Order your Secure Email for Organization certificate

With Secure Email for Organization certificates, secure emails for your organization on your email domains. These certificates are ideal for securing emails from shared or other email addresses not assigned to a specific individual.

Use your Secure Email certificate to sign and encrypt your organization emails. Signing authenticates your organization as the sender, adding an extra level of assurance for recipients, while encryption protects sensitive email data.

Before you begin

CSR requirements

You must provide a certificate signing request (CSR) before DigiCert can issue your Secure Email for Organization certificate. You can include a CSR with your request. Or, after submitting your request, you can generate it in the browser.

Secure Email certificates support the following algorithms and key lengths:

  • RSA 2048, 3072, and 4096

  • ECC p-256 and p-384

Provide a CSR now.

You can only add a CSR when you place your request. After submitting your order, you cannot add or update a CSR.

We only use the public key embedded in the CSR to create your certificate. All other fields in the CSR are ignored. Learn how to Create a CSR (Certificate Signing Request).

Provide a CSR later.

After DigiCert processes your order and you complete the necessary email address validation, we send instructions to the email recipient for generating the CSR and certificate in their browser. Learn how to Generate your client certificate using DigiCert's KeyGen tool.

Email address domain requirements

Before DigiCert can issue your Secure Email for Organization certificate, you must demonstrate control over the domains in the email addresses on the certificate order. In other words, if you add, you must complete the domain control validation (DCV) for the email address domain

Use one of the following domain validation options to demonstrate control over the email address domain:

Organization validation

Before DigiCert can issue a Secure Email for Organization certificate, we must validate the organization for SMIME – SMIME Organization Validation. Organization validation is valid for 825 days. See How do we validate your organization.

Use one of the following options to validate your organization:

  • Validate the organization before ordering certificates

    CertCentral features an organization validation process that allows you to validate your organization before ordering certificates. Completing the organization validation ahead of time allows for quicker certificate issuance. See Submit an organization for prevalidation.

  • Validate the organization as part of the order process

    If you add a new organization or an organization with expired S/MIME validation, DigiCert will complete the S/MIME organization validation as part of the order process

Certificate profile

Before filling out the certificate request form, you must select a certificate profile for your Secure Email for Organization certificate. DigiCert currently supports three profiles:Multipurpose, Strict, and Legacy.

The profile affects the certificate validity and the supported certificate usages.

  • Certificate validity:

    • One year and two-year certificates – Strict and Multipurpose

    • One year, two year, and three-year certificates - Legacy

  • Additional certificate usage:

    • Non-repudiation – Strict, Multipurpose, and Legacy

    • Data encipherment – Multipurpose and Legacy

    • Client authentication – Multipurpose and Legacy

  • See Profile option below.

Order a Secure Email for Organization certificate

  1. In the left main menu, go to Request a Certificate > Secure Email Certificates > Secure Email for Org.

  2. On the Request Secure Email for Organization Certificate page, in the For menu, select the division to manage the certificate.

    The For menu only appears if your account uses Divisions.

  3. Profile option

    In the menu, select the profile you want to use for your certificate:

    • Strict

      If you are unsure which profile to select and only need a certificate to secure your email, select Strict.

      • Certificate validity: 1 year and 2 years

      • Additional certificate usages: Non-repudiation

    • Multipurpose

      If you need the additional certificates usages, select Multipurpose.

      • Certificate validity: 1 year and 2 years

      • Additional certificate usages: Non-repudiation, Data encipherment, Client authentication

    • Legacy

      Only select Legacy if you have a specific reason/need to use this profile. Otherwise, select Multipurpose as this profile supports the same certificate usages.

      • Certificate validity: 1 year, 2 years and 3 years

      • Additional certificate usages: Non-repudiation, Data encipherment, Client authentication

  4. Certificate validity

    Under Certificate validity, do the following:

    1. Validity period

      Select a validity period for the certificate:

      • 1 year

      • 2 years

      • 3 years - only available with the Legacy profile

      • custom expiration date

      • custom length

    2. Auto-renew

      To set up automatic renewal for this certificate, check Auto-renew order 30 days before expiration.

      With auto-renew enabled, DigiCert automatically submits a request to renew the order thirty days before it expires. This option is not available if you pay with a credit card.

      You must charge the order to the account balance to use the automatic renewal option. To configure your account's finance settings, in the left main menu, go to Finances > Settings.

  5. Organization

    You can add an existing organization from your account or a new organization. If you add a new organization, it will be added to your account.

    Under Organization, select Add an organization. In the Add organization window, complete the following task as needed:

    • Add an existing organization.

      1. Select An existing organization.

      2. In the menu, select the organization and then select Add.

        If you choose an organization not validated for S/MIME certificates or if the organization's validation has expired, DigiCert must validate the organization for S/MIME validation before we can issue your certificate.

