Email Security and Encryption

Encrypt/Decrypt Messages

Aspose.Email provides the facility to encrypt and decrypt email messages using X.509 certificates. This article shows how an existing or a new message can be loaded and encrypted through the MailMessage class. The encrypt() and decrypt() methods return a new MailMessage object with the applied effect, so the returned object is the one to save or send.

Encrypting and decrypting messages involves the following steps:

  1. Create a new message or load an existing one.
  2. Read the certificate file into a bytes object.
  3. Encrypt the message with the public certificate.
  4. Send the message or save it.
  5. Decrypt the message with the certificate that contains the private key.

The following code snippet shows you how to encrypt and decrypt messages:

import aspose.email as ae

with open(data_dir + "MartinCertificate.cer", "rb") as f:
    public_cert = f.read()

with open(data_dir + "MartinCertificate.pfx", "rb") as f:
    private_cert = f.read()

# Create a message
msg = ae.MailMessage("sender@domain.com", "receiver@domain.com", "Test subject", "Test Body")

# Encrypt the message
encrypted = msg.encrypt(public_cert)
print("Is encrypted: " + str(encrypted.is_encrypted))

# Decrypt the message
decrypted = encrypted.decrypt(private_cert)
print("Is encrypted: " + str(decrypted.is_encrypted))

Verify Message Encryption

The is_encrypted property of the MailMessage class allows you to check whether a message is encrypted, as shown in the following code sample:

import aspose.email as ae

with open(data_dir + "MartinCertificate.cer", "rb") as f:
    public_cert = f.read()

with open(data_dir + "MartinCertificate.pfx", "rb") as f:
    private_cert = f.read()

mail_message = ae.MailMessage.load(data_dir + "message.msg", ae.MsgLoadOptions())
print("Message is encrypted: " + str(mail_message.is_encrypted))

mail_message = mail_message.encrypt(public_cert)
print("Message is encrypted: " + str(mail_message.is_encrypted))

mail_message = mail_message.decrypt(private_cert)
print("Message is encrypted: " + str(mail_message.is_encrypted))

Checking Secure Emails Signature

The SecureEmailManager class allows you to check the signature of secure MailMessage objects. The SmimeResult class stores the result of the check, exposed through its is_success property.

Check the signature of a message without providing a certificate:

import aspose.email as ae

eml = ae.MailMessage.load(data_dir + "signed.eml")

result = ae.SecureEmailManager().check_signature(eml)
print("Signature is valid: " + str(result.is_success))

Check the signature of an encrypted message by providing the certificate used for decryption:

import aspose.email as ae

with open(data_dir + "MartinCertificate.pfx", "rb") as f:
    certificate = f.read()

eml = ae.MailMessage.load(data_dir + "signed_and_encrypted.eml")

result = ae.SecureEmailManager().check_signature(eml, certificate)
print("Signature is valid: " + str(result.is_success))

Signing Messages

Signing a message is covered in Creating and Managing Emails, which describes the attach_signature method and the detached certificate option.