SecureMail: email encryption at the gateway

SecureMail encrypts and signs email centrally with S/MIME and OpenPGP, including key management and a portal for recipients without a certificate.

SecureMail is the gateway module for email encryption. Messages are signed, encrypted, decrypted and verified centrally in the mail flow, without endpoints or mail clients having to install anything.

SecureMail overview with encryption status and routing SecureMail overview with the cryptography status.

Two standards: S/MIME and OpenPGP

SecureMail handles both established methods at the same time. S/MIME works with X.509 certificates and a hierarchical chain of trust, widespread in companies and public authorities. OpenPGP works with public and private keys. Per message the rule set picks the fitting method for the respective recipient. Details on the processing are described under decrypting incoming messages and signing and encrypting outgoing messages.

Central key management

Certificates and keys are held centrally in the tenant, not on individual devices. Public keys of incoming partners are imported automatically, your own certificates are issued through an internal CA or through SwissSign and renewed before they expire. The management is described under S/MIME certificates and PGP keys.

Rules per tenant

Routes define which senders and recipients are treated how. Every rule applies to one direction, one or several protocols and one cryptographic logic. Encryption can additionally be triggered through keywords in the subject.

Delivery without a certificate

If the recipient has no certificate or key, the message portal steps in as a web reader, or delivery takes place as a password-protected PDF. Confidential communication thus remains possible with partners who have no encryption of their own.

Anyone who wants to choose encryption while writing finds the client extensions under SecureMail for Microsoft 365 for Outlook and under Thunderbird add-on for Thunderbird.

For the connection to Exchange Online see SecureMail for Microsoft 365. The cryptographic signature from SecureMail differs from the visual signature of the Disclaimer module. A connected domain is the precondition. The SecureMail product page gives a market overview.