hero-faq-1

FAQs

Are Free S/MIME Certificates Worth It?

Free certificates from some CAs offer basic encryption and signing, but they’re limited to mailbox validation, include no vendor support, and cannot display your organization’s identity. Paid email certificates from Sectigo or DigiCert add support, organization or sponsor validation, document signing capabilities, and multi-year coverage.

Copy Link

How Long Is an S/MIME Certificate Valid?

SSL Dragon’s email signing certificates are valid for up to 2 years. Under the CA/Browser Forum’s S/MIME Baseline Requirements, Strict and Multipurpose certificate profiles have a maximum validity of 825 days.

Copy Link

Which Email Clients Support S/MIME?

Most major clients: Microsoft Outlook, Apple Mail, Mozilla Thunderbird, iOS Mail, and Gmail for Google Workspace enterprise accounts. Exchange-based environments support S/MIME natively.

Copy Link

Do Both Sender and Recipient Need an S/MIME Certificate?

For encryption, yes. Both parties need certificates so they can exchange public keys. For digital signing alone, only the sender needs one. Sending a signed email automatically shares your public key with the recipient, letting them reply with an encrypted message.

Copy Link

What Is the Difference Between S/MIME and TLS for Email?

TLS encrypts the connection between mail servers during delivery. S/MIME protects the email content itself, regardless of where it’s stored or how many servers it passes through. They solve different problems and work best together: TLS protects transit, while S/MIME keeps messages encrypted at rest on the server.

Copy Link

How long does it take to get an SSL certificate for an IP address?

About 5 minutes for the GoGetSSL Public IP SAN (DV). Sectigo and Comodo InstantSSL Pro take 1–2 business days because Business Validation requires verification of company documents.

Copy Link

What if I need to secure a private or internal IP address?

A public CA cannot issue for private IPs. Sectigo Private PKI is the production answer; self-signed certs are only suitable for non-trusted internal testing.

Copy Link

Does an IP certificate use weaker encryption than a domain certificate?

No. Same TLS 1.2 and 1.3 protocols, same RSA and ECC key options, same warranty levels.

Copy Link

Can one certificate cover an IP address and a domain name?

Yes. The GoGetSSL Public IP SAN supports up to 250 SAN entries combining public IPs and fully-qualified domain names on a single certificate. For domain-only setups across many hostnames, see the Multi-Domain SAN certificate range.

Copy Link

Can I get an SSL certificate for any IP address?

No. Only public, routable IPs are eligible. DV and BV are both available for IP certificates, but EV is not: the CA/Browser Forum does not permit Extended Validation for IPs at all.

Copy Link