Personal & Email Certificates · Comodo CPAC

Sign your email so nobody can send invoices in your name

Sign and encrypt your email so nobody can fake it — and nobody but the recipient can read it.

  • Nobody can send mail as youA signed message carries proof it came from your address and was not altered. The invoice-redirection scam falls apart, because the fake will not carry the signature.
  • Only the recipient can read itEnd-to-end encryption in Outlook, Apple Mail, Thunderbird and mobile. Not your mail provider, not anyone reading the server.
  • Log in without a passwordThe same certificate works as a client certificate for VPNs, intranets and admin panels — two-factor by key, not by SMS.
  • Working this afternoonClick a link in your inbox and it is issued. Recipients need nothing installed — every mainstream mail client already trusts it.

Publicly trusted certificate authorities — recipients verify your signature with nothing installed

  • Comodo
  • Sectigo
  • Certum
  • $16a year for our best seller
  • 59% offits list price of $39
  • Minutesto issue, mailbox validated
  • 14 certificatesfrom 3 authorities, all priced here

Three levels, one difference: how much the certificate authority checks before it issues.

  1. Mailbox validated Proves you control the address. Your email goes in the certificate, your name does not. Minutes
  2. Individual validated Adds your legal identity, checked against government photo ID, so your verified name goes in too. 1–3 working days
  3. Organisation validated Adds your company: that it exists and that you may act for it. The registered name goes in as well. 1–3 working days once documents are in

ComodoStart here

The complete range — mailbox, identity and organisation validated

Show prices for

The Comodo Personal Authentication Certificate is the product this page is named after, and it is still the one we sell most of. It is the only line here that covers all three assurance levels, which matters more than it sounds: you can put a $16 mailbox certificate on the whole team today and move the two people who sign contracts up to Pro or Enterprise later, on the same root, with the same install instructions and the same support desk.

  • The only full ladder on this page — move up a level without changing vendor
  • Comodo roots have been in every mainstream trust store since long before S/MIME was fashionable
  • CPAC Enterprise writes your registered company name into the certificate
  • Cheapest entry into a range that goes all the way up: $16 for a year
  • Most chosen Mailbox validated

    CPAC Basic - Personal Authentication Signature

    The entry point to the CPAC range. Mailbox validated, issued in minutes, and the cheapest certificate that keeps the upgrade path open.

    $16 $39 save 59% for 1 year
    $29 $69 save 58% for 2 years · $14.50/yr
  • Mailbox validated

    Personal Digital Signature Certificate

    Comodo mailbox certificate sold as a straight personal signing product — same validation, bundled a little differently.

    $19.99 $39 save 49% for 1 year
    $32.99 $69 save 52% for 2 years · $16.50/yr
  • Mailbox validated

    Comodo Secure Email Certificate

    The general-purpose Comodo email certificate: signing, encryption and client authentication in one.

    $24 $39 save 38% for 1 year
    $44 $69 save 36% for 2 years · $22/yr
  • Mailbox validated

    Comodo Email Digital Signature

    Comodo’s email signing certificate, aimed at people whose priority is a visible, verifiable signature on outbound mail.

    $24.99 for 1 year
    $37.99 for 2 years · $19/yr
  • Individual validated

    CPAC Pro - Sectigo Personal Authentication Pro Certificate

    Adds a checked government-ID identity, so your verified full name appears in the certificate, not just your address.

    $49 $59 save 17% for 1 year
    $79 $120 save 34% for 2 years · $39.50/yr
  • Organisation validated

    CPAC Enterprise - Sectigo CPAC Enterprise Certificate

    Full organisation validation: your registered company name goes in alongside yours. The one to buy for contracts and tenders.

    $69 $79 save 13% for 1 year
    $119 $160 save 26% for 2 years · $59.50/yr

Sectigo

The same certificate authority, under the name it uses today

Show prices for

Comodo CA was renamed Sectigo in 2018, so these come off the same infrastructure, from the same certificate authority, and verify identically. Buy them when a policy document or a purchase order names Sectigo, or when you already run Sectigo SSL and want one vendor on the invoice.

  • Identical trust and identical validation to the Comodo equivalents
  • The right answer when a policy or an auditor names Sectigo
  • The Adobe-trusted PDF signing certificate below is Sectigo too
  • Start here Mailbox validated

    Sectigo Secure Email Certificate

    The Sectigo-branded equivalent of the Comodo secure email certificate, off the same infrastructure.

    $24.99 $39 save 36% for 1 year
    $37.99 $69 save 45% for 2 years · $19/yr
  • Mailbox validated

    Digital Signature Certificate for Email

    Sectigo email signing certificate — the product to quote when a policy document names Sectigo.

