S/MIME – your own certificate and setup check
S/MIME lets your email application sign and encrypt messages using an email certificate. Use a certificate you already have, or obtain one from your employer or a certificate issuer. Meil does not issue or purchase the certificate for you; any costs are arranged with the issuer or your employer.
Before you start
You need an S/MIME-compatible email application, a valid certificate for the sender address and access to its private key. An ordinary website certificate is not an email certificate.
Install the certificate and private key in the client or device's secure key store, and select the correct signing identity. Encryption also requires the recipient's encryption certificate. Follow the guide for your exact version: Thunderbird, Outlook or Apple Mail on iOS. These are vendor guides, not a guarantee for every client and account variant.
Your private key stays with you. Meil does not request a .p12 or .pfx file, passphrase or private key in the setup check.
Check the setup in Meil
- Open Settings → Login & Security.
- Find S/MIME and choose Check setup. Keep the page open.
- Compose a new message in your email application, from and to the displayed address.
- Copy the subject and message text exactly from Meil. Use plain text, with no attachments or extra signature text.
- Enable S/MIME signing, but not encryption, for this non-sensitive test message only. Send it through the Meil account.
- Once the message is in your inbox, return and choose Check test message within 15 minutes.
This is a signature test, not an encryption test. It uses only the new test message, not ordinary messages in your mailbox.
What does the result mean?
A successful signature check means the signature, sender address and test message through Meil have been checked. It does not automatically confirm the recipient's trust in the certificate issuer, revocation status or ability to decrypt.
Check trust and encryption separately in your client: exchange public certificates with the recipient, send a non-sensitive encrypted message and confirm that both parties can read their received messages. Do not disable certificate validation to obtain a green result.
If the check stops
| Result | Next step |
|---|---|
| Message not found yet | Wait, check the inbox and retry. Check the address and subject; do not move the message to another folder. |
| Test expired | Start a new check and send a new message with the new values. |
| Test could not be approved | Check the certificate, sender, plain text and S/MIME signing. Remove extra signature text and start a new test. |
| Temporarily unavailable | Retry within the test deadline; start a new test if it expires. |
| Too many attempts | Wait. You can start up to five tests per hour. |
If needed, send the result reference, client version and time to support. Do not send private keys, passphrases or ordinary email content.
Privacy and renewal
Meil reads the identified test message in your inbox when you request a check. The result and certificate fingerprint are stored temporarily for 30 days. The security log records the outcome, not the fingerprint, content or private key. You can delete the test message afterwards.
Renew the certificate before it expires, select the new one in your client and run the check again. If compromised, contact the issuer for revocation and inform your contacts. Keep old decryption keys secure for older messages. Read about backups.