{"id":6685,"date":"2018-07-09T14:33:01","date_gmt":"2018-07-09T18:33:01","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=6685"},"modified":"2023-05-17T11:49:32","modified_gmt":"2023-05-17T15:49:32","slug":"email-security-part-1-certificate-signed-emails","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/email-security-part-1-certificate-signed-emails\/","title":{"rendered":"Email Security \u2013 Part 1: Certificate Signed Emails"},"content":{"rendered":"<h2>How and why to install an email signing certificate<\/h2>\n<p>Long before Twitter or even SMS (Short Message Service), email was a dominant force in communication spanning from global business reach to the next cubicle over. It still is a highly utilized method of communication, but it brings many complications with it.<\/p>\n<p>For example, the junk-mail game of the traditional stamp and drop method of the postal service was easily carried over into the digital space and renamed as spam. Some of this spam could be confusing to wade through. While some spam is as obvious as African royalty in a financial conundrum, some spam may be sourced as slight variances of trusted domain names. Does Amazon have a Customer Tracking and Assistance department and why are they asking for password verification through a poorly worded and logo-less email?<\/p>\n<p>Conversely, how can one ensure that their legitimate outbound email communication is not flagged or mistaken as something insidious? In a 2015 study, <a href=\"https:\/\/returnpath.com\/wp-content\/uploads\/2015\/10\/2015-Deliverability-Benchmark-Report.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Return Path reported<\/a> that only 79% of (legitimate) commercial emails actually make it to the intended destination. 1 in 5 commercial emails gets filtered out or flagged one way or another. There are many ways in which this can happen and many points in an email\u2019s lifecycle of WHERE filtering\/flagging can happen.<\/p>\n<p>We are going to kick off my venture into the world of commercial blogging with a series about email security. Not only will we be reviewing methods to identify bad emails coming in and how to protect oneself, but we will also be looking into methods to successfully delivering emails and establishing a trusted and reputable brand.<span id=\"newline\"><\/span><\/p>\n<h2>Will Anyone Vouch For This Person?!<\/h2>\n<p>Verification of identity can be seen all over the world:<\/p>\n<p><em>Police officer? \u201cLet me see your badge number so I can phone it in.\u201d<\/em><\/p>\n<p><em>Knock on the door? Let\u2019s have a look through the peephole to see if it is someone recognizable. Don\u2019t recognize them? \u201cWho are you?&#8230; Show me your girl scout license number so I can phone it in.\u201d<\/em><\/p>\n<p><em>Technical support for your account? \u201cWould you confirm your mother\u2019s maiden shoe size?<\/em>\u201d<\/p>\n<p>Besides intuition, there are no basic human sense cues that can help verify the origins of an email so it is a little more of a challenge. \u00a0The display name, source email address and writing style would be the best indications as to whether the email is legitimate or was composed by a spoofer. One could also follow the cumbersome mail headers and follow the route the email took to see if it makes some sense. However, the email sender is able to make this scrutinization a little laxer.<\/p>\n<span style=\"--tl-form-height-m:140.667px;--tl-form-height-t:118.1042px;--tl-form-height-d:118.1042px;\" class=\"tl-placeholder-f-type-shortcode_12779 tl-preload-form\"><span><\/span><\/span>\n<p>Coupled with intuition, signing certificates via S\/MIME (Secure\/Multipurpose Internet Mail Extensions) assist in establishing trust between sender and receiver. The little red Outlook ribbon (green check in Gmail) on a signed email carries with it a hierarchy of root certificates from whichever issuing authority.<\/p>\n<p>In a sense, a signing certificate tells the receiver, \u201cI went out of my way to get a CA (certificate authority) to vouch for me. Also, I paid for it\u2026..\u201d For a recipient that one might be in frequent contact with, this can bring peace of mind at a glance.<\/p>\n<h2>Let\u2019s Certify Some Emails<\/h2>\n<p>Now that we have gone over the generic overview of email certificates, let\u2019s apply a certificate in practice. <a href=\"https:\/\/litmus.com\/blog\/the-2017-email-client-market-share-infographic\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Despite the fact that it only accounts for a smallish percentage of total mail origination<\/a>, this tutorial will go over the application of email certificates to Outlook 2016 on a Windows-based machine.<\/p>\n<p><strong>Assumptions:<\/strong><\/p>\n<ul>\n<li>Windows 7+<\/li>\n<li>Outlook 2016<\/li>\n<li>Possession of a proper security certificate file (.crt)<\/li>\n<\/ul>\n<p><strong>Execution steps:<\/strong><\/p>\n<ul>\n<li>Open Outlook 2016<\/li>\n<li>\u2018File\u2019-&gt;\u2019Options\u2019-&gt;\u2019Trust Center\u2019-&gt;\u2019Trust Center Settings\u2019<\/li>\n<li>Trust Center window will appear<\/li>\n<li>Select \u2018Email Security\u2019 in the left menu options<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6690\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-1.png\" alt=\"Installing an email signing certificate on Outlook\" width=\"838\" height=\"675\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-1.png 838w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-1-300x242.