
Email is the most widely used means of communication in businesses – and, at the same time, one of the least secure. Every day, forged sender addresses, manipulated content and intercepted messages are used as attack vectors. S/MIME is one of the oldest and, at the same time, most robust solutions to this problem. Nevertheless, the standard is still rarely used in many organisations.
What is S/MIME?
S/MIME stands for Secure/Multipurpose Internet Mail Extensions. Behind this rather unwieldy name lies an open standard for the cryptographic hardening of emails. Specifically, S/MIME enables two things:
Digital signature
The recipient can be certain that the email really does come from the specified sender and has not been altered in transit.
encryption
The content of the email is encrypted in such a way that only the intended recipient can read it – not the mail server, not the provider, and no one else.
Both functions are based on the principle of asymmetric cryptography: each participant has a key pair consisting of a public and a private key. Anything encrypted with one key can only be decrypted with the other – and vice versa.
How does this work in practice?
To use S/MIME, you first need an S/MIME certificate issued by a trusted certification authority (CA). This certificate links a person’s email address to their public key, thereby confirming their identity.
An S/MIME certificate is essentially a digital ID for an email address. The certification authority confirms: ‘Yes, this person or organisation is genuinely behind this address.’ Much like a notary certifies a signature.
This is how signed and encrypted communication works:
Signing when sending
The sender signs the email with their private key. The signature is unique and cannot be forged without knowing the private key.
Assessment upon receipt
The recipient verifies the signature using the sender’s public key. If the assessment fails, the email has been altered or does not originate from the stated sender.
Encryption for the recipient
If the sender wishes to encrypt the message further, they use the recipient’s public key. Only the recipient’s private key can decrypt the message.
End-to-end protection
Encryption takes place on the sender’s device and is only decrypted on the recipient’s device – no intermediary point along the transmission path can read the message.
What does S/MIME protect – and what doesn’t it?
S/MIME is not a panacea. It is important to understand which threat scenarios it addresses and which it does not.
What S/MIME protects
Sender authenticity (no spoofing), content integrity (no man-in-the-middle attacks), confidentiality during transmission and archiving.
What S/MIME does not protect against
Phishing via genuine but compromised accounts, Malware in attachments, Social Engineering, and metadata such as the subject line, sender and recipient addresses.
A common misconception: even with S/MIME, the subject line, sender and recipient remain visible in plain text. Only the actual email content is encrypted. Anyone requiring complete metadata anonymity must resort to other solutions.
S/MIME vs. PGP – what is the difference?
Alongside S/MIME, PGP (Pretty Good Privacy) is another widely used standard for email encryption. Both utilise asymmetric cryptography, but differ fundamentally in their trust models:
S/MIME: Centralised trust via certification authorities
Trust is verified by an official CA. This is compatible with corporate structures, works out-of-the-box in Outlook, Apple Mail and other common clients – and can be managed centrally via Active Directory or MDM systems.
PGP: Decentralised web of trust
Here, users verify each other’s keys. No intermediary is required, but it involves considerably more manual effort. Particularly widespread in technical communities and amongst security researchers.
For corporate use, S/MIME is generally the more practical choice: it is more deeply integrated into standard email clients and is easier to scale and manage.
Why do so few companies use S/MIME?
The technology has been around since the 1990s. Nevertheless, S/MIME is far from being used across the board in German companies. The reasons are well known:
Certificate management is labour-intensive
Certificates have a limited validity period and must be renewed regularly. Without centralised management, they quickly become an administrative nightmare – particularly in larger organisations.
Key exchange is not straightforward
For encrypted communication to be possible, both parties must know each other’s public key. Without automated processes, this can quickly lead to friction.
Lack of awareness raising
Many employees do not know what a digital signature is – or why it is problematic when emails arrive without one. The topic rarely features on the agenda.
Compatibility issues with external recipients
Not every communication partner supports S/MIME. Encrypted emails may appear illegible on poorly configured clients, leading to frustration and setbacks.
Getting started: Even without immediate encryption, the benefits of S/MIME can be realised straight away: digital signatures do not require a key exchange with the recipient and can be activated immediately. The recipient sees the signature – and knows that the email is genuine.
S/MIME and compliance: What do TISAX and ISO 27001 say?
For organisations that are certified to TISAX or ISO 27001, or are seeking certification, email security is not an optional topic. Both frameworks explicitly address the protection of sensitive information during transmission.
TISAX
In the automotive sector, there are specific requirements for hardening confidential communications. S/MIME can be an important component in meeting these security requirements.
ISO 27001
Annex A of the standard addresses cryptography and message security. S/MIME is an established means of demonstrably fulfilling the relevant controls.
GDPR
Article 32 of the GDPR requires ‘appropriate technical measures’ to protect personal data. Anyone sending personal data by email should be able to explain why encryption is not being used.
How Mint Secure supports you
The introduction of S/MIME is not purely a technical decision. It affects processes, infrastructure and user behaviour in equal measure. We support organisations from the initial needs analysis right through to live operation.
Certificate infrastructure
We assist with selecting suitable certification authorities, planning validity periods and integrating the system into existing directory services such as Active Directory.
Technical integration
Whether it’s Outlook, Apple Mail, Exchange or an MDM system: we configure S/MIME so that it works transparently for end users without any extra effort.
Awareness raising & training
Technology alone is not enough. We train employees to recognise signed emails, interpret them correctly and handle them securely.
Are you unsure whether S/MIME is the right choice for your organisation? In a free initial consultation, we’ll analyse your current email infrastructure and highlight which measures will deliver the greatest security benefits. Get in touch.
Conclusion
S/MIME is not a new concept – but it is more relevant than ever. In light of increasing phishing attacks, business email compromise and heightened compliance requirements, the cryptographic hardening of emails should be on every IT security agenda.
Getting started doesn’t have to be complicated. Even the introduction of digital signatures – without encryption – provides verifiable authenticity and protects against a whole range of attacks.
Mint Secure provides consulting and supports you throughout the process, whether you’re just starting out or looking to secure an existing infrastructure. Talk to us.

