ZTmail supports automated provisioning of both RSA and SM2 certificates. You can choose the algorithm based on your recipient and your preference. And it's not just RSA and SM2, PQC (post-quantum cryptography) support is already on the roadmap. Multiple algorithm support means you have real choice.
The S/MIME standard is built on RSA, the global standard for email encryption. But China has its own cryptographic standard, SM2, which is required for compliance in regulated domestic scenarios. Meanwhile, quantum computing is approaching fast, and PQC is becoming the next-generation standard.
ZTmail supports RSA, SM2, and is preparing for PQC, giving you choice across “global interoperability,” “modern performance,” and “future readiness.”
Free edition S/MIME certificates issued by ZoTrus Root. Paid edition issued by publicly trusted CAs. Seamlessly interoperates with Outlook, Thunderbird, Apple Mail, and all standard S/MIME clients. RSA is the most widely supported standard today.
SM2 algorithm S/MIME certificates Issued by ZoTrus Root. Enables end-to-end encryption within the ZTmail and China cryptographic ecosystem. Carries multi-level trusted identities (T2 / T3 / T4).
Beyond compliance, SM2 is built on Elliptic Curve Cryptography (ECC). A 256-bit SM2 key delivers the same security strength as a 3072-bit RSA key — shorter keys, faster performance.
SM2 is an ISO/IEC international standard (ISO/IEC 14888-3:2018), not a regional algorithm, but a globally recognized standard.
Quantum computing is no longer a distant threat. NIST published the first PQC standards in August 2024. The CA/Browser Forum added ML-DSA and ML-KEM to S/MIME Baseline Requirements in August 2025. ZTmail has PQC support on its roadmap, ensuring your email encryption transitions smoothly from “classical security” to “quantum security.”
ZTmail automatically configures an RSA email certificate for users by default, but users can also switch to SM2 as the default algorithm in the settings. When writing an email, you can also switch with one click, and the system will automatically provide the corresponding email certificate, fully automated.
RSA ensures your encrypted emails can be read by any S/MIME client worldwide. SM2 gives you shorter keys, faster performance, and trusted identity display in regulated scenarios. PQC prepares you for tomorrow.
Not competition. Complement.