Email signing & encryption

Prove a message came from you — and encrypt it so only they can read it

Email was designed with no way to prove who sent a message. An S/MIME certificate adds the proof — a signature your recipient can check, and encryption only they can undo.

  • Nobody can send mail as youThe fake will not carry your signature, and your recipient will see that it does not.
  • Only the recipient can read itEncrypted end to end. Not your mail provider, not anyone with the server backups.
  • Log in without a passwordThe same certificate authenticates you to VPNs, intranets and admin panels.
  • Working this afternoonClick a link in your inbox and it is issued. Recipients install nothing.
4.3 out of 5 from 223 published reviews on the certificates below — unedited, and on their own product pages

Issued by publicly trusted certificate authorities — your recipient’s mail client verifies the signature with nothing installed

  • Comodo
  • Sectigo
  • Certum
  • We do not issue it — they doThe certificate authority signs your certificate, not us. Identical file, identical trust in every mail client, lower price.
  • Lowest price guaranteeFind the same certificate cheaper anywhere else and we match it. Tell us where you saw it.
  • We tell you before you buyEmail signing certificates cannot be refunded once issued, so we would rather talk you out of the wrong one first. Ask us and we will say which level you actually need. Read the policy.
  • Free set-up help from engineersCollecting it, exporting the key backup, and turning signing on in Outlook, Apple Mail or Thunderbird.

The reason this is not optional any more

Every mail client on earth shows you a friendly name and an address in the From line, and neither is verified. Typing them is all it takes. The scam that follows is not clever and does not need to be: someone watches a mailbox long enough to learn who signs off payments, then sends one message, at the right moment, asking for a bank detail to be updated. Nothing in the message looks wrong, because nothing about it is wrong — it is a genuine email that simply is not from who it claims.

David Oseid.osei@acme-trading.co

Re: October remittance — updated bank details

Hi — before you run tomorrow’s payment run, our account has moved to the new facility. Details attached. Can you get this in before 4pm?

No signature · sender unverified
David Oseid.osei@acmetrading.com

Board pack for Thursday

Papers attached, and the revised forecast is in the second tab. Shout if anything looks off before I circulate it wider.

Signed by d.osei@acmetrading.com

Two messages, one afternoon, from the same name. The difference is one character in the domain and one thing the reader cannot see: only the second carries a signature the mail client could check. With signing turned on across the team, the first one stands out on its own.

  • Your domain protections do not travel with the messageSPF, DKIM and DMARC check the server that handed the mail over. They are invisible to the person reading it, they say nothing about which human wrote it, they do not survive most forwarding, and they do nothing at all when the attacker registers a lookalike domain of their own — which is what they do.
  • The finance team cannot tell, and it is not their faultTraining people to spot a message with no visible tell is not a control. A signature is: it is either present and valid, or it is not, and the mail client makes that judgement rather than the reader.
  • The confidential half of the problem is quieterOrdinary mail sits in readable form on every server it crosses, in every backup taken of them, and in the recipient’s mailbox for years. TLS protects the hop, not the message. One mailbox breach later, all of it is readable at once.
  • Afterwards, you have to prove what you sentDisputes over what was agreed, and when, are settled by evidence. An unsigned email is an assertion. A signed one carries cryptographic proof of author and of the fact that not one character has been altered since.

What it costs to be wrong once, against what it costs not to be

The FBI’s Internet Crime Complaint Centre logged 21,489 business email compromise reports in 2023, with adjusted losses of $2.9 billion in the United States alone — an average of roughly $135,000 for every incident reported.

Average loss per reported incident, 2023$135,000
Signing 25 mailboxes for a year, at our cheapest certificate$298.75

Figures: FBI IC3 Internet Crime Report 2023, and the IC3 public service announcement of 11 September 2024, which put worldwide exposed losses at $55.49 billion between October 2013 and December 2023. The comparison bar is drawn to scale.

Three guarantees, one file

A certificate is not a security product you have to operate. It is a small file you install once, after which your mail client does all three of these on every message without being asked again.

  • Authenticity

    The signature can only have been produced by the private key that lives on your device, and that key never leaves it. A recipient’s mail client checks the signature against the certificate authority’s root and shows a result. There is nothing for them to judge and nothing for them to install.

