Setting up S/MIME certificate under iOS
This article describes how to install and activate an S/MIME certificate to securely sign and encrypt your email communication with mailbox.
S/MIME (Secure/Multipurpose Internet Mail Extensions) enables you to digitally sign and encrypt emails. This ensures that your messages genuinely originate from you and cannot be altered or read during transmission. This technology is ideal for secure communication with mailbox, especially when exchanging sensitive information.
Installing an S/MIME certificate on iOS – step by step
Requirements
- Personal S/MIME certificate in
.p12or.pfxformat (including the private key). - The corresponding certificate password.
- Access to the respective email account on the iPhone/iPad.
Transferring the certificate to the device
- Send the .p12/.pfx file to your iOS device via email or transfer it using AirDrop/the Files app.
- Open the message or file and tap the certificate attachment.
Installing the certificate
- Tap Install.
- Enter the certificate password and confirm.
- Complete the assistant.
Verification:
The certificate appears on your device:
- Current iOS versions: Settings > General > About > Certificate Trust Settings
- Older iOS versions: Settings > General > VPN & Device Management > Profile
Activating S/MIME in the iOS mail app – step by step
Enabling S/MIME for an account
- Open Settings > Mail > Accounts.
- Select the desired account and tap Account.
- Open Advanced (or Advanced > S/MIME).
- Enable S/MIME.
- Tap Sign and select your certificate.
- Tap Encrypt and select your certificate.
Checking default behavior
- Set Sign to On if outgoing messages should be signed by default.
- Set Encrypt to Automatic/Yes if messages should be encrypted whenever possible.
Signing and encrypting while sending
When composing an email
- Open Mail and create a new message.
- Check the checkmark next to your sender address:
Checkmark = message will be signed. - Check the lock symbol:
- Closed lock: message will be encrypted.
- Open lock: encryption not possible (public certificate of the recipient is missing).
Public certificate of recipients
- To encrypt a message, you need the recipient’s public certificate.
- This is automatically stored when you receive a signed email from that person. Afterwards, the closed lock will appear when composing emails.
Troubleshooting
Certificate not displayed
- Check whether the .p12/.pfx file contains the private key.
- Reinstall the certificate and enter the correct password.
Signature/encryption not possible
- Check whether your certificate is selected under
Settings > Mail > Accounts > Account > Account > Advanced > S/MIME - For encryption: Is a public certificate for the recipient available? If not, ask them to send a signed email.
Multiple accounts
Repeat the S/MIME activation steps for each email account separately.
Digital signature and encryption in everyday use
When composing a new email, you will see a lock icon in the subject line. An open lock means that the message will be sent unencrypted, while a closed lock indicates that the email will be encrypted. In addition, when the signature is enabled, a tick appears next to your name to indicate that the email is digitally signed.
If you do not have a recipient’s public certificate, you can sign the message but cannot encrypt it. In this case, it is advisable to first send a signed email to the recipient to initiate the certificate exchange.
