---
sourceDocument: Brazil ServiceNow AI Platform Administration
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-administration

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil ServiceNow AI Platform Administration

ft:clusterId :

    - platadm

bundleId :

    - platadm

workflow :

    - Platform


---

# Email encryption

# Email encryption - S/MIME protocol {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Email encryption - S/MIME protocol

S/MIME (Secure/Multipurpose Internet Mail Extensions) is an end-to-end email encryption protocol designed to ensure data confidentiality, authenticity, and integrity through digitally signed and encrypted emails.
It enables ServiceNow customers to securely send and receive emails with verified sender identities and protected content.
Show full answer Show less  

## Key Features

* **Digital Signatures and Verification:** Verifies the sender's identity and guarantees that the email message is exactly as sent, preventing impersonation.
* **Message Encryption and Decryption:** Encrypts email content so only intended recipients with the correct private key can decrypt and read it, ensuring confidentiality and data integrity.
* **Public Key Infrastructure:** Uses asymmetric cryptography with key pairs (private and public keys). The sender's private key signs emails, while public keys are exchanged via digital certificates to enable encryption and signature verification between sender and recipient.
* **Digital Certificates:** Issued by certification authorities (CAs), certificates validate identity and enable secure sharing of public keys. ServiceNow does not provide S/MIME certificates; customers must acquire them from third-party providers.
* **Integration with ServiceNow AI Platform:** The platform uses private keys to sign outbound emails and recipients' public keys to encrypt them. For inbound emails, the platform verifies signatures and decrypts messages using the appropriate keys.
* **Activation:** Administrators with the admin role can enable S/MIME Email by activating the plugin `com.glide.email.smime` for Notifications within ServiceNow.

## Key Outcomes

* Secure email communication with verified sender identities and protected content.
* Prevention of email tampering, spoofing, and unauthorized access to sensitive information.
* Improved trust and compliance in email exchanges through use of digital certificates and cryptographic processes.
* Seamless integration of S/MIME capabilities into ServiceNow email infrastructure for both inbound and outbound messages.  
Secure/Multipurpose Internet Mail Extensions (S/MIME) is an end-end encryption protocol
for sending digitally signed and encrypted emails that support data confidentiality, authenticity,
and integrity.

## Introduction to S/MIME {#smime-inbound-outbound-mails__section_xy5_xff_vtb}

An administrator with privileges can enable and configure S/MIME. Understanding of the following is required when using the full capabilities of S/MIME:

* Digital signatures and signature verification
* Message encryption and decryption
* Public key
* Digital certificates
{#smime-inbound-outbound-mails__ul_a33_fff_vtb}

## Digital signatures and verification {#smime-inbound-outbound-mails__section_zsj_jhf_vtb}

With digital signature, S/MIME verifies the identity of the sender of the email. This verification ensures the following:

* Message in the email is the exact message sent by the sender.
* Message is received from the right sender and not someone pretending to be the sender.
{#smime-inbound-outbound-mails__ul_q4p_rhf_vtb}

## Message encryption and decryption {#smime-inbound-outbound-mails__section_flk_khf_vtb}

S/MIME uses encryption to protect the content of the email, which ensures that only the
receiver can decrypt the content. Encryption creates coded information so that it cannot be read
or understood until it is decoded and readable. Message encryption helps with the two key
security factors of confidentiality and data integrity.

## Public key {#smime-inbound-outbound-mails__section_odw_hhp_ttb}

S/MIME uses key pairs and asymmetric cryptography. A private key in a key pair belongs only to
the sender. If the private key has been used, the owner of that key has used it.

Public key cryptography ensures secure communication between the sender and the receiver. Both
have a key-pair, with one being private and the other public​.

Public keys are shared between the sender and the receiver. A public key is paired to only one
private key. The corresponding public key is used to identify its paired private key and only
its paired private key. A public key can be used by multiple recipients.  
A key pair can be used to

* Sign and verify a signature
* Encrypt and decrypt the content of an email
{#smime-inbound-outbound-mails__ul_e33_lqf_vtb}

S/MIME digital signatures and encryption require each sender and recipient to have it enabled.
They also need to send or exchange public keys though digital certificates to identify each
other.

For more information about key management and cryprographic module, see [Key Management Framework Reference](https://www.servicenow.com/docs/access?context=understanding-kmf&version=brazil&pubname=brazil-platform-security&ft:locale=en-US).

## Digital certificates {#smime-inbound-outbound-mails__section_zzp_krf_vtb}

Digital certificates help in delivering the public key in the key pair. A digital certificate is a digital credential that provides information about the identity, validity, and any other required information. Digital certificates are issued by a certification authority (CA) and are valid for only a specific period of time.  
Note:  
ServiceNow® does not provide S/MIME certificates for ServiceNow mail infra users. Users should get their S/MIME certificates issued from the third party S/MIME certificate solution providers.

## S/MIME outbound emails {#smime-inbound-outbound-mails__section_txr_vhg_vtb}

Signing outbound mails

The ServiceNow AI Platform uses the private key of the sender (instance email account)​ and
the receiver uses the public key to verify signatures.

Encrypting outbound mails

The ServiceNow AI Platform uses public keys of the recipients to encrypt the emails and every
recipient uses their private key to decrypt the email.

## S/MIME for inbound email {#smime-inbound-outbound-mails__section_xsh_nhp_ttb}

Sign verification for inbound mails

The sender uses a private key to sign the email and the ServiceNow AI Platform uses the
public key of the sender to verify the signature.

Decrypting inbound mails

The sender uses the public key to encrypt the email and the ServiceNow AI Platform uses the
private key to decrypt the email.
* **[Activate S/MIME Email](https://www.servicenow.com/docs/nTNKt0RKGgvIPpgHaUn9Aw)**   
  You can activate the S/MIME Email plugin (com.glide.email.smime) for Notifications if you have the admin role.
* **[Setting up S/MIME for email](https://www.servicenow.com/docs/IiSs~UFgIGhr4Pt~9ZlvqA)**   
  S/MIME is a protocol for sending digitally signed and encrypted emails to ensure the confidentiality, authenticity and integrity.

