DigiCert S/MIME Email Certificates — from 8,90 € a Year

Signing and encryption of mail from DigiCert: the recipient sees that the message really came from your address and was not altered on the way

Buy an email certificate for 8,90 €
S/MIME certificate for signing and encrypting email

An S/MIME certificate signs and encrypts email: the recipient sees that the message really came from your address and was not altered on the way, and the contents of an encrypted message can be read by the addressee alone. It is issued for a mailbox address, not for a domain — the authority sends a message with a link, and following that link confirms the mailbox is yours. It works in Outlook, Apple Mail on macOS and iOS, Thunderbird and most corporate clients; support in webmail interfaces is limited. The price starts at €8.90 a year and the catalogue holds five options: for individuals, for employees and for organizations.

Certificates for email

Five options: for private individuals, for employees and for organizations

Certificate Validation and issuance What it secures Warranty Price
DigiCert Secure Email for Individuals (S/MIME Class 1)
DigiCert
One domain and its www 8.9
per year
Order
Comodo Personal Authentication Basic Certificate
Sectigo
One domain and its www 10.9
per year
Order
Comodo Personal Authentication Pro Certificate
Sectigo
One domain and its www 26.9
per year
Order
DigiCert Secure Email for Business (Premium)
DigiCert
One domain and its www 32.9
per year
Order
Comodo Personal Authentication Enterprise Certificate
Sectigo
One domain and its www 33.9
per year
Order

The certificate is issued for a mailbox address, not for a domain: ownership of the mailbox is what gets validated.

What S/MIME gives you

Three jobs an email certificate does

1

Message signature

The recipient sees that the message was sent from your address and was not altered on the way.

2

Encrypted correspondence

Only the addressee can read the contents — even if the mail server itself is compromised.

3

Protection against forged mail

Signed messages are harder to fake: an attacker would need the private key, not just a look-alike address.

How it works

Set up once in your mail client

1

Order and address validation

The authority sends a message with a link to the mailbox you named — following it confirms that the address is yours.

2

Issuance and installation

You receive the certificate file with the key and install it in Outlook, Apple Mail, Thunderbird or the system keychain.

3

Signing messages

You switch signing on in the mail client, and from then on messages are signed automatically.

4

Key exchange for encryption

To encrypt mail both sides exchange signed messages first: that is how their clients learn each other's public keys.

Who needs this

Who needs this

  • Companies whose name gets used by scammers. Signed messages are distinguishable from fakes.
  • Accountants and lawyers who send documents and payment details by mail.
  • Remote employees who need encrypted correspondence over untrusted networks.
  • Anyone bound by policy: in several industries email signing is part of the security requirements.
Your logo in email

Frequently asked questions about S/MIME

Issuance, installation and compatibility

For one specific mailbox address. Several mailboxes need separate certificates, or a corporate product line.

Outlook, Apple Mail on macOS and iOS, Thunderbird and most corporate clients. Support in webmail interfaces is limited.

DKIM signs messages on the server side and protects the whole domain. S/MIME signs a specific message on behalf of a person.

They will read a signed message as usual, sometimes with a signature attachment. An encrypted message cannot be sent to someone without a certificate.

As a rule one or two years, depending on the product line. Renewal goes through the same mailbox validation.

Export the certificate together with its private key into a PFX file and install that file on the new device.

For PDF and office files there are separate document signing certificates — they are in the document signing section.

Encrypted messages become unreadable, because the key cannot be recovered. Keep a backup copy of the PFX file.