S/MIME Certificate Setup – Mozilla Thunderbird
Step-by-step guide for installing an S/MIME email certificate in Mozilla Thunderbird for digital signing and message encryption.
Introduction
An S/MIME email certificate allows you to digitally sign and encrypt your emails. While the encryption strength remains the same regardless of the certificate type, the primary difference lies in the identity information displayed to the recipient upon signing.
See all our email certificates here.
Certificate Type Comparison
| Feature | GlobalSign PersonalSign 1 | DigiCert Secure Email for Individual | DigiCert Secure Email for Business |
|---|---|---|---|
| Email Address(es) | ✓ (1 address) | ✓ (+2 free SANs) | ✓ (+3 free SANs) |
| Employee Name / Pseudonym | ✗ | ✗ | ✓ |
| Organisation Name | ✗ | ✗ | ✓ |
| Validation Type | Email (DV) | Email (DV) | Organisation (OV) |
| Price / year | 400 DKK | 500 DKK | 950 DKK |
| Issuance Time | Minutes | Minutes | 1-5 days |
We also offer GlobalSign Qualified Electronic Signature (QES, 4,000 DKK/year) and GlobalSign Qualified Electronic Seal (QESeal, 8,650 DKK/year) – qualified electronic signatures and seals provided on QSCD USB tokens.
Shared and Departmental Mailboxes
For shared mailboxes such as support@fairssl.dk, legal@fairssl.dk, or sales@fairssl.dk, we recommend DigiCert Secure Email for Business using a pseudonym instead of an individual name. Note that the pseudonym must not contain spaces – for example, use Sales, TechDepartment, or Support. The certificate will display the organisation name, the pseudonym, and the associated email address(es).
Installation in Thunderbird
Mozilla Thunderbird has built-in S/MIME support, so no additional plugins are required.
Open Thunderbird. Go to Settings (⚙) → Account Settings.
Select your email account from the left-hand sidebar. Click on End-To-End Encryption.
In the S/MIME section, click Manage S/MIME Certificates. (In older versions: Security → Manage Certificates)
Click the Your Certificates tab, then click Import. Locate your .pfx file and enter the password.
Back in Account Settings → End-To-End Encryption: Click Select next to Personal certificate for digital signing. Choose the imported certificate.
Thunderbird will ask if you want to use this certificate for encryption as well – select Yes.
Under Default settings, you can choose:
- Require encryption by default – for mandatory encryption.
- Digitally sign messages (by default) – recommended for all outgoing mail.
Click OK. When composing a new message, you will find the Sign/Encrypt buttons under the Security (🔒) menu in the compose window.
CSR Generation in Thunderbird (Version 128+)
From Thunderbird 128, you can generate a CSR (Certificate Signing Request) directly within the application, without using OpenSSL or other external tools. Under End-To-End Encryption → S/MIME, you will find the button "Generate and save a CSR file as...". Save the CSR and send it to your certificate provider to have your S/MIME certificate provisioned.
Thunderbird on Linux
The process is identical on Linux. Thunderbird maintains its own internal certificate database independent of the system keyring, so the .pfx file is imported directly into Thunderbird regardless of your operating system.