Skip to main content

    S/MIME Certificate Validation Types: Mailbox, Organization, Sponsor and Individual

    Mailbox, organization, sponsor and individual validation: what each S/MIME type proves, the policy OIDs, and how to check which one you hold.

    MS
    My-SSL Team
    ·
    14 min read
    ·
    Published August 12, 2026
    ·
    Last updated August 12, 2026

    The short answer

    The CA/Browser Forum's S/MIME Baseline Requirements define four certificate types, and every publicly trusted S/MIME certificate is exactly one of them: mailbox-validated, organization-validated, sponsor-validated, or individual-validated. All four require the certificate authority to confirm control of the email address, and they differ only in whose identity is verified and written alongside it — nobody's, a company's, a named employee's together with their employer's, or a named individual's. Each type also comes in a generation (Legacy, Multipurpose or Strict) that governs what else the certificate may contain, and since July 15, 2025 Legacy profiles can no longer be issued. You can tell which combination you hold by reading a single certificate policy OID under the arc 2.23.140.1.5.

    If you already know which type you need and want to move, the S/MIME email certificates we issue cover both the individual and the organization-backed profiles. If you are still working out which one your situation calls for, the rest of this page is the decision.

    What each of the four S/MIME certificate types places in the certificate subject, above a shared band showing that all four verify control of the mailbox addressA band across the top states the constant: in all four types the certificate authority confirms control of the mailbox address, which appears in the subject alternative name extension. Below it, four panels show what each type adds. Mailbox-validated carries the email address, and optionally a common name and serial number, and asserts nothing about who holds it. Organization-validated carries legal-entity attributes only, asserting that a verified company controls the address, which suits shared role addresses. Sponsor-validated, highlighted in gold, combines natural-person attributes with an organization name, asserting that a named person is associated with a named company. Individual-validated carries natural-person attributes alone, with no organization. A closing bar states the takeaway: the mailbox is the constant across all four, and the type only records whose identity was verified alongside it.All four verify the same mailbox — they differ in who else is namedCONSTANT IN EVERY TYPE — control of the mailbox addresssubjectAltName: rfc822Name = you@example.comTYPE 1Mailbox-validatedSubject: email address, plus anoptional common name and serialSays nothing about who holds it.Issued in minutes.TYPE 2Organization-validatedSubject: legal-entity attributesonly — no natural personA verified company controls theaddress. Fits billing@, support@.TYPE 3Sponsor-validatedSubject: natural-person attributestogether with organizationNameA named person at a named company.The employee profile.TYPE 4Individual-validatedSubject: natural-person attributesonly — no organizationA named person signing in apersonal capacity.Picking a type is not about how much encryption you get. It is about how much identity a recipient can check.
    Encryption strength is identical across all four. The only thing that changes is how much a relying party can establish about the sender without taking your word for it.

    Most buying guides frame this as personal versus business, which is a reasonable shorthand for a shop window and a poor guide to what you actually receive. The four types are the real taxonomy: they are written into the requirements every publicly trusted CA is audited against, they are recorded in the certificate itself, and they are what a relying party can check. Product names are not. What follows is what each type asserts, how to read the type out of a certificate you already hold, and which one fits the way your mail is actually sent.

    What are the four S/MIME certificate types?

    They are mailbox-validated, organization-validated, sponsor-validated and individual-validated, and the difference between them is the contents of the certificate subject. Mailbox-validated is limited to an email address with an optional common name and serial number. Organization-validated carries legal-entity attributes only. Sponsor-validated combines natural-person attributes with an organizationName. And individual-validated carries natural-person attributes with no organization at all.

    An S/MIME certificate is recognisable in the first place by two things: an extended key usage of id-kp-emailProtection (OID 1.3.6.1.5.5.7.3.4), and a mailbox address in the subject alternative name extension, carried either as an rfc822Name or, for internationalised addresses, as an otherName of type id-on-SmtpUTF8Mailbox. Every publicly trusted S/MIME certificate has both, whichever of the four types it is.

    One consequence is worth stating plainly, because it is the thing people most often get backwards: the type has no bearing on the cryptography. A mailbox-validated certificate and a sponsor-validated certificate protect a message identically. What differs is how much a recipient can establish about who sent it — and, therefore, how much your signature is worth to somebody who does not already know you.

