This article describes how outgoing emails are signed via the Hornetsecurity Encryption Service and how to identify whether an incoming message has been signed.
Requirements
Two conditions must be met for outgoing signatures:
- The Hornetsecurity Encryption Service is subscribed to.
- A valid S/MIME certificate is stored in the system for the sender.
Outgoing Signature
As a SecureGateway, Hornetsecurity manages the signatures automatically. If you use a valid S/MIME certificate via the Hornetsecurity Encryption Module, your emails are automatically sent signed for the certificate owner.
If necessary, you can disable signing at any time, either permanently or for individual emails:
- Permanently: Remove the check mark for “S/MIME Signature” in the Control Panel under Security Settings ⇾ Email Encryption ⇾ S/MIME Users.
- Once for an email: Write the keyword “NOSIGN” anywhere in the subject of the email that should not be signed.
Incoming Signature
You can usually see directly in your email client whether an incoming email is signed. Where the signature is displayed depends on the respective manufacturer. However, every signed email includes a .p7m file as an attachment in which the signature is stored. For details on how it is displayed in your client, please contact its manufacturer.
Checking via the Control Panel
Regardless of the direction of the email, you can use the Control Panel to check whether an email was signed:
- Log in to the Control Panel.
- Search for the relevant email using Email Live Tracking.
- Check the email header. If the signature was successful, you will find the entry
X-antispameurope-crypt: smime/cryptedthere.