    $24.99 $29 save 14% for 1 year
    $42.99 $49 save 12% for 2 years · $21.50/yr

CertumLowest cost

The budget route — publicly trusted, and about a third of the price

Show prices for

A Polish certificate authority whose roots sit in the same trust stores as everything above, so a recipient cannot tell the difference in how the signature verifies. What differs is commercial, not technical: prices start at $11.95 and support runs to Central European hours. If cost is the deciding factor, this is the cheapest publicly trusted way to do it.

  • Cheapest certificate on the page at $11.95 for a year
  • Publicly trusted — recipients verify it with nothing installed
  • Covers all three levels, so a budget rollout is not capped at mailbox
  • Sensible for volume: a whole department costs less than a few CPAC Pro
  • Cheapest here Mailbox validated

    Certum Basic ID Certificate

    The cheapest publicly trusted S/MIME certificate we sell. Mailbox validated, and it verifies in every mainstream mail client.

    $11.95 $49 save 76% for 1 year
    $22.95 $89 save 74% for 2 years · $11.48/yr
  • Mailbox validated

    Certum Email ID - Individual

    Certum’s individual mailbox certificate, a small step up from Basic ID in what is bundled with it.

    $15 $49 save 69% for 1 year
    $28 $89 save 69% for 2 years · $14/yr
  • Individual validated

    Certum Professional ID (S/MIME)

    Certum’s identity-validated certificate: photo ID checked, your verified name in the certificate.

    $29.95 $99 save 70% for 1 year
    $49.95 $179 save 72% for 2 years · $24.98/yr
  • Organisation validated

    Certum Business ID

    Organisation validated at a price closer to most rivals’ individual tier — the value pick for company signing.

    $30.95 $99 save 69% for 1 year
    $49.95 $179 save 72% for 2 years · $24.98/yr
  • Organisation validated

    Certum Enterprise ID

    Certum’s full organisation-validated certificate, aimed at rollouts across a company.

    $36 $119 save 70% for 1 year
    $64 $199 save 68% for 2 years · $32/yr

If what you actually need is a PDF signature Adobe trusts

This is the mistake that costs people money on this page, so it is worth two minutes. Every certificate above can sign a PDF — the signature is cryptographically real and it will verify. But Adobe Reader will still show “At least one signature has problems”, because Adobe trusts its own list of certificate authorities, the Adobe Approved Trust List, and personal S/MIME certificates are not on it. If a client, a court or a regulator has to open your PDF and see a clean green tick without configuring anything, you need a Document Signing certificate.

  • On the Adobe Approved Trust List — verifies cleanly in Reader and Acrobat with no setup at the other end
  • Long-term validation, so the signature still verifies years after the certificate expires
  • Supplied on a hardware token or in an HSM, as the requirements demand
  • Signs Microsoft Office documents to the same standard
SECTIGO

PDF Signing Certificate (Adobe Digital Signature)

$299 for 1 year
$498 for 2 years · $249/yr
Compare all 14 certificates side by side Both terms at once, every brand, with the assurance level against each

Any price is a buy button — it opens the same order card as the product page, with that term already chosen.

Certificate Validates 1 year 2 years
Comodo — The complete range — mailbox, identity and organisation validated
CPAC Basic - Personal Authentication Signature Mailbox validated Details →
Personal Digital Signature Certificate Mailbox validated Details →
Comodo Secure Email Certificate Mailbox validated Details →
Comodo Email Digital Signature Mailbox validated Details →
CPAC Pro - Sectigo Personal Authentication Pro Certificate Individual validated Details →
CPAC Enterprise - Sectigo CPAC Enterprise Certificate Organisation validated Details →
Sectigo — The same certificate authority, under the name it uses today
Sectigo Secure Email Certificate Mailbox validated Details →
Digital Signature Certificate for Email Mailbox validated Details →
Certum — The budget route — publicly trusted, and about a third of the price
Certum Basic ID Certificate Mailbox validated Details →
Certum Email ID - Individual Mailbox validated Details →
Certum Professional ID (S/MIME) Individual validated Details →
Certum Business ID Organisation validated Details →
Certum Enterprise ID Organisation validated Details →
Document signing — Adobe Approved Trust List
PDF Signing Certificate (Adobe Digital Signature) Organisation validated Details →

What one of these certificates actually does

  • Signs your email

    Recipients get a visible confirmation the message came from your address and was not altered on the way. It is the practical answer to someone spoofing your address in an invoice-redirection scam, because the fake will not carry the signature.

  • Encrypts email end to end

    Once someone has your signed message they hold your public key and can reply encrypted. Only your private key opens it — not your mail provider, not anyone reading the server. This is the part that satisfies most confidentiality obligations.

  • Logs you in without a password

    The same certificate works as a client certificate for VPNs, intranets and admin panels that ask for one. Two-factor by possession of the key rather than by SMS.

  • Signs documents, with one caveat

    It signs Word, Excel and PDF files, and those signatures are real. For a PDF that Adobe Reader trusts out of the box you want the Document Signing certificate instead — see the section above.

Getting it working

The certificate arrives as a file you install once. The step people get stuck on is not installation — it is realising the private key is the certificate.

