Is Your S/MIME certificate compliant?

Use our certificate checker to compare your S/MIME certificate against the new CA/Browser Forum’s S/MIME Baseline Requirements.

Drag and drop Certificate or browse to upload a file

Upload a DER or PEM file type no more than 3 KB in size

Protect more than your certificate

 

S/MIME compliance is one part of a broader email trust strategy. Whether you need to stop domain spoofing, sign and encrypt sensitive messages, or display your verified logo in the inbox, DigiCert can help you build trust across every email touchpoint.

Stop email spoofing with DMARC enforcement

Gain visibility into who is sending from your domains, identify unauthorized senders, and move toward DMARC enforcement to help prevent phishing and domain spoofing.

Explore Messaging Trust

Sign and encrypt email with S/MIME certificates

Protect sensitive communications with S/MIME certificates that help verify sender identity, preserve message integrity, and encrypt email content.

Buy S/MIME Certificates

Display your verified logo with Mark Certificates

Use a DigiCert Mark Certificate with BIMI to show your approved brand logo in Google and Apple inboxes.

Buy Mark Certificates

Frequently asked questions

How do I get an S/MIME certificate? +
You can get an S/MIME certificate from DigiCert to digitally sign and encrypt email communications, verify sender identity, and protect sensitive messages.
What is PKI? +
Public key infrastructure (PKI) is a system of processes, technologies and policies that allows you to encrypt and sign data. You can issue digital certificates that authenticate the identity of users, devices, or services. In S/MIME, public PKI is used to issue public TLS/SSL certificates, a type of digital certificate for public domains or web servers that can be viewed and logged publicly.
Can I run the S/MIME linter on my local computer? +
To perform the S/MIME certificate check on your local computer, download the open-source certificate linter on GitHub.
What are the S/MIME Baseline Requirements? +
On January 1, 2023, the CA/Browser Forum released the Baseline Requirements for the Issuance and Management of Publicly‐Trusted S/MIME Certificates, a set of standards governing the way certificate authorities (CAs) like DigiCert issue S/MIME digital certificates. The Baseline Requirements apply to all publicly trusted digital certificates that include:
  • The Extended Key Usage (EKU) extension for id-kp-emailProtection (OID: 1.3.6.1.5.5.7.3.4).
  • An email address (as rfc822Name or otherName of type id-on-SmtpUTF8Mailbox) in the subjectAltName extension.
What file types does the S/MIME linter accept? +
The S/MIME linter accepts DER and PEM certificate files up to 3 KB. It does not accept .cer, .crt, or other certificate file formats.

Learn how DigiCert can help you build email trust

 

By supplying my information and clicking submit, I agree to receive communications about DigiCert products and services, and I agree to DigiCert and its affiliates processing my data in accordance with DigiCert’s Privacy Policy.