Click here to subscribe
to our weekly newsletter
Exchange Messaging Outlook

EMO back issues




Encryption and Message Security Tools

These pages deal with tools and methods that add encryption, digital signatures, or rights management to individual messages. For tools dealing with securing Outlook and Exchange data with folder and user permissions, see:

  • Managing Exchange Server Permissions
  • To add encryption and security signatures to Exchange messages on the Internet, you can use either PGP (Pretty Good Privacy) or S/MIME (Secure MIME.) S/MIME support is built into Outlook, starting with Outlook 98. See:

  • OL2000 - Encryption and Message Security Overview
  • OL2002 Encryption and Message Security Overview
  • Choose Tools | Options | Security. You can add S/MIME support to earlier versions with third-party utilities. CW users note: OL2000 (CW): Rich Text Signed Messages Are Always Sent As HTML. With Outlook 97, you can tell that you've received an S/MIME message if it has an attachment with one of these extensions: 

    .p7s Signed, but not encrypted
    .p7c Certificate only, no digital signature or encryption
    .p7m Signed and encrypted. Cannot be read except by an S/MIME client

    Outlook 2000 SR-1/1a adds support for S/MIME version 3, but most features need to be activated via Windows registry settings. A white paper, Microsoft Outlook 2000 Service Release 1, provides complete details.

    For S/Mime utilities, see S/MIME Encryption and Message Security Tools
    PGP add-ins are now found at PGP Encryption and Message Security Tools
    Public key servers and other services are listed at Secure E-mail Services
    Tools and utilities which do not fit any of the above categories are list at Encryption and Message Security Tools

     