    Answers: did this really come from you?
  • Integrity

    The signature covers the message and its attachments. Change a digit in an account number, a figure in a spreadsheet or a word in a contract anywhere between you and the reader, and the signature stops verifying. There is no way to alter signed mail quietly.

    Answers: is this exactly what you sent?
  • Confidentiality

    Once someone holds your certificate they can reply encrypted, and only your private key opens the result. Not the mail provider, not the server administrator, not whoever eventually gets hold of the backups. This is the part that satisfies most written confidentiality obligations.

    Answers: who else could ever read it?

What actually happens when you press send

Worth two minutes, because it explains both why the recipient needs nothing installed and why losing your key is the one mistake that cannot be undone.

  1. 1

    Your key signs it

    Your mail client takes a fingerprint of the message and encrypts that fingerprint with the private key held on your device. That is the signature. The message itself is unchanged.

  2. 2

    The certificate travels with it

    Your certificate goes out attached to the message. It contains your public key and the address, name or company the authority checked before issuing it.

  3. 3

    Their client checks it

    The public key undoes the fingerprint, and it is compared with a fresh fingerprint of the message as received. Match, and nothing was altered. Then the certificate is traced back to its root.

  4. 4

    They can reply encrypted

    Having received one signed message, their client now holds your public key. Anything they encrypt with it can be opened by your private key and by nothing else.

This is why S/MIME works with everyone rather than only with people who also bought something: the recipient needs no certificate, no account, no plug-in and no instructions. Every mainstream mail client — Outlook, Apple Mail, Thunderbird, iOS and Android — already trusts these certificate authorities and does the checking silently.

Do you actually need one? Here is the honest test

We would rather you bought nothing than bought the wrong thing. If none of the following is true of you, an email certificate is a nicety and you can close this page. If two or more are true, it is the cheapest control on your risk register.

  • Somebody in your organisation can change bank details or release a payment on the strength of an email
  • You send personal, financial, medical or legal data to people outside your own network
  • A regulator, insurer or customer contract requires encryption of data in transit — GDPR Article 32, HIPAA, or an ISO 27001 statement of applicability
  • You have already had, or narrowly avoided, an invoice-redirection or impersonation attempt
  • Your signature on a message needs to mean something afterwards — instructions, approvals, filings, professional advice
  • You want staff to reach an intranet, VPN or admin panel without another password to phish
  • Your name or brand is worth impersonating, and a lookalike domain is a plausible attack
  • You are asked to prove a message was authorised by the company, not merely sent from it

Where to start if you are unsure: put a mailbox-validated certificate on the three people who authorise money — usually the finance mailbox, whoever signs off invoices, and the director whose name gets impersonated. At our cheapest certificate that is $35.85 a year for all three. It changes nothing about how anybody works, and it removes the exact gap the invoice scam walks through. Widen it later if it earns its place.

Three levels — and the only thing that changes is what goes inside

Every certificate on this page uses the same cryptography and signs to the same standard. The price difference buys one thing: how much the certificate authority verifies before it writes your details into the file, and therefore how much a recipient can read out of it. The panels below show the actual subject line of the certificate at each level.

Mailbox validated

That you control the address

The authority emails a link to the address and you click it. Your address goes into the certificate; your name does not. That is enough to stop anyone signing as you, and enough to encrypt.

Inside the certificate

E
d.osei@acmetrading.com
CN
not verified at this level
O
not verified at this level
Issued in minutesNo documentsOne mailbox

Right for: Individuals, small teams, and anyone who wants signed and encrypted mail working today without paperwork.

Individual validated

That you are who you say you are

You prove your legal identity with government photo ID, and your verified full name is written into the certificate beside the address. A recipient sees a person they can check, not just a mailbox.

Inside the certificate

E
d.osei@acmetrading.com
CN
David Osei
O
not verified at this level
Photo ID checked1–3 working daysYour legal name inside

Right for: Professionals signing on their own authority — lawyers, accountants, consultants, doctors — and anyone whose counterparty reads the name on a signature.

Organisation validated

That you act for your company

Your identity is checked, and so is the company: that it legally exists, that its address is real, and that you are authorised to act for it. The registered company name goes into the certificate with your own.