    What does each type actually prove?

    Section 3.2 of the requirements sets out three separate checks — mailbox control, organization identity and individual identity — and each type is defined by which of the three the CA must complete. Mailbox-validated needs the first alone. Organization-validated needs mailbox control plus organization identity. Individual-validated needs mailbox control plus individual identity. Sponsor-validated is the only type that requires all three.

    Matrix of which three identity checks a certificate authority must perform for each of the four S/MIME certificate typesA grid with four rows, one per certificate type, and three check columns: mailbox control, organization identity, and individual identity. Mailbox-validated requires mailbox control alone. Organization-validated requires mailbox control and organization identity. Sponsor-validated, highlighted in gold, is the only type requiring all three checks, which is why it takes the longest to issue. Individual-validated requires mailbox control and individual identity but no organization check. A closing bar notes that each additional column is evidence a person has to supply and a certificate authority has to review, so the row you choose sets your issuance time far more than the price does.What the CA has to verify before it will issueCERTIFICATE TYPEMAILBOXORGANIZATIONINDIVIDUALMailbox-validatedOrganization-validatedSponsor-validatedIndividual-validatedEVERY EXTRA COLUMN IS PAPERWORK AND REVIEW TIMEThe row you pick decides how long issuance takes far more than the price does. Sponsor-validated needs all three.
    Read this before promising a rollout date. A mailbox-validated batch can be live the same afternoon; a sponsor-validated batch waits on identity documents from every person on the list.

    Mailbox control itself has more than one permitted method, and the choice affects your timeline more than most people expect. A CA can prove authority over the whole email domain using the same kinds of checks used for TLS certificates, or it can prove control of a single mailbox by sending something to it, or it can confirm the applicant runs the associated mail servers. There is also an ACME-based method, which is what makes automated S/MIME issuance possible for organisations willing to run the plumbing.

    Organization and individual identity are heavier. Organization identity means the CA establishes that the legal entity exists and that the attributes going into the certificate match a reliable source. Individual identity means verifying a natural person, normally against identity documents. Neither can be waved through, and neither is instant. If your rollout plan assumes sponsor-validated certificates for forty people will arrive as quickly as mailbox-validated ones, the plan is wrong by days rather than hours.

    There is one registration shortcut worth knowing about. Sponsor-validated certificates may be registered through an Enterprise RA — an organisation the CA has delegated certain request duties to — which is how a company issues to its own staff without every employee dealing with the CA directly. For a broader look at where email certificates fit alongside the rest of a certificate estate, see what an email certificate is and how S/MIME works.

    What are the Legacy, Multipurpose and Strict generations?

    Generations are a second axis, applied on top of the type, that controls what else the certificate is allowed to contain. There are three: Legacy, Multipurpose and Strict. Legacy existed to let pre-existing CA practices become auditable when the requirements first arrived, and it has been closed since July 15, 2025 — subscriber certificates may no longer be issued under any of the four Legacy policy OIDs. That leaves Multipurpose and Strict as the only live choices.

    The practical difference is the extended key usage extension. Strict requires id-kp-emailProtection and forbids any other value, so a Strict certificate does email and nothing else. Multipurpose requires email protection too but permits additional values alongside it, which is how one certificate can sign mail and authenticate a user to a system. Neither generation may ever carry server authentication, code signing, time stamping, or anyExtendedKeyUsage — those are prohibited outright.

    GenerationExtended key usageMaximum validityStatus
    StrictEmail protection only; nothing else permitted825 daysCurrent, and the long-term target profile
    MultipurposeEmail protection, plus other values where needed825 daysCurrent; the choice when client authentication matters
    LegacyEmail protection, plus other values1,185 daysClosed to new issuance since July 15, 2025

    That validity column explains a stubborn piece of misinformation. A great deal of published material still says S/MIME certificates run for up to three years, and the figure was accurate when Legacy allowed 1,185 days. It is not accurate for anything issued today. As of August 2026 the ceiling is 825 days, a little over two years, for both live generations — and the requirements themselves suggest CAs should stop short of the maximum, because of how the day count is defined.

