S/MIME Certificate Installation – Microsoft Outlook (Windows)
Step-by-step technical guide for installing and configuring S/MIME email certificates in Microsoft Outlook on Windows for secure digital signing and encryption.
Introduction
An S/MIME email certificate allows you to digitally sign and encrypt your email communications. While the encryption strength remains the same regardless of the certificate type, the level of identity information displayed to the recipient when signing varies.
View all our email certificates here.
Certificate Type Comparison
| Feature | GlobalSign PersonalSign 1 | DigiCert Secure Email for Individual | DigiCert Secure Email for Business |
|---|---|---|---|
| Email address(es) | ✓ (1 address) | ✓ (+2 free SANs) | ✓ (+3 free SANs) |
| Employee name / pseudonym | ✗ | ✗ | ✓ |
| Organisation name | ✗ | ✗ | ✓ |
| Validation | Email (DV) | Email (DV) | Organisation (OV) |
| Price / year | 400 DKK | 500 DKK | 950 DKK |
| Issuance time | Minutes | Minutes | 1-5 days |
We also provide GlobalSign Qualified Electronic Signature (QES, 4,000 DKK/year) and GlobalSign Qualified Electronic Seal (QESeal, 8,650 DKK/year) – these are qualified electronic signatures and seals supplied on QSCD-compliant USB tokens.
Shared Mailboxes
For shared mailboxes such as support@fairssl.dk, legal@fairssl.dk, or sales@fairssl.dk, we recommend the DigiCert Secure Email for Business certificate using a pseudonym instead of an individual employee name. Note that pseudonyms must not contain spaces – use terms like Sales, TechDepartment, or Support. The certificate will display the organisation name, the pseudonym, and the associated email address(es).
Installation in Outlook (Classic)
This method applies to Outlook 2016, 2019, and the Classic edition of Microsoft 365. Microsoft has committed to supporting Classic Outlook until at least 2029.
Open Outlook. Navigate to File and select Options.

Select Trust Center from the left-hand menu, then click Trust Center Settings.

Click Email Security in the left pane, then click Import/Export.

Click Browse to locate your certificate file (.pfx). Enter the password for the file and click OK.

Confirm the import by clicking OK.

Click Settings. Name your security setting (e.g., "Default S/MIME"). Click Choose next to Signing Certificate.

Select your certificate. If it is not visible, click More choices to see the full list.

Ensure SHA256 is selected as the Hash Algorithm.

Click Choose next to Encryption Certificate and select the same certificate.

Select AES (256-bit) as the Encryption Algorithm. Click OK and close all dialogue boxes to return to Outlook.

For quick access: Open a new email, go to File → Options → Customize Ribbon. Create a new group (e.g., "Security") and add the Sign and Encrypt commands from the "All Commands" list.

The Encrypt and Sign buttons will now be available in the ribbon of all new email windows.

Installation in New Outlook (Windows)
Microsoft is gradually rolling out "New Outlook" as a replacement for the classic desktop client. New Outlook uses a different configuration interface and does not include the Trust Center.
- Click the cog icon (Settings) in the top-right corner.
- Navigate to Mail → S/MIME.
- Click Import, select your .pfx file, and enter the password. Click Import.
- Enable "Add a digital signature to all messages I send" and, if required, "Encrypt contents and attachments for all messages I send".
Note: New Outlook does not automatically pull certificates from the Windows Certificate Store. You must manually import the .pfx file via the Outlook settings menu.
Which version am I using?
If you see File → Options in the menu bar, you are using Classic Outlook. If you see a cog icon for settings without a traditional File menu, you are using New Outlook.