox is yours. It works in Outlook, Apple Mail on macOS and iOS, Thunderbird and most corporate clients; support in webmail interfaces is limited. The price starts at €8.90 a year and the catalogue holds five options: for individuals, for employees and for organizations.
Certificates for email
Five options: for private individuals, for employees and for organizations
| Certificate | Validation and issuance | What it secures | Warranty | Price | |
|---|---|---|---|---|---|
| DigiCert Secure Email for Individuals (S/MIME Class 1) DigiCert |
— | One domain and its www | — |
€8.9
per year | Order |
| Comodo Personal Authentication Basic Certificate Sectigo |
— | One domain and its www | — |
€10.9
per year | Order |
| Comodo Personal Authentication Pro Certificate Sectigo |
— | One domain and its www | — |
€26.9
per year | Order |
| DigiCert Secure Email for Business (Premium) DigiCert |
— | One domain and its www | — |
€32.9
per year | Order |
| Comodo Personal Authentication Enterprise Certificate Sectigo |
— | One domain and its www | — |
€33.9
per year | Order |
The certificate is issued for a mailbox address, not for a domain: ownership of the mailbox is what gets validated.
What S/MIME gives you
Three jobs an email certificate does
Message signature
The recipient sees that the message was sent from your address and was not altered on the way.
Encrypted correspondence
Only the addressee can read the contents — even if the mail server itself is compromised.
Protection against forged mail
Signed messages are harder to fake: an attacker would need the private key, not just a look-alike address.
How it works
Set up once in your mail client
Order and address validation
The authority sends a message with a link to the mailbox you named — following it confirms that the address is yours.
Issuance and installation
You receive the certificate file with the key and install it in Outlook, Apple Mail, Thunderbird or the system keychain.
Signing messages
You switch signing on in the mail client, and from then on messages are signed automatically.
Key exchange for encryption
To encrypt mail both sides exchange signed messages first: that is how their clients learn each other's public keys.
Who needs this
- Companies whose name gets used by scammers. Signed messages are distinguishable from fakes.
- Accountants and lawyers who send documents and payment details by mail.
- Remote employees who need encrypted correspondence over untrusted networks.
- Anyone bound by policy: in several industries email signing is part of the security requirements.
Frequently asked questions about S/MIME
Issuance, installation and compatibility
For one specific mailbox address. Several mailboxes need separate certificates, or a corporate product line.
Outlook, Apple Mail on macOS and iOS, Thunderbird and most corporate clients. Support in webmail interfaces is limited.
DKIM signs messages on the server side and protects the whole domain. S/MIME signs a specific message on behalf of a person.
They will read a signed message as usual, sometimes with a signature attachment. An encrypted message cannot be sent to someone without a certificate.
As a rule one or two years, depending on the product line. Renewal goes through the same mailbox validation.
Export the certificate together with its private key into a PFX file and install that file on the new device.
For PDF and office files there are separate document signing certificates — they are in the document signing section.
Encrypted messages become unreadable, because the key cannot be recovered. Keep a backup copy of the PFX file.