Obsidian SuiteDocumentation
Obsidian Mail Client: all chapters

Docs / Obsidian Mail Client / Privacy & security

Encryption, app lock and S/MIME

Your mail on this computer is encrypted

The app keeps a copy of your mail on your PC, so it opens instantly and works offline. That copy is encrypted with AES-256. The key is sealed to your Windows account, so a copy of the files is unreadable on another PC or under another Windows account.

There's nothing to set up: the app encrypts its copy the first time it starts. File > Options > Security shows the state under This computer.

Lock the app with Windows Hello

You can make the app ask for your face, fingerprint or PIN.

  1. Go to File > Options > Security.
  2. Check Require Windows Hello to open Obsidian Mail Client (face, fingerprint or PIN).
  3. Click OK.

From then on, the app opens locked and shows Unlock with Windows Hello. It locks again every time it goes to the tray, for example when you close its window. While it's locked, new-mail notifications only say who wrote, not what.

The option needs Windows Hello to be set up. If it isn't, the page says so: set it up in Windows Settings > Accounts > Sign-in options. If Windows Hello is later turned off, the app opens unlocked rather than shut you out.

Signed and encrypted mail (S/MIME)

S/MIME works as it does in Outlook:

  • Signing a message proves it's from you and wasn't changed on the way.
  • Encrypting a message means only the recipients can read it and its attachments.

Encrypting needs a certificate for every recipient. For people who have none, send a secure link instead.

Get a digital ID

You need a digital ID (an S/MIME certificate) for your address. Get one from a certificate authority (some give free S/MIME certificates), then:

  1. Go to File > Options > Security.
  2. Under Digital IDs (S/MIME certificates), click Import a digital ID (.pfx / .p12)….
  3. Pick the file and type The file's password.

The ID is kept in Windows' own certificate store, where Outlook keeps it too. The page lists each account and its digital ID, with its expiry date. Certificates in Windows… opens Windows' certificate manager.

Encrypt or sign a message

In the message window, click Encrypt or Sign before you send. To do it for every new message, check Encrypt contents and attachments of outgoing messages or Add a digital signature to outgoing messages under New messages in File > Options > Security. You can still change both for each message.

To encrypt to someone, you need their certificate. The app collects it when you open a signed message from them, so ask them to send you one first. You also need your own digital ID, to read your copy in Sent Items.

If a certificate is missing, the app tells you which one and asks whether to send without encryption (or without a signature). It never sends an encrypted message unencrypted without asking.

Reading signed and encrypted mail

A signed message shows who signed it and whether the signature is valid and the certificate trusted. An encrypted message opens only when your digital ID is on this computer.