SSL Toolkit Logo

S/MIME Checker

Check if a certificate supports S/MIME email encryption

About S/MIME Email Encryption

S/MIME (Secure/Multipurpose Internet Mail Extensions) is a protocol for email encryption and digital signing that uses X.509 certificates. A certificate must include the Email Protection Extended Key Usage (EKU) to be valid for S/MIME. Our S/MIME Checker inspects a server's certificate to determine whether it supports secure email communication, verifying the EKU extension and extracting the embedded email address.

How to Use

  1. Enter the domain name of the server hosting the certificate.
  2. Click Check S/MIME to fetch and analyze the certificate.
  3. Review the S/MIME support status and certificate details.
  4. Check the Subject, Issuer, and embedded email address if available.

Use Cases

Frequently Asked Questions

S/MIME is a standard for public key encryption and digital signing of email messages. It allows senders to encrypt email content and attachments, and recipients to verify the sender's identity through digital signatures.
TLS (STARTTLS) encrypts the connection between email servers during transit, while S/MIME encrypts the email message itself end-to-end. S/MIME ensures that even if the email server is compromised, the message content remains encrypted.
S/MIME certificates include the Email Protection EKU (1.3.6.1.5.5.7.3.4) in their Extended Key Usage extension. Some certificates also include the Email Signing (1.3.6.1.5.5.7.3.4) and Email Encryption (1.3.6.1.5.5.7.3.4) key purpose IDs.

Tips & Best Practices

Technical Details

Protocol: Secure/Multipurpose Internet Mail Extensions (S/MIME) support
Features: Email encryption, digital signing, and certificate validation
Clients: Email client S/MIME compatibility
Output: S/MIME support status with configuration recommendations

Related Tools