      3. Organization and technical contacts.

        DigiCert automatically adds the contacts assigned to the organization to the request form. To see the organization and technical contacts, select Show organization contacts.

    • Add a new organization.

      1. Select A new organization and select Next.

      2. Under Organization address details, enter your organization's legal name, assumed name (optional), address, and phone number.

        DigiCert must validate the new organization for S/MIME validation before we can issue your certificate.

      3. When ready, select Add.

      4.  Add an organization contact.

        The organization contact is the person we contact when validating the organization and verifying your authority to order a DigiCert certificate for the organization. They may also receive the following notifications: Order status updates for certificates requested for their organization and Domain status updates for domains associated with their organization.

        In the Add organization window, add yourself or someone else from your account or create a new organization contact.

        • Add yourself as the organization contact.

          Select Add me as the organization contact and then select Add or Next.

          • If we have all your information, you will select Add.

          • If we need more information, you will select Next, enter the missing data, and then select Add.

        • Add someone else as the organization contact.

          Select Add someone else as the organization contact. Then, in the Add contact , select the contact or user and then select Add or Next.

          • If we have the needed user information, you will select Add.

          • If we need more user information, you will select Next, enter the missing data, and then select Add.

        • Create a new contact.

          1. Select Add someone else as the organization contact.

          2. In the Add contact menu, select Create new contact and then select Next.

          3. Enter the needed user information and then select Add.

    • Add a technical contact for the organization (optional)

      We may contact a technical contact for inquiries regarding certificate orders for the organization. They may receive the certificate lifecycle-related emails: certificate issued, reissued, and expiring.

      1. Select Show organization contacts.

      2. Select Add technical contact (Optional).

      3. Add yourself as the technical contact.

        Select Add me as the technical contact for the organization and then select Add or Next.

        • If we have all your information, you will select Add.

        • If we need more information, you will select Next, enter the missing data, and then select Add.

      4. Add someone else as the technical contact.

        1. Select Add someone else as the technical contact for the organization.

        2. Then, in the Add contact menu, select the contact or user and then select Add or Next.

          • If we have the needed user information, you will select Add.

          • If we need more user information, you will select Next, enter the missing data, and then select Add.

      5. Create a new contact.

        1. Select Add someone else as the technical contact for the organization.

        2. In the Add contact menu, select Create new contact and then select Next.

        3. Enter the needed user information and then select Add.

  6. Add your CSR

    You can add your CSR now or generate it in your browser after DigiCert processes your order, and we are ready to issue it.

    1. Generate CSR in the browser

      To generate the CSR and your certificate via the browser, select Generate CSR in the browser.

      For this option, we send instructions to the email recipient for using the DigiCert KeyGen tool to generate the CSR and certificate in their browser.

    2. I have my CSR

      You can only add a CSR when placing your request. After submitting your order, you cannot add or update a CSR.

      Use your CSR to specify the algorithm (RSA or ECC) and key size (e.g., 2048 (RSA) or p-256 (ECC)) for your certificate.

      1. To include a CSR with your request, select I have my CSR.

      2. Upload or paste your CSR in the box.

        Your CSR must include the -----BEGIN NEW CERTIFICATE REQUEST----- and -----END NEW CERTIFICATE REQUEST----- tags.

  7. Certificate details

    In your certificate details, you can include an email address or the organization name as the common name on the certificate.

    • Email address as the common name

      1. Select Email.

      2. Under Email address, enter the address you want to secure and use as the common name on the certificate and select Add.

      3. Under Additional email address (optional), enter other email addresses you want the certificate to secure.

        You can leave this box empty. You don't need to add any additional emails.

    • Organization name as the common name

      1. Select Organization.

        We automatically populate the common name with the name of the organization you added to the request form – Organization.

      2. Under Email address, enter the address you want the certificate to secure and select Add.

      3. Under Additional email address (optional), enter other email addresses you want the certificate to secure.

        You can leave this box empty. You don't need to add any additional emails.

  8. Additional certificate options

    Certificate key size

    When using the generate in browser option, you can select the algorithm and key size for generating your certificate.

    In the menu, select the algorithm and key size for generating your CSR:

    • RSA 2048, 3072, or 4096

    • ECC p-256 or p-384

    DigiCert recommends using RSA 2048 unless you have specific reasons for using a different key size (e.g., company policy requires a 3072-bit key size).

    Certificate use

    By default, DigiCert Secure Email certificates are dual use for signing and encrypting emails. However, you can update the certificate usage to meet your needs.

    1. RSA options

      To view and use the RSA options, add an RSA CSR to the request form or generate the CSR via the browser.

