How S/MIME works
- You get a certificate. A certificate authority, or your employer’s own one, confirms you control an email address and issues a certificate holding your public key.2 The matching private key stays with you.
- You sign. Your mail app signs outgoing messages with your private key and attaches your certificate. The recipient’s app checks the signature and that the certificate chains back to an authority it trusts.
- Others encrypt to you. Once someone has your certificate, usually from a signed message you sent them, their app can encrypt messages that only your private key opens.
Under the hood, S/MIME wraps the message in a format called Cryptographic Message Syntax. The current version, S/MIME 4.0, added authenticated encryption with AES-GCM and newer signature algorithms.1
S/MIME compared with PGP
| S/MIME | PGP | |
|---|---|---|
| Who vouches for a key | A certificate authority | The users themselves, by checking fingerprints or signing each other’s keys |
| What you need | A certificate for your email address | A key pair you create yourself |
| Standard | RFC 85511 | RFC 9580, OpenPGP3 |
The two don’t work together. A message protected with one has to be opened with the same one.
Why S/MIME matters
S/MIME answers two questions ordinary email leaves open: did this message really come from that person, and has anyone else been able to read it on the way? Because trust comes from a certificate authority, an organization can issue certificates to all its staff and have signing and encryption work without each person exchanging keys by hand.
What S/MIME leaves open
- It protects the message, not the envelope. Who wrote to whom, and when, stays visible to the mail servers that deliver it.
- Certificates expire. They have to be renewed, and old private keys kept, or older encrypted mail can no longer be opened.
- Both people need certificates before a message between them can be encrypted.
Where you’ll see S/MIME
- In mail apps. Many desktop and mobile mail apps, especially those used at work, have settings for S/MIME signing and encryption.
- As a small attachment. A signed message opened in an app without S/MIME support shows a file called smime.p7s. That file is the signature, and it is safe to ignore.
- As a badge or ribbon on signed mail, in apps that do support it.
Related terms
Sources
- IETF, RFC 8551: Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 4.0 Message Specification (April 2019).
- IETF, RFC 5280: Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile (May 2008).
- IETF, RFC 9580: OpenPGP (July 2024).
Checked October 2026.
Questions about S/MIME
What is the smime.p7s attachment in my email?
It is the digital signature of a message signed with S/MIME. Mail apps that support S/MIME use it to verify the sender and hide the file. Apps that don’t support it show it as an attachment. You don’t need to open it.
What is the difference between S/MIME and PGP?
Both encrypt and sign email, and they aren’t compatible. S/MIME relies on certificates issued by a certificate authority. PGP relies on keys that people create and verify themselves.
What is the difference between S/MIME and TLS?
TLS encrypts the connection between two servers, so each mail server on the way still handles the readable message. S/MIME encrypts the message itself, so it stays protected from the sender’s mail app to the recipient’s.
Do I need a certificate to use S/MIME?
Yes. To sign mail, or to receive encrypted mail, you need a certificate for your email address and its private key. To send someone an encrypted message, you need their certificate.
What is the difference between S/MIME and DKIM?
DKIM is a signature added by the sending domain’s mail server, checked automatically by the receiving server. S/MIME is a signature from an individual person’s certificate, checked by the recipient’s mail app, and it can also encrypt.