    How do I tell which type my certificate is?

    Read the certificate policies extension and find the OID under the arc 2.23.140.1.5. The digit that follows the arc is the type — 1 mailbox-validated, 2 organization-validated, 3 sponsor-validated, 4 individual-validated — and the digit after that is the generation, with 1 Legacy, 2 Multipurpose and 3 Strict. Two numbers, and you have identified the certificate exactly, without relying on whatever the product was called at checkout.

    Anatomy of an S/MIME certificate policy object identifier, showing which digit encodes the certificate type and which encodes the generationThe example object identifier 2.23.140.1.5.3.2 is split into labelled segments. The leading 2.23.140.1 identifies the CA/Browser Forum certificate policies arc. The next digit, 5, marks the S/MIME baseline. The following digit is the certificate type and the final digit, highlighted in gold, is the generation. Two lookup lists follow. Type digits: 1 is mailbox-validated, 2 is organization-validated, 3 is sponsor-validated, 4 is individual-validated. Generation digits: 1 is Legacy, which certificate authorities have not been permitted to issue since July 15 2025, 2 is Multipurpose, and 3 is Strict. A closing bar reads the example back: the object identifier 2.23.140.1.5.3.2 is a sponsor-validated certificate of the Multipurpose generation.One OID tells you both the type and the generation2.23.140.1532CA/Browser Forum policiesS/MIME baselineTYPEGENERATIONTYPE DIGIT1 — mailbox-validated2 — organization-validated3 — sponsor-validated4 — individual-validatedWhose identity was verified.GENERATION DIGIT1 — Legacynot issuable since July 15, 20252 — Multipurpose3 — StrictWhat else the certificate may contain.READING THE EXAMPLE BACK2.23.140.1.5.3.2 is a sponsor-validated certificate of the Multipurpose generation. No product name required.
    Worth committing to memory if you audit certificates. Vendors name their products whatever they like; this arc is fixed by the requirements and means the same thing whichever CA issued the certificate.

    For a PEM-encoded certificate, one command is enough:

    openssl x509 -in mycert.pem -noout -text | grep -A2 "Certificate Policies"

    S/MIME certificates are more often delivered as a password- protected PKCS#12 file, in which case extract the certificate part first and pipe it through:

    openssl pkcs12 -in mycert.p12 -nokeys -clcerts | openssl x509 -noout -text

    Then read the whole subject while you are in there. If the subject shows an organizationName next to a person's given name and surname, you are holding a sponsor-validated certificate whatever the invoice said. If it shows an email address and little else, it is mailbox-validated. The OID and the subject should agree; if they do not, that is worth raising with the CA. The general layout of these fields is covered in our walkthrough of X.509 fields and extensions.

    TypeLegacyMultipurposeStrict
    Mailbox-validated2.23.140.1.5.1.12.23.140.1.5.1.22.23.140.1.5.1.3
    Organization-validated2.23.140.1.5.2.12.23.140.1.5.2.22.23.140.1.5.2.3
    Sponsor-validated2.23.140.1.5.3.12.23.140.1.5.3.22.23.140.1.5.3.3
    Individual-validated2.23.140.1.5.4.12.23.140.1.5.4.22.23.140.1.5.4.3

    The four OIDs ending in .1 are the Legacy ones. Seeing one of those in a certificate is not a fault — it simply means the certificate was issued before July 15, 2025, and its replacement will carry a different profile.

    Which validation type do you need?

    Start from what you want a recipient to be able to verify, not from a price list. If the answer is only that the message came from that address, mailbox-validated is enough. If it is that a company stands behind a shared address, organization-validated is the fit. If it is that a specific employee sent it on the company's behalf, sponsor-validated is the only type that says so. And if a named person is signing for themselves, individual-validated does it without inventing an employer.