    More Information

    Tools

    cGeep   cGeep Pro has been designed to automate and simplify encryption actions. Messages are decrypted automatically and attachments are decrypted in one click within Outlook. You are prompted only once for your decryption passphrase during each Windows session, it won’t be requested again for any file and email decryption. cGeep Pro is fully OpenPGP compliant.
    Classify   Inserts security classification labels into the first line of the message body and prevents messages from being sent until a classification label has been added. Separate versions available for Exchange and Outlook. Works with all versions of Outlook. Outlook 97 needs to be Version 8.04.5619 (or later) and Outlook 98 needs to be Version 8.5.5603.0 (or later); see instructions on Classify web site.
    ClickYes Pro   ClickYes Pro is a tuning tool for Microsoft Outlook security settings. It allows you to configure which applications can automatically send emails using Outlook and access email addresses stored in Outlook address book. ClickYes Pro runs as a background task providing a convenient icon in the taskbar notification area to manage allowed applications. It uses an encrypted storage and is highly secure and safe. Version 2.5.9
    eCipher   eCipher allows you to send and read encrypted messages directly through your existing desktop email client (Outlook, Thunderbird, Eudora). The current version supports reading encrypted mail from any webmail client (Gmail, Yahoo!, AOL, etc.). eCipher protected emails utilize strong encryption and digital signatures, ensuring that they can only be opened by the intended recipients. eCipher also provides extra security options for your email, including the ability to prevent message forwarding, copying, saving, and printing. Free trial.
    Ensuredmail   Security software for Outlook, Outlook Express and AOL mail, protecting messages and attachments and providing read receipts. Also can protect local files. Both sender and recipient need a copy of the program, but it's free.
    Entrust   Family of security products, including support for Exchange and Outlook users.
    FileSurf   Records management system for applying consistent retention policies to Microsoft Outlook, as well as other corporate data. FileSurf can manage the entire lifecycles of both physical and electronic records, including emails and their attachments. FileSurf is certified by the latest version of the U.S. DoD 5015.2 Standard for records management software. FileSurf is designed to be flexible, scalable and extensible to address the unique records management requirements of any organization.
    Folder Permissions Manager   Symprex Folder Permissions Manager allows administrators to centrally manage all permissions on mailbox folders and public folders on Exchange 5.5, 2000 and 2003. Folder permissions can be listed and changed manually, or using templates with permissions settings created using the built-in wizard. Permissions can be applied to any number of mailboxes and folders at the click of a button.
    iQ.Suite for Exchange   Tool suite for Exchange 2000 and 2003 provides anti-virus protection, disclaimers, spam and junk mail filtering, content-based filtering, PGP and S/MIME encryption, encrypted archival storage and mail forwarding.
    IronMail   Secure appliance for your enterprise gateway. IronMail combines spam and fraud prevention, web filtering, virus and worm protection, policy and content compliance, email privacy, and secure email capabilities into a single platform.
    Outlook Security Labels   Outlook COM add-in that security labels to digitally signed (S/MIME) messages. Security labels can be used to enforce a user's authorization to access the contents of the message. The label can also restrict which recipients can open, forward, or send the message.
    OutlookSpy   This update adds full support for the final version of Outlook 2007. It has a new hex viewer and editor for the binary (PT_BINARY) MAPI properties, a new script editor ("Script Editor" window and "Script" tab for the IDispatch-derived objects), along with several new symbolic MAPI property tags. OutlookSpy version 2.11 build 2.11.0.422
    OWA Prevent   Allows users to classify and label OWA messages to prevent leakage of sensitive information. Administrators can also block viewing of certain messages over OWA depending on message sensitivity, or if attachments are present. For Exchange 2003.
    Redemption   Supports Outlook 2007. This update contains many new features and bug fixes. See Redemption history for a complete list of changes in this build. Version 4.7.0.1026
    RightsEnforcer Email   Server and client software to allow users to set rights on documents sent as email attachments, adding a Send Secure Attachments button to Outlook. Can integrate with Microsoft Windows Rights Management to add protection to another 200 document types or operate by itself. Allows users to change the protection on a document after it has been sent.
    SAFEmail.mil Security Subsystem   Component of military messaging client based on Outlook supports S/MIME v.3 encryption and signatures.
    SAFEmail.net   Boldon James have extended the Microsoft OWA client to support military message handling. The extensions encompass a number of military attributes embedded in the user interface and a security labeller that appears as a separate 'pop-up' dialogue when the user sends the message. These extensions, when applied to the Microsoft OWA client, mean it can be used as part of a military message handling system (MMHS).
    SecureZIP for Desktop   SecureZIP enables users to secure files with strong passphrase or digital certificate-based encryption, as well as digital signature support to ensure data integrity. Encrypt email body and calendar attachments – Ensure that the information contained in the body of your e-mail, email attachments and calendar attachments is protected through integration with Outlook. Re-encryption – Save time by forwarding encrypted e-mails to new recipients automatically from your e-mail without having to download and resave your files
    Security Enhancements for Microsoft Exchange   From HP, Exchange (SE) relies on a policy matrix to enforce mail handling rules based on classification and destination. Supports "proof of content origin" signing and PKI. CASM level 2 compliant.
    Security Incident Report   Unsupported Microsoft sample form application.
    Security Manager 2007   Outlook Security Manager is a one-line programming tool that allows you to bypass security settings and avoid security warnings, alerts or prompts in add-ins and applications that interact with Microsoft Outlook. Outlook Security Manager is developed for .NET, VCL and ActiveX platforms (VB.NET, C#, C++, Visual Basic 6, Delphi, VBA, Word MailMerge) and supports MS Outlook 2000, Outlook 2002 (XP), Outlook 2003 and Outlook 2007 with / without service packs.
    SessionGuard 2000   SessionGuard is Exchange security software that protects Outlook Web Access users from fraudulent use of their login credentials. SessionGuard ensures that an OWA user’s cached credentials cannot be reused to gain access to Exchange. In addition SessionGuard provides administrators the ability to set session timeouts to protect against forgetful users. Available for OWA 5.5, 2000 and 2003. (Was SecureLogoff)
    Voltage SecureMail   Email encryption application for both internal and external recipients. Users get a Send Secure button in Outlook. Recipients only need to authenticate; they don't need special software.
    Windows Rights Management   Tools for setting policies on email messages and files that govern who can read, copy, print, etc. and how long mail messages can be retained. Client supports rights assignment in Office 2003 and reading in Office 2003 or Internet Explorer (on Windows only). Server for corporate use available as add-in component for Windows 2003 Server. Microsoft is also maintaining (for the time being) a free, public RM server for use with .NET Passport accounts.
    Back to Top

     

    More Information

  • Compression Tools -- Some of these tools can encrypt as well as compress attachments.
  • Crypto Law Survey -- Encryption of e-mail is not universally legal. This site tracks encryption law around the world.
  • Digital IDs with Microsoft Outlook 98
  • X.400 Services
  • OL2002- Exchange 2000 Account with Revoked Security Can Send and Receive E-mail

  • Outlook S/MIME Vulnerability

  • OL2002 Recipients Cannot Read Messages When 168-Bit (3DES) Encryption Is Enabled -- discusses UseAlternateDefaultEncryptionAlg registry value

  • You Cannot Send Encrypted E-Mail Messages to a Contact While You Are Working Offline -- hotfix available for Outlook 2002

  • Windows Prompts You for Your Password Multiple Times When You Use Outlook If Strong Private Key Protection Is Set to High -- hotfix available for Outlook 2002

  • Quick Start for S/MIME in Exchange Server 2003 (whitepaper)

  • Microsoft Exchange Server 2003 Message Security Guide (whitepaper)

  • OL2002 Recipients Cannot Read Messages When 168-Bit (3DES) Encryption Is Enabled

  • Signed E-Mail Message Displays the Incorrect Sending Address

  • Updated Apr 10 2009

    Copyright Slipstick Systems. All rights reserved.
    Send comments using our Feedback page

    Home | What's New | Exchange Server | Outlook | Utilities | Bookstore
    About Slipstick | Feedback | Privacy Policy | Site Map | Archived Pages | Link to Us | Advertise