      1. Dual use - email signing and encryption

        Additional certificate usages:

        • Non-repudiation

        • Data encipherment – only available with the Multipurpose and Legacy profiles

        • Client authentication – only available with the Multipurpose and Legacy profiles

      2. Email signing only

        Additional certificate usages:

        • Non-repudiation

        • Client authentication – only available with the Multipurpose and Legacy profiles

      3. Email encryption only

        Additional certificate usages:

        • Data encipherment – only available with the Multipurpose and Legacy profiles

        • Client authentication – only available with the Multipurpose and Legacy profiles

    2. ECC options

      To view and use the ECC options, add an ECC CSR to the request form or generate the CSR via the browser.

      1. Dual use - email signing and encryption

        Additional certificate usages:

        • Non-repudiation

        • Client authentication – only available with the Multipurpose and Legacy profiles

        • Restrict key agreement

          • Encipher only

          • Decipher only

      2. Email signing only

        Additional certificate usages:

        • Non-repudiation

        • Client authentication – only available with the Multipurpose and Legacy profiles

      3. Email encryption only

        Additional certificate usages:

        • Client authentication – only available with the Multipurpose and Legacy profiles

        • Restrict key agreement

          • Encipher only

          • Decipher only

    3. Signature Hash

      By default, DigiCert issues RSA certificates with a SHA-256 signature hash and RSA signing algorithm. DigiCert recommends using the default RSA settings unless you have specific reasons for using a different key size or signing algorithm (e.g., company policy requires a 3072-bit key size or an RSASSA-PSS signature).

      In the menu, select the signature hash and signing algorithm you want DigiCert to use for your certificate:

      • SHA-256 with RSA

      • SHA-384 with RSA

      • SHA-512 with RSA

      • SHA-256 with RSASSA-PSS

      • SHA-384 with RSASSA-PSS

      • SHA-512 with RSASSA-PSS

      With ECC certificates, there is a one-to-one correlation between the signature hash and the signing algorithm.

      • When using the ECC p-256 key size, your certificate includes a SHA-256 signature hash with ECDSA signing algorithm.

      • When using ECC p-384 as the key size, your certificate includes a SHA-384 signature hash with ECDSA signing algorithm.


      The industry does not support issuing ECC certificates with an RSASSA-PSS signing algorithm. If you require an RSASSA-PSS signature, get an RSA certificate instead.

  9. Additional order options

    Expand Additional order options and add information as needed.

    The information in this section is not required to issue your certificate. Adding comments and messaging are optional.

    • Additional Renewal Message (optional)

      To create a renewal message for this certificate, type a renewal message with information that might be relevant to the certificate’s renewal. Comments and renewal messages are not included in the certificate.

    • Additional emails (optional)

      Enter the email addresses (comma separated) for the people you want to receive the certificate notification emails with information such as certificate issuance and certificate renewals.

      These recipients don't manage the order. They only receive all the certificate-related emails.

  10. Payment information

    Under Payment information, select a payment method to pay for the certificate:

    • Pay with credit card

      We authorize the credit card when you make the request. However, we only complete the transaction once we issue your certificate.

    • Pay with contract terms

      When you have a contract, it is the default payment method.

    • Pay with account balance

      Bill the cost to your account balance. To deposit funds, select the Deposit link. Selecting the link takes you to another page inside your CertCentral account. Any information entered in the request form will not be saved.

  11. Master Services Agreement

    Read through the Master Services Agreement.

  12. Select Submit Request.

    By selecting Submit Request, you agree to the Master Service Agreement.

What's next

Before we can issue your certificate, these tasks must be completed:

  1. Demonstrate control over the domains on your order

    Complete the domain validation for the email address domains on the order (demonstrate control over the domain). See Supported DCV methods for validating the domains on certificate orders.

  2. Complete organization validation

    DigiCert must validate and authenticate your authority to order a certificate for the organization on your certificate order. To do this, we will call a verified phone number to speak with someone who represents you, the certificate requestor, such as the organization or technical contact.

    To get organization consent for your certificate order:

    • Answer the organization/validation phone call (preferred method)*.

      • After you submit your certificate order, ensure that the organization contact, technical contact, and company receptionist know you’ve ordered a Secure Email for Organization certificate.

      • Let them know DigiCert will call a verified phone number to speak with one of them to complete organization validation/authentication.

      • This phone call usually takes place within 24 hours of the order being placed.

    • Respond to the organization consent message.

      • If the DigiCert validation agent can’t reach someone who represents you at the verified phone number, they will leave a message with a call-back phone number and a verification code.

      • Make sure that the organization or technical contact responds to the message and provides the verification code.

Getting your Secure Email for Organization certificate

  • Generate CSR in the browser

    After all email addresses are validated, a link will be sent to the first email address on the list so the recipient can generate the CSR and Secure Email certificate via the browser. See Generate your client certificate.

  • Included a CSR with your request

    After all email addresses are validated, the client certificate will be attached to the "client certificate issued" email. You can also download a copy from your account.

