Solution · Mozilla Thunderbird

Email encryptionfor Thunderbird.Without an add-on.

Protection is created not inside the mail client but on a station in front of it. Thunderbird composes and sends exactly as before, without an extension and without a certificate in the profile. S/MIME, PGP, password-protected PDF and secure portal are selected per recipient automatically.

Why S/MIME fails inside the client

Thunderbird can do encryption. The problem is administration, not technology.

One certificate per person and per device

Desktop, laptop and company phone each need the same key. Every device replacement repeats the process, and the phone is almost always left out in practice.

Expiry, leavers, stand-ins

Certificates expire after one to three years. When someone leaves, the private key stays on the device. A stand-in cannot read encrypted mail at all.

No binding rule

A mail client can offer encryption but cannot require it. Whether the message with payroll data goes out protected depends on a click someone may forget.

Recipients without a certificate

Without the recipient public certificate no encrypted message is possible. That leaves the choice between plain text and not sending at all.

Move where encryption happens

What happens on the gateway applies to every client and every device.

A station in front of the mailbox

SecureMail is placed in front of the existing mail flow. The message leaves Thunderbird as usual and is signed and encrypted afterwards. Nothing is configured at the workplace.

Four delivery paths, chosen automatically

S/MIME where a certificate exists, PGP where a key exists, otherwise a password-protected PDF or the secure portal. No sender needs to know what the other side supports.

Rules instead of manual steps

Rules per sender, recipient, domain or group decide bindingly. Anything covered by a mandatory rule leaves the company protected or not at all.

What this covers

Encryption, signature and evidence in one place.

S/MIME and PGP centrally

Keys are held centrally, not on end devices. Procurement, renewal and revocation happen in one place, with lead time and notifications.

Password-protected PDF

Where the recipient has nothing in place, message and attachments become a protected PDF. The password travels over a separate channel.

Secure message portal

The message stays protected on the server while the recipient reads and replies in the browser. No installation, no certificate, no account with the sender.

Signature to the outside

Outbound mail is signed. The other side can see that the message genuinely originates from your company and was not altered in transit.

Inbound decrypted and verified

Encrypted inbound mail is opened and its signature checked before delivery. In Thunderbird an ordinary, readable message appears.

Independent of the access protocol

Whether Thunderbird reaches the mailbox over IMAP, EWS or Graph in future makes no difference to protection. Protocol changes do not touch encryption.

Gateway versus certificates in the client

The same encryption, two very different operating models.

 
Conbool SecureMail
S/MIME in the Thunderbird profile
Setup at the workplace
None. No add-on, no certificate, no profile change
Import per person and per device
Certificate management
Central, with renewal and revocation
Spread across devices, expiry noticed only by the recipient
Recipient without a certificate
Falls back to PDF or portal
Plain text is the only option
Binding policy
Rule per sender, recipient or group
Depends on a click in the compose window
Company phone and webmail
Included, without setup
Unprotected in practice
Evidence for an audit
Centrally traceable
Cannot be determined from distributed profiles

This comparison describes operation across a company. For individual users, encryption inside the client remains a workable solution.

Frequently asked questions

Can Thunderbird encrypt without an add-on?
In this setup yes, because Thunderbird does not encrypt at all. Protection is created on the station in front of the mailbox, after the message has left the client. Thunderbird stays unchanged and needs neither an extension nor a certificate in the profile.
Does the built-in S/MIME function in Thunderbird have to stay switched off?
Yes. If the client encrypts as well, the gateway can no longer inspect and process the message. A second envelope around the first adds no protection, only sources of error.
What happens when the recipient has no certificate?
The next available path applies. Where neither an S/MIME certificate nor a PGP key exists, the message is delivered as a password-protected PDF or made available in the secure portal. Plain text is ruled out under a mandatory rule.
Does protection also apply on a company phone?
Yes. Because encryption does not sit inside the client, it also covers the mail app on the phone and webmail in the browser, without anything being configured there.
Does the EWS shutdown in Exchange Online change anything here?
No. Microsoft disables Exchange Web Services in Exchange Online by default from 1 October 2026. That affects the access path of the client, not the mail flow. Anyone running encryption in front of the mailbox simply switches protocol and leaves encryption untouched.
How is a single message marked as confidential without an add-on?
Through a keyword agreed during setup, written in square brackets at the start of the subject line. It triggers protection for that message and is removed again before delivery, so the recipient never sees it.

Verwandte Lösungen

Keep Thunderbird, gain encryption.

No software at the workplace, no certificates on end devices. Operated with data in Germany.