What is S/MIME?

S/MIME (Secure/Multipurpose Internet Mail Extensions) is a standard for encrypting and digitally signing email with certificates. A certificate authority issues each person a certificate that ties their email address to a public key. Mail apps use it to encrypt messages to that person and to check that signed messages really came from them.

Also called: Secure/Multipurpose Internet Mail Extensions, S/MIME certificate, email certificate

Updated October 2026. Sources are numbered and listed at the end.

On this page

How S/MIME works

  1. You get a certificate. A certificate authority, or your employer’s own one, confirms you control an email address and issues a certificate holding your public key.2 The matching private key stays with you.
  2. You sign. Your mail app signs outgoing messages with your private key and attaches your certificate. The recipient’s app checks the signature and that the certificate chains back to an authority it trusts.
  3. Others encrypt to you. Once someone has your certificate, usually from a signed message you sent them, their app can encrypt messages that only your private key opens.

Under the hood, S/MIME wraps the message in a format called Cryptographic Message Syntax. The current version, S/MIME 4.0, added authenticated encryption with AES-GCM and newer signature algorithms.1

S/MIME compared with PGP

Two standards with the same goal and different ways of establishing trust.
S/MIMEPGP
Who vouches for a keyA certificate authorityThe users themselves, by checking fingerprints or signing each other’s keys
What you needA certificate for your email addressA key pair you create yourself
StandardRFC 85511RFC 9580, OpenPGP3

The two don’t work together. A message protected with one has to be opened with the same one.

Why S/MIME matters

S/MIME answers two questions ordinary email leaves open: did this message really come from that person, and has anyone else been able to read it on the way? Because trust comes from a certificate authority, an organization can issue certificates to all its staff and have signing and encryption work without each person exchanging keys by hand.

What S/MIME leaves open

  • It protects the message, not the envelope. Who wrote to whom, and when, stays visible to the mail servers that deliver it.
  • Certificates expire. They have to be renewed, and old private keys kept, or older encrypted mail can no longer be opened.
  • Both people need certificates before a message between them can be encrypted.

Where you’ll see S/MIME

  • In mail apps. Many desktop and mobile mail apps, especially those used at work, have settings for S/MIME signing and encryption.
  • As a small attachment. A signed message opened in an app without S/MIME support shows a file called smime.p7s. That file is the signature, and it is safe to ignore.
  • As a badge or ribbon on signed mail, in apps that do support it.

Sources

  1. IETF, RFC 8551: Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 4.0 Message Specification (April 2019).
  2. IETF, RFC 5280: Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile (May 2008).
  3. IETF, RFC 9580: OpenPGP (July 2024).

Checked October 2026.

Questions about S/MIME

What is the smime.p7s attachment in my email?

It is the digital signature of a message signed with S/MIME. Mail apps that support S/MIME use it to verify the sender and hide the file. Apps that don’t support it show it as an attachment. You don’t need to open it.

What is the difference between S/MIME and PGP?

Both encrypt and sign email, and they aren’t compatible. S/MIME relies on certificates issued by a certificate authority. PGP relies on keys that people create and verify themselves.

What is the difference between S/MIME and TLS?

TLS encrypts the connection between two servers, so each mail server on the way still handles the readable message. S/MIME encrypts the message itself, so it stays protected from the sender’s mail app to the recipient’s.

Do I need a certificate to use S/MIME?

Yes. To sign mail, or to receive encrypted mail, you need a certificate for your email address and its private key. To send someone an encrypted message, you need their certificate.

What is the difference between S/MIME and DKIM?

DKIM is a signature added by the sending domain’s mail server, checked automatically by the receiving server. S/MIME is a signature from an individual person’s certificate, checked by the recipient’s mail app, and it can also encrypt.

Email that’s ready for what comes next.

Post-quantum encryption on every plan, free included.

Start free

Explore Secria Mail