Signing and encrypting outgoing email

Sign and encrypt outgoing messages by rule with S/MIME or OpenPGP, with a fallback to the message portal or as a PDF.

For outgoing messages SecureMail signs and encrypts automatically at the gateway. A route with the direction outbound defines which senders and recipients receive which cryptographic treatment.

Addressees and direction

The first step determines the addressees. With outgoing mail the sender is a mailbox of the tenant domain and the recipient is the external counterpart. Addressees can be chosen as a single address, as a group or as all mailboxes. A rule thus applies specifically to one team, one domain or the entire tenant.

Choosing the addressees of an outbound route in SecureMail Addressees and direction of an outbound route.

Protocols and order

Then the protocols are enabled: S/MIME, OpenPGP, the message portal and PDF password delivery. If several are active, SecureMail works through an order. If no key-based encryption can be applied, the fallback into the portal or as an encrypted PDF takes effect.

Protocol selection with portal and PDF fallback for outgoing messages Protocols with portal and PDF fallback.

Signature and encryption rules

The cryptography step governs signing and encrypting separately. For signing, send without signature, sign if possible and send signed only are available. For encrypting the options range from send without encryption through encrypt if possible and send encrypted only to send only if all recipients can be encrypted for. In addition the signature mode, encryption mode, symmetric algorithm and hash algorithm can be set. The key is determined automatically from the sender address, a specific certificate is optional.

Routing rules in SecureMail with S/MIME, PGP and portal per direction The routing table governs signature and encryption.

Encryption can additionally be triggered through a keyword in the subject, for instance secure. This cryptographic signature under S/MIME or OpenPGP differs from the visual, legal signature of the Disclaimer module, and both can be combined.

The opposite direction is described in inbound messages. Keys and certificates are managed on the certificates page. The fallback without a certificate is described under message portal. On domain authentication see SPF and DKIM.