Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.


  • Contact Us
  • Home
  • General Information

S/MIME Rules Configuration

Updated at August 28th, 2025

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.


  • General Information
  • Pre-deployment
  • Forwarding Address (Archiving Address)
  • Email Flow (Fusion)
  • Mailbox (Email Sync)
  • Storage
    Box Service Account OneDrive for Organizations
  • Mail2Sign
    Box Sign DocuSign
  • Login
  • mxHERO AI
  • Labs
  • Basics
  • Mail2Cloud Dashboard
  • Auto Filling
  • Drag And Drop
  • MXHERO App
+ More

Table of Contents

S/MIME Rules Configuration How S/MIME Rules Work 1. Select S/MIME Actions 2. Define Email Flow Scope 3. Certificate Requirements Rule Processing Logic Example Rule Scenarios Scenario 1: Sign All Outgoing Emails Scenario 2: Encrypt to External Partners Scenario 3: Validate Incoming Signatures Scenario 4: Full S/MIME Protection Advanced Filtering Rule Priority and Conflict Resolution Best Practices for Rule Configuration Troubleshooting Common Issues

S/MIME Rules Configuration

Before certificates and email accounts can be used for S/MIME operations, your organization must create S/MIME Rules in the MXHero dashboard. These rules define when and how S/MIME operations are applied to email flows.

How S/MIME Rules Work

1. Select S/MIME Actions

For emails matching the flow, you can enable one or more actions:

  • Validate: Verify digital signatures on incoming emails
  • Sign: Add digital signatures to outgoing emails
  • Encrypt: Encrypt outgoing emails
  • Decrypt: Decrypt incoming emails

2. Define Email Flow Scope

Rules specify which emails are affected by defining the flow direction:

  • From → To: Specific sender to specific recipient

3. Certificate Requirements

S/MIME operations will only apply to email accounts that meet these conditions:

  • The email account must be registered via the API (as described in this guide)
  • The account must have the appropriate certificates for the requested action:
    • Signing/Decrypting: Requires P12 certificate with private key
    • Encrypting/Validating: Can use PEM certificates (public key only)

Rule Processing Logic

Email Flow → Rule Match → Action Check → Certificate Availability → S/MIME Operation

Important: If an email account is not registered or lacks the required certificates, the S/MIME operation will be skipped for that account, even if a rule exists.

Example Rule Scenarios

Scenario 1: Sign All Outgoing Emails

  • Flow: yourcompany.com → Anyone
  • Action: Sign
  • Result: All outgoing emails from registered accounts with P12 certificates will be signed

Scenario 2: Encrypt to External Partners

  • Flow: yourcompany.com → partner-company.com
  • Action: Encrypt
  • Result: Emails to partner-company.com will be encrypted if recipient certificates are available

Scenario 3: Validate Incoming Signatures

  • Flow: Anyone → yourcompany.com
  • Action: Validate
  • Result: Incoming signed emails will be validated against registered sender certificates

Scenario 4: Full S/MIME Protection

  • Flow: yourcompany.com ↔ partner-company.com
  • Actions: Sign, Encrypt, Decrypt, Validate
  • Result: Complete S/MIME protection for bidirectional communication

Advanced Filtering

S/MIME rules support the same advanced filtering options available in other MXHero rules:

  • Sender/Recipient (From/To) Exclusions
  • Use filter policy

Rule Priority and Conflict Resolution

  • Rules are processed in order of priority
  • More specific rules take precedence over general rules
  • Only one rule can be executed by organization on the same email
  • Certificate availability is checked for each action independently

Configure S/MIME Rules (via Dashboard)

  • Define email flows
  • Select S/MIME actions
  • Set filtering criteria

Email Processing (Automatic)

  • Rules evaluate incoming/outgoing emails
  • S/MIME operations applied based on available certificates
  • Emails processed according to rule configuration

Best Practices for Rule Configuration

  1. Start Simple: Begin with basic organization-wide rules before creating specific flows
  2. Test Gradually: Deploy rules to small groups first, then expand
  3. Monitor Logs: Check processing logs to ensure rules work as expected
  4. Certificate Coverage: Ensure all users in rule scope have appropriate certificates
  5. External Coordination: Coordinate with external partners for mutual S/MIME setup

Troubleshooting Common Issues

Issue Cause Solution
Emails not being signed Missing P12 certificate or not set as primary Upload P12 and set as primary via API
Cannot encrypt to recipient No certificate for recipient email Upload recipient's PEM certificate
Signature validation fails Sender's certificate not registered Upload sender's PEM certificate
Rule not triggering Email flow doesn't match rule criteria Review and adjust rule scope
encryption rules email security

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Managing S/MIME through mxHERO V3 API
  • Managing datasets through mxHERO V3 API
  • mxHERO Email work flow
astors-3-tiny.png

Company

Home

About

News

Blog

Security & Trust

Terms of Service

Privacy Policy

Service Status

Partners

Products & Papers

Data Sheets

Products

FAQ

Roadmap

Contact

Sales

Support

Videos

Japan

Report Incident

Contact Us!
  • LinkedIn

contact@mxhero.com

3x Astors Homeland Security Platinum Award for Best Email Security Solution

© 2022 mxHERO Inc.

BoxElite.png

USA

100 Pine St., Suite 1250

San Francisco, CA 94111

USA

​

Japan

105-0003

DLX Building 9F

Nishi-Shinbashi 1-13-1

Minato-ku, Tokyo

Japan

Definition by Author

0
0
Expand