Inside the certificate

E
d.osei@acmetrading.com
CN
David Osei
O
Acme Trading Limited
Company register checked1–3 working daysRegistered name inside

Right for: Anyone signing on the company’s behalf — contracts, tenders, purchase orders, regulatory filings — and organisations rolling certificates out to staff.

Every email certificate we sell, by what it proves

Inside each level the certificates are interchangeable in how they verify — a recipient cannot tell one authority from another in the result they see. What differs is the name on the invoice and the price, so buy on whichever of those matters to you.

Show prices for
Mailbox validated

That you control the address

Individuals, small teams, and anyone who wants signed and encrypted mail working today without paperwork.

  • Our pick Comodo CPAC

    CPAC Basic - Personal Authentication Signature

    The entry point to the CPAC range, and the one we sell most of. Mailbox validated, issued in minutes, and the cheapest certificate that keeps the upgrade path to Pro and Enterprise open.

    $16 $39 save 59% for 1 year
    $29 $69 save 58% for 2 years · $14.50/yr
    Full specification →
  • Certum

    Certum Basic ID Certificate

    The cheapest publicly trusted S/MIME certificate we sell. Verifies in every mainstream mail client exactly as the others do; what you give up is brand recognition, not trust.

    $11.95 $49 save 76% for 1 year
    $22.95 $89 save 74% for 2 years · $11.48/yr
    Full specification →
  • Sectigo

    Sectigo Secure Email Certificate

    The Sectigo-branded secure email certificate, off the same infrastructure as the Comodo one. Buy it when a policy document or purchase order names Sectigo.

    $24.99 $39 save 36% for 1 year
    $37.99 $69 save 45% for 2 years · $19/yr
    Full specification →
  • Comodo

    Comodo Secure Email Certificate

    The general-purpose Comodo email certificate: signing, encryption and client authentication in one, under the name most people search for.

    $24 $39 save 38% for 1 year
    $44 $69 save 36% for 2 years · $22/yr
    Full specification →
  • Comodo

    Comodo Email Digital Signature

    Comodo’s email signing certificate, aimed at people whose priority is a visible, verifiable signature on outbound mail.

    $24.99 for 1 year
    $37.99 for 2 years · $19/yr
    Full specification →
  • Sectigo

    Digital Signature Certificate for Email

    Sectigo email signing certificate — the product to quote when a compliance list names Sectigo rather than Comodo.

    $24.99 $29 save 14% for 1 year
    $42.99 $49 save 12% for 2 years · $21.50/yr
    Full specification →
  • Comodo CPAC

    Personal Digital Signature Certificate

    A Comodo mailbox certificate sold as a straight personal signing product: same validation, bundled a little differently.

    $19.99 $39 save 49% for 1 year
    $32.99 $69 save 52% for 2 years · $16.50/yr
    Full specification →
  • Certum

    Certum Email ID - Individual

    Certum’s individual mailbox certificate, a small step up from Basic ID in what is bundled with it.

    $15 $49 save 69% for 1 year
    $28 $89 save 69% for 2 years · $14/yr
    Full specification →
Individual validated

That you are who you say you are

Professionals signing on their own authority — lawyers, accountants, consultants, doctors — and anyone whose counterparty reads the name on a signature.

Organisation validated

That you act for your company

Anyone signing on the company’s behalf — contracts, tenders, purchase orders, regulatory filings — and organisations rolling certificates out to staff.

  • Our pick Comodo CPAC

    CPAC Enterprise - Sectigo CPAC Enterprise Certificate

    Full organisation validation on the Comodo range: your registered company name goes in alongside your own. The one to buy for contracts and tenders.

    $69 $79 save 13% for 1 year
    $119 $160 save 26% for 2 years · $59.50/yr
    Full specification →
  • Certum

    Certum Business ID

    Organisation validated at a price closer to most rivals’ individual tier — the value pick for company signing, and the sensible base for a rollout.

    $30.95 $99 save 69% for 1 year
    $49.95 $179 save 72% for 2 years · $24.98/yr
    Full specification →
  • Certum

    Certum Enterprise ID

    Certum’s full organisation-validated certificate, aimed at deployments across a whole company.