  1. Order and validate

    You get a validation link at the address the certificate will carry. Mailbox-validated certificates are issued as soon as you click it; the identity and organisation levels add a document check.

    Minutes to 3 days
  2. Collect it in a browser

    You collect the certificate in the same browser you started in, because that is where the private key was generated. Use a different machine and the key is not there to pair with it.

    5 minutes
  3. Export a PKCS#12 backup

    Export it as a .pfx or .p12 file with the private key, set a strong password and store it somewhere safe. This is the file you install on your phone, your laptop and your mail client.

    5 minutes
  4. Turn it on in your mail client

    Outlook, Apple Mail and Thunderbird each have a security setting where you pick the certificate and choose whether to sign every message by default. We will walk you through yours.

    10 minutes

Read this before you order

Two years is now the longest term anyone can sell you

Under the CA/Browser Forum’s S/MIME Baseline Requirements, in force since 1 September 2023, publicly trusted S/MIME certificates are capped at 825 days. The one profile that allowed longer has been withdrawn by the certificate authorities. If a reseller is still offering you a three-year email certificate, they are selling something that cannot be issued. We removed ours.

Lose the private key and you lose the encrypted mail with it

Encrypted messages can only be opened by the key they were encrypted to. Replacing an expired or lost certificate does not recover them, because the new key is a different key. Export the PKCS#12 backup on the day you get the certificate and keep it after the certificate expires — an expired key still decrypts old mail even though it can no longer sign new.

The certificate belongs to one address

It carries the mailbox it was issued to. A second address, a shared team mailbox or an alias needs its own certificate. If you change employer or your address changes, the old certificate cannot be edited — you order a new one.

Signing is not the same as Adobe trusting the signature

Worth repeating because it is the most common and most expensive misunderstanding on this page. A personal certificate produces a valid PDF signature that Adobe Reader will still flag, because the issuer is not on the Adobe Approved Trust List. Only a Document Signing certificate clears that.

Questions we get asked about this

Which one should I actually buy?

For most people, Comodo CPAC Basic. It is $16 for the year, it is issued in minutes, and because the CPAC range runs all the way up to organisation validation you can move to Pro or Enterprise later without changing vendor or re-learning the process. Go straight to CPAC Pro or Enterprise if someone on the other side has to see your verified name, or your company’s, inside the certificate. Go to Certum if the price is genuinely the deciding factor.

What is the difference between the Comodo and Sectigo certificates here?

Technically nothing worth paying for either way: Comodo CA was renamed Sectigo in 2018, so both come from the same certificate authority and verify identically everywhere. We list Comodo first because the CPAC range covers all three assurance levels while the Sectigo listings here cover mailbox validation only. Buy the Sectigo one when a policy document, a procurement list or an auditor names Sectigo, or when you already buy Sectigo SSL and want one vendor on the invoice.

Is Certum worth the saving, or am I buying something weaker?

You are not buying weaker cryptography or weaker trust. Certum is a publicly trusted certificate authority in the same mail-client and browser trust stores, and a recipient cannot tell the difference in how the signature verifies. What you give up is at the commercial end — validation and support run to Central European hours, and it is a smaller brand to put in front of a compliance reviewer. If cost is the deciding factor, or you are signing a whole department, it is the sensible choice. If a counterparty is going to read the issuer name, buy Comodo.

Is a two-year certificate better value than one year?

Usually, and the table shows you by how much per year. The argument for a single year is that the certificate cannot be edited: if your address, surname or employer might change inside two years, a shorter term costs less than a wasted one.

Do the recipients need anything installed?

No. Every mainstream mail client already trusts these certificate authorities and verifies your signature automatically. For someone to send you encrypted mail they need your public key, which they get simply by receiving one signed message from you — most clients pick it up silently.

Can I use it on my phone as well as my laptop?

Yes, on as many of your own devices as you like. Install the same PKCS#12 backup file on each. iOS and Android both accept it — iOS installs it as a configuration profile, Android through the security settings.

Can I mix brands across a team?

Yes. Nothing about S/MIME requires everyone in an organisation to hold a certificate from the same authority, and signatures verify across them without configuration. A common pattern is Certum for general staff mailboxes and CPAC Pro or Enterprise for the few people who sign contracts.

What happens when it expires?

Signatures you made while it was valid stay valid — that is the point of timestamping. You order a fresh certificate and install it. Keep the old key file: you still need it to read encrypted mail sent to the old certificate.

Can I get it reissued if I install it on the wrong machine?

Tell us before you do anything else. Collection generates the key in the browser you collect from, so collecting on the wrong machine is the usual cause of a certificate that will not import anywhere. It is fixable, and it is much easier to fix on the day than a month later.

Not sure which level you need?

Tell us who has to trust the signature and what they have to see in it, and we will tell you the cheapest certificate that satisfies them — before you spend anything.

help@sslretail.com