One Encrypted Email, Your Choice of Algorithms

ZTmail supports automated provisioning of both RSA and SM2 certificates. You can choose the algorithm based on your recipient and your preference. And it's not just RSA and SM2, PQC (post-quantum cryptography) support is already on the roadmap. Multiple algorithm support means you have real choice.

1. Why Multiple Algorithms?

The S/MIME standard is built on RSA, the global standard for email encryption. But China has its own cryptographic standard, SM2, which is required for compliance in regulated domestic scenarios. Meanwhile, quantum computing is approaching fast, and PQC is becoming the next-generation standard.

ZTmail supports RSA, SM2, and is preparing for PQC, giving you choice across “global interoperability,” “modern performance,” and “future readiness.”

2. Three Algorithms, Three Roles

RSA — Global Interoperability

Free edition S/MIME certificates issued by ZoTrus Root. Paid edition issued by publicly trusted CAs. Seamlessly interoperates with Outlook, Thunderbird, Apple Mail, and all standard S/MIME clients. RSA is the most widely supported standard today.

SM2 — Modern performance, more choice

SM2 algorithm S/MIME certificates Issued by ZoTrus Root. Enables end-to-end encryption within the ZTmail and China cryptographic ecosystem. Carries multi-level trusted identities (T2 / T3 / T4).

Beyond compliance, SM2 is built on Elliptic Curve Cryptography (ECC). A 256-bit SM2 key delivers the same security strength as a 3072-bit RSA key — shorter keys, faster performance.

SM2 is an ISO/IEC international standard (ISO/IEC 14888-3:2018), not a regional algorithm, but a globally recognized standard.

PQC — Future Ready

Quantum computing is no longer a distant threat. NIST published the first PQC standards in August 2024. The CA/Browser Forum added ML-DSA and ML-KEM to S/MIME Baseline Requirements in August 2025. ZTmail has PQC support on its roadmap, ensuring your email encryption transitions smoothly from “classical security” to “quantum security.”

3. When to Use RSA? When to Use SM2?

Scenario
Recommended Algorithm
Why
Sending to international clients/partners
RSA
Universal S/MIME compatibility
When you prefer shorter keys and faster performance
SM2
ISO standard, ECC-based, shorter keys, faster
Sending to government or regulated sectors in China
SM2
China cryptographic compliance + trusted identity
Sending to Chinese partners or colleagues
SM2
A thoughtful gesture. Using their national cryptographic standard shows respect, builds trust, and strengthens relationships with the same level of security
Personal communication
RSA or SM2
RSA for wider reach; SM2 for modern performance, more choice.

4. Automated Certificate Provisioning

ZTmail automatically configures an RSA email certificate for users by default, but users can also switch to SM2 as the default algorithm in the settings. When writing an email, you can also switch with one click, and the system will automatically provide the corresponding email certificate, fully automated.

5. RSA for Global Reach, SM2 for Modern Performance

RSA ensures your encrypted emails can be read by any S/MIME client worldwide. SM2 gives you shorter keys, faster performance, and trusted identity display in regulated scenarios. PQC prepares you for tomorrow.

Not competition. Complement.