    Decision tree for choosing an S/MIME certificate type and generationThe tree starts from one question: whose identity should the certificate assert. Four answers lead to four outcomes. If nobody's, only the address itself, choose mailbox-validated. If a company's, for a shared role address such as billing or support, choose organization-validated. If a named employee acting for their employer, highlighted in gold as the common business answer, choose sponsor-validated. If a named individual with no company, choose individual-validated. A second question follows underneath: does the certificate also need to authenticate to a system. If it is for email only, the Strict generation is the cleaner choice; if it must also serve client authentication, the Multipurpose generation is required because Strict forbids any extended key usage other than email protection.Two questions get you to the right certificate1. Whose identity should the certificate assert?Nobody's — justthe address itselfMailbox-validatedFastest to issueA company's, for ashared role addressOrganization-validatedbilling@ support@A named employee,acting for the firmSponsor-validatedThe usual business answerA named individual,with no companyIndividual-validatedConsultants, notaries2. Does it also need to authenticate to a system?Email onlyStrict generationAlso client authMultipurpose
    The second question is the one people skip, then rediscover months later when a Strict certificate refuses to authenticate anywhere except a mail client.

    A few patterns fall out of this that are worth naming. Role addresses — billing@, support@, invoices@ — should almost always be organization-validated, because they outlive the people who staff them and a certificate naming last year's finance manager ages badly. Regulated correspondence that has to attribute a document to a person, on the other hand, wants sponsor-validated, and no amount of organization validation substitutes for it.

    Mailbox-validated has a narrower place than its price suggests. It is genuinely useful for internal mail, for testing a deployment before committing budget, and anywhere the recipients already know who you are through some other channel. It is weak for exactly the case people buy it for — persuading an outsider that a message is genuine — because the certificate makes no claim about who holds it. Our individual and business S/MIME certificates cover the person-level and organization-backed options, and the S/MIME buying guide walks through the purchase itself, including client compatibility.

    Then answer the second question before you order, because it is the one that gets discovered late: does this certificate have a job beyond email? Strict is the cleaner profile and the direction the requirements are heading, but it will refuse to authenticate you to a VPN or a portal, by design. If a single credential has to do both, you need Multipurpose, and you need to confirm that is what the CA will issue.

    How long do they last, and when does validation repeat?

    As of August 2026, Strict and Multipurpose certificates may be issued for a maximum of 825 days. Separately, the requirements cap how long a CA may lean on validation work it has already done: organization identity and individual identity may each be reused for up to 825 days, mailbox control established through the domain or mail-server methods for up to 398 days, and mailbox control established by sending mail to the address for only 30 days.

    Those reuse windows are the reason renewals sometimes feel inconsistent. One renewal goes through in minutes and the next asks for identity documents again, and nothing about your account changed — the evidence behind the earlier issuance simply aged past its permitted reuse period. The 30-day window on email-based mailbox control is the tightest of the set, which is why a confirmation link tends to reappear on almost every reissue while the heavier identity checks do not.

    Plan renewals as a recurring obligation rather than an occasional event, particularly for a team. An expired S/MIME certificate does not only stop you signing: correspondents who hold your old certificate can keep encrypting to a key you are supposed to have retired, and anything already encrypted to it stays unreadable without the matching private key, so key backup deserves as much thought as renewal. Setting a reminder well before the date is worth the two minutes, and our certificate expiry reminder is free to use.

    One change is already scheduled and worth a note in the calendar. Effective September 15, 2027, a CA may not issue S/MIME certificates from an issuing CA whose RSA key is smaller than 3072 bits, and CA certificates signed on or after September 15, 2026 must use at least a 4096-bit RSA key. Neither affects the key in your own certificate — subscriber RSA keys stay at a 2048-bit minimum — but both may change which issuing CA your certificates chain to, which matters if anything in your environment pins an intermediate.

    Frequently Asked Questions

    Get instant answers to common questions about SSL certificates and our services.

    Still Have Questions?

    Our SSL experts are available 24/7 to help with any questions about certificates, installation, or technical issues.

    Getting the right type issued

    If you know which of the four types your mail needs, the ordering step is short. Our S/MIME certificates for individuals and organizations are issued from publicly trusted CAs, so the roots are already present in Outlook, Apple Mail and the other mainstream clients and your recipients install nothing. If you are unsure whether a role address should be organization-validated or sponsor-validated, ask us before you order — it is a five-minute question now and a reissue later.

    Related reading