Email encryptionfor Thunderbird.Without an add-on.
Protection is created not inside the mail client but on a station in front of it. Thunderbird composes and sends exactly as before, without an extension and without a certificate in the profile. S/MIME, PGP, password-protected PDF and secure portal are selected per recipient automatically.
Why S/MIME fails inside the client
Thunderbird can do encryption. The problem is administration, not technology.
One certificate per person and per device
Desktop, laptop and company phone each need the same key. Every device replacement repeats the process, and the phone is almost always left out in practice.
Expiry, leavers, stand-ins
Certificates expire after one to three years. When someone leaves, the private key stays on the device. A stand-in cannot read encrypted mail at all.
No binding rule
A mail client can offer encryption but cannot require it. Whether the message with payroll data goes out protected depends on a click someone may forget.
Recipients without a certificate
Without the recipient public certificate no encrypted message is possible. That leaves the choice between plain text and not sending at all.
Move where encryption happens
What happens on the gateway applies to every client and every device.
A station in front of the mailbox
SecureMail is placed in front of the existing mail flow. The message leaves Thunderbird as usual and is signed and encrypted afterwards. Nothing is configured at the workplace.
Four delivery paths, chosen automatically
S/MIME where a certificate exists, PGP where a key exists, otherwise a password-protected PDF or the secure portal. No sender needs to know what the other side supports.
Rules instead of manual steps
Rules per sender, recipient, domain or group decide bindingly. Anything covered by a mandatory rule leaves the company protected or not at all.
What this covers
Encryption, signature and evidence in one place.
S/MIME and PGP centrally
Keys are held centrally, not on end devices. Procurement, renewal and revocation happen in one place, with lead time and notifications.
Password-protected PDF
Where the recipient has nothing in place, message and attachments become a protected PDF. The password travels over a separate channel.
Secure message portal
The message stays protected on the server while the recipient reads and replies in the browser. No installation, no certificate, no account with the sender.
Signature to the outside
Outbound mail is signed. The other side can see that the message genuinely originates from your company and was not altered in transit.
Inbound decrypted and verified
Encrypted inbound mail is opened and its signature checked before delivery. In Thunderbird an ordinary, readable message appears.
Independent of the access protocol
Whether Thunderbird reaches the mailbox over IMAP, EWS or Graph in future makes no difference to protection. Protocol changes do not touch encryption.
Gateway versus certificates in the client
The same encryption, two very different operating models.
Conbool SecureMail | S/MIME in the Thunderbird profile | |
|---|---|---|
| Setup at the workplace | None. No add-on, no certificate, no profile change | Import per person and per device |
| Certificate management | Central, with renewal and revocation | Spread across devices, expiry noticed only by the recipient |
| Recipient without a certificate | Falls back to PDF or portal | Plain text is the only option |
| Binding policy | Rule per sender, recipient or group | Depends on a click in the compose window |
| Company phone and webmail | Included, without setup | Unprotected in practice |
| Evidence for an audit | Centrally traceable | Cannot be determined from distributed profiles |
This comparison describes operation across a company. For individual users, encryption inside the client remains a workable solution.
Frequently asked questions
Can Thunderbird encrypt without an add-on?
Does the built-in S/MIME function in Thunderbird have to stay switched off?
What happens when the recipient has no certificate?
Does protection also apply on a company phone?
Does the EWS shutdown in Exchange Online change anything here?
How is a single message marked as confidential without an add-on?
Verwandte Lösungen
Keep Thunderbird, gain encryption.
No software at the workplace, no certificates on end devices. Operated with data in Germany.