Digital signatures can be attached to your outgoing email messages as proof that they came from you and not from a spammer or phisher.
A valid digital signature assures that an email was not altered in transit. When you receive a signed email, you will see a message indicating that it was signed and if the signature is valid. There will also often be an icon, like a padlock or a sealed envelope, depending on which email client (e.g. Outlook) you are using. You can check if your emails are being signed correctly by looking for these indicators on the copies stored in your sent emails folder.
If you don't already have a certificate, please visit the Digital Certificates page.
Configuring Email Signing
Email clients can be configured to sign all emails automatically.
If you have not already installed your certificate in Windows, use the following instructions to do so:
Browse to the folder where you saved the certificate file.
Right click on the certificate file and select "Install PFX" from the options.
From the "Certificate Import Wizard", choose the following options:
On the "Store Location" screen, select "Current User" and click Next.
On the "File to Import" screen, verify that the file name/location listed is correct and click Next.
On the "Private key protection" screen, make the following changes:
For your "Password", enter the PIN that you set earlier.
Check the box entitled "Mark this key as exportable".
Leave all of the other options as defaults and click Next.
On the "Certificate Store" screen, keep the default "Automatically select" action and click Next.
On the "Completing" screen, verify the options and click Finish.
When prompted that "The Import was successful", click OK to finish the import process.
To configure Microsoft Outlook to use the installed certificate:
Open Microsoft Outlook.
Click the "File" tab and select "Options" from the choices in the left pane.
In the left pane of the "Outlook Options" window, click on "Trust Center".
In the right pane of the "Trust Center" menu, click on the "Trust Center Settings" button.
In the left pane of the "Trust Center" window, click on "Email Security".
In the right pane of the "Email Security" menu, complete the following steps:
Under the "Encrypted email" heading:
Check the box entitled "Add digital signature to outgoing messages".
Do NOT uncheck "Send clear text signed message when sending signed messages" (necessary so that people without digital signature capabilities can still read your messages).
To the right of "Default Setting:", click the "Settings" button.
In the "Change Security Settings" window, verify that your certificate is selected under "Security Settings Name" (will be named something like "My S/MIME Settings (ubitname@buffalo.edu)") and click OK (this will close this window).
Change the drop-down menu option to the right of "Default Setting:" to the certificate from the previous step (if not listed).
Under the "Digital IDs (Certificates)" heading, click the "Publish to GAL" button to add your public certificate in the Global Address List (GAL) so that other people can send you encrypted messages.
Click OK to close the "Trust Center" window and the "Outlook Options" window.
Send a test email to yourself. The header bar for the incoming message should have a picture of a red ribbon. If you click on it, it should say "Digital Signature Valid".
Email Encryption
Digital certificates can also be used to encrypt emails, meaning that they are more protected from being read by anyone other than the recipient. Encryption requires that both parties have certificates and that they have shared their certificates' public keys with each other, so that should only be done for people who you know and for whom you have taken the necessary steps.
Encryption does not guarantee that emails won't be read by anyone besides the recipients.
An email client set up to sign emails is ready to encrypt emails as well. Settings for encrypting your emails can typically be found alongside the options for signing your emails. Typically, there is an option that controls if encryption will always be attempted or only used when requested.