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-1-768x619.png 768w\" sizes=\"auto, (max-width: 838px) 100vw, 838px\" \/><\/p>\n<ul>\n<li>Select \u2018Import\/Export\u2019 and the window will appear<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6689\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-2.png\" alt=\"Email Security\" width=\"837\" height=\"679\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-2.png 837w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-2-300x243.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-2-768x623.png 768w\" sizes=\"auto, (max-width: 837px) 100vw, 837px\" \/><\/p>\n<ul>\n<li>Browse to certificate and enter appropriate password (if applicable)<\/li>\n<li>Select \u2018OK\u2019 and the certificate will import<\/li>\n<li>Select \u2018Publish to GAL\u2019\n<ul>\n<li><em><strong>NOTE:<\/strong> The Global Address List is a list that is tied to some domain management, such, as an LDAP, that will have the certificates available that should be ready for encryption. Otherwise, a sender would need to send a signed certificate to a recipient prior to sending an encrypted message <\/em>so<em> the recipient will get the certificate to decrypt.<\/em><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6688\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-3.png\" alt=\"Push to GAL\" width=\"838\" height=\"679\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-3.png 838w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-3-300x243.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-3-768x622.png 768w\" sizes=\"auto, (max-width: 838px) 100vw, 838px\" \/><\/p>\n<ul>\n<li>There will be notification that this has completed<\/li>\n<\/ul>\n<h2>Configure certificate for email client<\/h2>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Open Outlook 2016<\/li>\n<li>Go to the trust center settings outlined in the previous section<\/li>\n<li>There is an optional checkbox for \u2018Add Digital Signature for Outgoing Messages\u2019<\/li>\n<li>This will sign every email generated for that particular email domain<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6687\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-4.png\" alt=\"Add Digital Signature\" width=\"842\" height=\"686\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-4.png 842w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-4-300x244.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-4-768x626.png 768w\" sizes=\"auto, (max-width: 842px) 100vw, 842px\" \/><\/p>\n<ul>\n<li>Select \u2018Settings\u2019<\/li>\n<li>Under \u2018Security Settings Name\u2019, make sure the correct email domain is selected<\/li>\n<li>In the \u2018Certificates and Algorithms\u2019 section, make sure the \u2018Hash Algorithm\u2019 is higher than \u2018SHA1\u2019 (selected by default). \u2018SHA256\u2019 is acceptable by most mail services\/exchangers so that should be suffice.<\/li>\n<li>Select \u2018OK\u2019<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-6686\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-5.png\" alt=\"Security Setting\" width=\"841\" height=\"684\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-5.png 841w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-5-300x244.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/EmailSecurity-5-768x625.png 768w\" sizes=\"auto, (max-width: 841px) 100vw, 841px\" \/><\/p>\n<ul>\n<li>Select \u2018OK\u2019 to close the Trust Center.<\/li>\n<\/ul>\n<p>In order to turn on\/off certificate signing or <a href=\"https:\/\/www.thesslstore.com\/blog\/how-to-send-encrypted-email-on-3-major-email-platforms\/\">encryption per email<\/a>, pop the email out and click \u2018Options\u2019 up top and select \u2018Signing\u2019 or \u2018Encrypt\u2019 to enable\/disable.<\/p>\n<p>Are the signing certificates enough? Maybe not but that is where intuition comes into play. We\u2019ll discuss that next time.<\/p>\n<p>Happy scrutinizing!<\/p>\n<h2>Make sure to check out the rest of the Email Security series:<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/email-security-part-2-phishing-and-other-falseness\/\">Email Security \u2013 Part 2: Phishing and Other Falseness<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/email-security-spf\/\">Email Security \u2013 Part 3: Sender Policy Framework (SPF)<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/dkim-domainkeys-identified-mail\/\">Email Security \u2013 Part 4: DKIM (DomainKeys Identified Mail)<\/a><\/li>\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/dmarc-reporting-and-email\/\">Email Security &#8211; Part 5: DMARC, Reporting and Email<\/a><\/li>\n<\/ul>\n<p>Check back every Monday for a new article.<\/p>\n\n<span style=\"--tl-form-height-m:966.781px;--tl-form-height-t:989px;--tl-form-height-d:989px;\" class=\"tl-placeholder-f-type-shortcode_12768 tl-preload-form\"><span><\/span><\/span>\n\n","protected":false},"excerpt":{"rendered":"<p>How and why to install an email signing certificate Long before Twitter or even SMS (Short Message Service), email was a dominant force in communication spanning from global business reach&#8230;<\/p>\n","protected":false},"author":11,"featured_media":6692,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[7770],"class_list":["post-6685","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-email-signing","post-with-tags"],"views":40639,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/07\/bigstock-206390116.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6685","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=6685"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6685\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/6692"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=6685"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=6685"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=6685"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}