    $36 $119 save 70% for 1 year
    $64 $199 save 68% for 2 years · $32/yr
    Full specification →
Compare all 13 certificates side by side Both terms at once, every authority, with the assurance level against each
Certificate Brand 1 year 2 years
Mailbox validated — That you control the address
CPAC Basic - Personal Authentication Signature Comodo CPAC Details →
Certum Basic ID Certificate Certum Details →
Sectigo Secure Email Certificate Sectigo Details →
Comodo Secure Email Certificate Comodo Details →
Comodo Email Digital Signature Comodo Details →
Digital Signature Certificate for Email Sectigo Details →
Personal Digital Signature Certificate Comodo CPAC Details →
Certum Email ID - Individual Certum Details →
Individual validated — That you are who you say you are
CPAC Pro - Sectigo Personal Authentication Pro Certificate Comodo CPAC Details →
Certum Professional ID (S/MIME) Certum Details →
Organisation validated — That you act for your company
CPAC Enterprise - Sectigo CPAC Enterprise Certificate Comodo CPAC Details →
Certum Business ID Certum Details →
Certum Enterprise ID Certum Details →

This is not SPF, DKIM or DMARC — and it is not a disclaimer

Almost everyone arriving here already has the domain-level records in place and has been told that means their email is protected. It does not mean that, and the difference is the reason invoice fraud still works against organisations with a perfect DMARC report.

  SPF, DKIM and DMARC S/MIME certificate
What is being verifiedThe server that handed over the message, and the domain it claimed.The individual person who wrote it, and every byte of what they wrote.
Who sees the resultThe receiving mail server. Nothing is shown to the reader.The reader, in their own mail client, on every message.
Survives forwardingOften not — forwarding commonly breaks the check.Yes. The signature is part of the message and travels with it.
Stops a lookalike domainNo. The attacker’s own domain passes its own records perfectly.Yes. They cannot produce your signature from any domain.
Encrypts the message itselfNo. TLS protects a hop; the message rests in readable form at both ends.Yes, end to end, readable only by the holder of the private key.
Proof afterwardsA server log, if anyone kept one.Cryptographic proof of author and content, in the message itself.
What it is forStopping bulk spoofing of your domain and protecting deliverability.Proving a particular human sent a particular message, and hiding it from everyone else.

If what you actually need is a PDF signature Adobe trusts

This is the mistake that costs people money, so it is worth two minutes. Every certificate above can sign a PDF, and the signature is cryptographically real. But Adobe Reader will still show “At least one signature has problems”, because Adobe trusts its own list of certificate authorities — the Adobe Approved Trust List — and personal S/MIME certificates are not on it. If a client, a court or a regulator has to open your document and see a clean green tick with nothing configured at their end, you need a document signing certificate instead.

  • On the Adobe Approved Trust List — verifies cleanly in Reader and Acrobat with no set-up at the other end
  • Long-term validation, so the signature still verifies years after the certificate itself has expired
  • Supplied on a hardware token or in an HSM, as the current requirements demand
  • Signs Microsoft Office documents to the same standard

PDF Signing Certificate (Adobe Digital Signature)

$299 for 1 year
$498 for 2 years · $249/yr

Getting it working

The certificate arrives as a file you install once. The step people get stuck on is not installation — it is realising that the private key is the certificate, and that it was generated on the machine you ordered from.

  1. Order and validate

    A validation link arrives at the address the certificate will carry. Mailbox-validated certificates are issued the moment you click it; the higher levels add a document check.

    Minutes to 3 days
  2. Collect it in the same browser

    Collect the certificate in the browser you started the order in, because that is where the private key was generated. Collect it somewhere else and there is no key waiting to pair with it.

    5 minutes
  3. Export a PKCS#12 backup

    Export it as a .pfx or .p12 file with the private key, set a strong password, and store it somewhere durable. This one file is what you install on the laptop, the phone and the mail client.

    5 minutes
  4. Turn signing on by default

    Outlook, Apple Mail and Thunderbird each have a security setting where you choose the certificate and tick sign-every-message. Doing it by default is what makes an unsigned message from you look wrong.

    10 minutes

Read this before you order

Two years is the longest anyone can legitimately sell you

Under the CA/Browser Forum’s S/MIME Baseline Requirements, in force since 1 September 2023, publicly trusted S/MIME certificates are capped at 825 days. The profile that allowed longer has been withdrawn by the authorities themselves. If a reseller is still offering a three-year email certificate, they are selling something that cannot be issued. We removed ours.

