---
sourceDocument: Xanadu ServiceNow AI Platform Administration
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/xanadu/platform-administration

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu ServiceNow AI Platform Administration

ft:clusterId :

    - platadm

bundleId :

    - platadm

workflow :

    - Platform


---

# Enable S/MIME

# Enable S/MIME {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure S/MIME settings for inbound and outbound email.

## Enable S/MIME for Inbound and Outbound emails {#enable-smime-for-outbound-and-inbound__section_erh_2jl_5tb}

You can configure email properties from the Email Properties page through the System Mailboxes or System Properties module.  
Email properties are available from either of these modules:

* System MailboxesEmail Properties
* System PropertiesEmail Properties
{#enable-smime-for-outbound-and-inbound__ul_qpc_zn1_mbc}

## Outbound S/MIME configuration {#enable-smime-for-outbound-and-inbound__section_tcc_cmy_vtb}

For encryption, you must upload the email certificate for the recipients in PEM format and
the CA certificates for the issuing authority. For more information, see [Upload an email certificate](https://servicenow-prod.fluidtopics.net/MCL7DX~DQ3zdQCq9mqVnWQ "Upload an email certificate to validate a signature for inbound email or encrypt an outbound email or both for secure communication.") and [Upload a CA certificate](https://servicenow-prod.fluidtopics.net/75AJrZjHxbp22vrHO62mfw "Upload a digital CA (Certificate Authority) certificate to validate email certificates for secure communication.").

For signing, you must upload the email account key pair in P12 format. For more
information, see [Import an S/MIME key pair](https://servicenow-prod.fluidtopics.net/h5Q9PoeYzpZAE07g5NW4lw "Import an S/MIME key pair consisting of the private key and certificate to sign outbound emails or decrypt emails.").  
{#enable-smime-for-outbound-and-inbound__table_uvv_2my_vtb__entry__2}

| Configuration | Related property |
|-|-|
| Digitally sign your outbound emails. | email.outbound.smime.signing.enabled |
| Send a public certificate in the outbound email. | email.outbound.smime.signing.send_public_cert |
| Encrypt message contents and attachments. | email.outbound.smime.encryption.enabled |
| Encryption algorithm. Select AES-CBC or AES-GCM. Note: Before selecting AES-GCM, check whether GCM is supported by the client for S/MIME. | email.outbound.smime.encryption.algo |
[Table 1. Outbound S/MIME configuration properties]

{#enable-smime-for-outbound-and-inbound__table_uvv_2my_vtb}

## Inbound S/MIME configuration {#enable-smime-for-outbound-and-inbound__section_g15_gmy_vtb}

For decryption, you must upload the email certificate for the recipients in PEM format and
the CA certificates for the issuing authority. For more information, see [Upload an email certificate](https://servicenow-prod.fluidtopics.net/MCL7DX~DQ3zdQCq9mqVnWQ "Upload an email certificate to validate a signature for inbound email or encrypt an outbound email or both for secure communication.") and [Upload a CA certificate](https://servicenow-prod.fluidtopics.net/75AJrZjHxbp22vrHO62mfw "Upload a digital CA (Certificate Authority) certificate to validate email certificates for secure communication.").

For signature verification, you must upload the email account key pair in P12 format. For
more information, see [Import an S/MIME key pair](https://servicenow-prod.fluidtopics.net/h5Q9PoeYzpZAE07g5NW4lw "Import an S/MIME key pair consisting of the private key and certificate to sign outbound emails or decrypt emails.").  
{#enable-smime-for-outbound-and-inbound__table_tdr_3my_vtb__entry__2}

| Configuration | Related property |
|-|-|
| Verify the signature for inbound emails. | email.inbound.smime.verify_sign |
| Decrypt inbound emails. | email.inbound.smime.decrypt |
[Table 2. Inbound S/MIME configuration properties]

{#enable-smime-for-outbound-and-inbound__table_tdr_3my_vtb}

## Enable S/MIME for email notification form {#enable-smime-for-outbound-and-inbound__section_jln_rpr_cwb}

To digitally sign or encrypt your emails, go to AllEmailNotifications, select New and select the Digitally sign your emails check box for digitally signing emails and Encrypt emails check box for email
encryptions.  
Figure 1. Enable S/MIME for email notification form

For more information, see [Create an email notification](https://servicenow-prod.fluidtopics.net/1uxmFe3Zi5x_C3q5DOmU5Q "Create an email notification specifying when to send it, who receives it, what it contains, and if it can be delivered in an email digest.").

## Enable S/MIME for email client {#enable-smime-for-outbound-and-inbound__section_ogt_21z_cwb}

In the compose email form, select the Digitally sign your emails check box for digitally signing emails and Encrypt emails check box for email encryptions.  
Figure 2. Enable S/MIME for email client
**Related tasks**   

* [Import an S/MIME key pair](https://servicenow-prod.fluidtopics.net/h5Q9PoeYzpZAE07g5NW4lw "Import an S/MIME key pair consisting of the private key and certificate to sign outbound emails or decrypt emails.")
* [Upload a CA certificate](https://servicenow-prod.fluidtopics.net/75AJrZjHxbp22vrHO62mfw "Upload a digital CA (Certificate Authority) certificate to validate email certificates for secure communication.")
* [Upload an email certificate](https://servicenow-prod.fluidtopics.net/MCL7DX~DQ3zdQCq9mqVnWQ "Upload an email certificate to validate a signature for inbound email or encrypt an outbound email or both for secure communication.")

*[\>]: and then


