For AI agents: the complete documentation index is available at https://docs.ovhcloud.com/en/llms.txt, the full documentation bundle is available at https://docs.ovhcloud.com/en/llms-full.txt, and this page is available as Markdown at https://docs.ovhcloud.com/en/guides/web-cloud/email-and-collaborative-solutions/microsoft-exchange/feature-smime.md.

Signing and encrypting Exchange emails with S/MIME

View as Markdown

Find out how to publish your S/MIME certificate and sign and encrypt your Exchange emails in Outlook, the OWA webmail, iOS and Android

Objective

S/MIME adds two guarantees to your Exchange emails, using a personal certificate:

  • Encryption ensures that only the intended recipient can read the message. If the email is intercepted in transit, or if an unauthorised person gains access to it, its content stays unreadable.
  • Digital signature guarantees the sender's identity and the message's integrity. It proves that the email was sent by the expected sender, and that its content has not been altered in transit.

The two are independent: an email can be signed, encrypted, or both.

S/MIME relies on a certificate specific to each user, containing a public key and a private key. OVHcloud does not issue S/MIME certificates: you order yours for the primary email address of your Exchange account from a certificate authority (CA) such as Sectigo.

This guide explains how to publish your S/MIME certificate and how to sign and encrypt your emails in Outlook, in the OWA webmail, and on mobile devices.

Requirements

  • An S/MIME certificate issued for the primary email address of your Exchange account
  • Outlook for Windows installed and configured with your Exchange account
  • To encrypt an email: each recipient's certificate, which your email client retrieves from the Global Address List (GAL) — see the How encryption works section below
Warning

Start with Outlook, whichever client you plan to use. Publishing your certificate to the Exchange organisation can only be done from Outlook for Windows. Until that is done, the other users of your organisation cannot encrypt emails addressed to you or verify your signatures — and the other clients (OWA, iOS, Android) cannot be used for S/MIME.

How it works

How encryption works

Each user has a certificate containing a public key and a private key. When an encrypted email is sent:

  1. The email client retrieves the recipient's certificate, and therefore their public key.
  2. The message is encrypted with this public key.
  3. Once encrypted, the message is unreadable to any intermediary, including the Exchange server.
  4. Only the recipient can decrypt it, with their private key stored on their device.

This is why you must already have the recipient's certificate to encrypt an email to them.

Diagram of S/MIME encryption: the sender gets the recipient's public key from the Global Address List, encrypts the email, and only the recipient's private key can decrypt it

How the signature works

  1. The email client computes a fingerprint (hash) of the email content.
  2. This fingerprint is encrypted with the sender's private key: this forms the signature.
  3. The recipient's email client verifies the signature with the sender's public key, retrieved from their certificate published in the Exchange organisation.

Any modification of the message invalidates the signature.

Diagram of the S/MIME signature: the sender signs a fingerprint of the message with their private key, the recipient verifies it with the sender's public key, and any modification invalidates the signature

Instructions

Step 1: publishing your certificate from Outlook

Publishing your certificate makes it accessible within your Exchange organisation. The other users then retrieve it automatically to encrypt the emails they send you, and to verify the digital signature of the messages you send them. You can then use the other email clients.

Follow the 4 tabs below in order:

1. Trust Center
2. Import the certificate
3. Security settings
4. Publish to the GAL

Opening the Trust Center

  1. In Outlook, click File, then Options.

  2. In the left-hand list, select Trust Center, then click Trust Center Settings....

  3. Open the Email Security section.

Outlook Options window with Trust Center selected and the Trust Center Settings button

Your certificate is now published. In Outlook, you can sign and encrypt a message from the Options tab of the compose window, with Sign and Encrypt.

A signed and/or encrypted email indicates this in its header: a padlock icon (encryption) and a rosette icon (signature) on the right, and a Signed By line with the signing address.

Step 2: configuring your other clients

OWA webmail
iOS
Android

Finding the S/MIME options

From the OWA webmail, you can decrypt received emails and verify their signature, as well as sign and encrypt the messages you send. The S/MIME settings are in the OWA options, under Mail > S/MIME. That page lets you encrypt and digitally sign every message you send by default, and choose the certificate used for signing.

S/MIME settings page in the OWA options

Installing the S/MIME control

To read an encrypted email or verify a signature, you need a compatible browser with the S/MIME control installed and configured. The control ships as a browser extension.

If the control is missing, OWA displays a message with a direct download link for the control.

OWA warning that the digital signature was not verified because the S/MIME control is not installed

Declaring the webmail domain

Once the control is installed, open its settings and add your Exchange webmail domain to the trusted domains, then save.

Microsoft S/MIME control options with the Exchange webmail domain added to the trusted domains
Warning

The control does not work in the reading pane. Open the email in a dedicated window to use the S/MIME functions.

Limitations

  • To encrypt an email, you must already have the recipient's certificate.
  • Without a backup, losing the device or the certificates means losing access to encrypted emails. Keep a backup copy of your certificate in a safe place.
  • S/MIME is configured on each client separately. On mobile, the iOS Mail app supports it natively; on Android, use an email client that supports S/MIME for Exchange (see Step 2).
  • If a transport rule modifies the body of the email, the signed email is shown as an attachment in the recipient's Outlook.

Go further

Exchange - Configure your email account on Outlook for Windows

Using your email address from the Outlook Web App (OWA) webmail

Configuring two-factor authentication on an Exchange account

Join our community of users.

Was this page helpful?