Lose the private key and the encrypted mail goes with it

Encrypted messages can only be opened by the key they were encrypted to. Replacing a lost or expired certificate does not recover them, because the new key is a different key. Export the PKCS#12 backup on the day you get the certificate, and keep it after expiry — an expired key still decrypts old mail even though it can no longer sign new.

The certificate belongs to one address

It carries the mailbox it was issued to. A second address, a shared team mailbox or an alias needs its own certificate. If you change employer, or your surname changes, the certificate cannot be edited — you order a new one.

Signing is not the same as Adobe trusting the signature

Worth repeating because it is the most expensive misunderstanding on this subject. A personal certificate produces a valid PDF signature that Adobe Reader will still flag, because the issuer is not on the Adobe Approved Trust List. Only a document signing certificate clears that.

Questions we get asked before people order

Which one should I actually buy?

For most people, a mailbox-validated certificate, and CPAC Basic is the one we sell most of — issued in minutes, and on a range that runs up to organisation validation if you need that later. Go straight to the individual level if a counterparty has to see your verified name inside the certificate, or the organisation level if they have to see your company’s. Go to Certum if price is genuinely the deciding factor: it is the same public trust for about a third of the money.

Do the recipients need anything installed?

No, and this is the single most useful thing about S/MIME. Every mainstream mail client already trusts these certificate authorities and verifies your signature automatically. For someone to send you encrypted mail they need your public key, which they get simply by receiving one signed message from you — most clients pick it up silently and offer encryption from then on.

We already have SPF, DKIM and DMARC. Is that not the same thing?

No, and the difference is the reason invoice fraud still works against organisations with clean DMARC reports. Those records authenticate the sending domain to the receiving server; they are invisible to the person reading the message, they frequently break on forwarding, and they are no obstacle at all to an attacker who registers a lookalike domain and configures it properly. S/MIME authenticates the human and the content, and shows the result to the reader. They solve different problems and you want both.

What is the difference between the Comodo and the Sectigo certificates here?

Technically nothing worth paying for either way: Comodo CA was renamed Sectigo in 2018, so both come off the same infrastructure, from the same certificate authority, and verify identically everywhere. We list both because the names are searched and specified differently — buy the Sectigo one when a policy document, a procurement list or an auditor names Sectigo, and the Comodo one otherwise.

Can I use it on my phone as well as my laptop?

Yes, on as many of your own devices as you like, at no extra cost. Install the same PKCS#12 backup file on each. iOS takes it as a configuration profile and Android through the security settings; both then sign and encrypt from the built-in mail app.

Can I mix brands and levels across a team?

Yes. Nothing about S/MIME requires everyone in an organisation to hold a certificate from the same authority, and signatures verify across them with no configuration. A common and sensible pattern is a cheap mailbox certificate for general staff and an organisation-validated one for the few people who sign contracts.

Is a two-year certificate better value than one year?

Usually, and the term switch shows you by how much per year. The argument for a single year is that a certificate cannot be edited: if your address, your surname or your employer might change inside two years, the shorter term costs less than a wasted one.

What happens when it expires?

Signatures you made while it was valid stay valid — that is what timestamping is for. You order a fresh certificate and install it. Keep the old key file even so: you still need it to read encrypted mail that was sent to the old certificate.

Does it work with Microsoft 365 or Google Workspace?

Yes. S/MIME is a property of the message rather than of the mail platform, so it works through any provider. Outlook on Windows, Mac and mobile supports it directly. Gmail’s web client supports S/MIME on Workspace Enterprise plans, and on other plans you sign from a desktop or mobile client such as Outlook, Apple Mail or Thunderbird instead.

What if I collect it on the wrong machine?

Tell us before you do anything else. Collection generates the key in the browser you collect from, so collecting on the wrong machine is the usual cause of a certificate that will not import anywhere. It is fixable, and it is very much easier to fix on the day than a month later.

Looking for something next to this?

Email signing is one of three things people mean by “a signing certificate”. These are the other two, and the certificate for the server your mail passes through.

Tell us who has to trust the signature

That one sentence is usually enough for us to name the cheapest certificate that satisfies them — and to tell you when the answer is a mailbox certificate for two people rather than a rollout. No obligation and no sales call.