To send IncaMail messages via the Mail Gateway Integration (MGI), your mail server must present a valid client certificate for mutual TLS authentication with the IncaMail platform. IncaMail offers the option to create dedicated sending certificates directly in the management portal.
Note: Certificates created through the IncaMail portal can only be used for authentication with IncaMail and are not suitable for other purposes.
Depending on your mail server infrastructure, different approaches are available:
Option A – Mail server supports dedicated client certificates
If your mail server or mail gateway allows the installation of a dedicated client certificate, you can create a certificate directly via the IncaMail portal. Two methods are available:
Method 1 – Generate key pair in the browser
The key pair is generated directly in your browser. The public key is transmitted to IncaMail, which then creates the certificate and makes it available for download.
Method 2 – Upload CSR (Certificate Signing Request)
You generate the private key yourself and only upload the CSR (Certificate Signing Request) to the portal. IncaMail creates the certificate based on the CSR without transmitting the private key. The certificate can then be downloaded.
The requirements for the CSR are as follows:
- It should be PEM-encoded
- The size must not exceed 16 kB
- The signature can be RSA: 2048–8192 or ECDSA P-256, P-384, P-521
We do not check or ignore: Subject / SAN / requested EKUs – We add these ourselves to the certificate.
This method is recommended if, for security reasons, it must be ensured that the private key never leaves your own system.
Option B – Locally operated Microsoft Exchange Server (Exchange On-Premises)
If you use a locally operated Microsoft Exchange Server, enable the option when creating the certificate:
“I am using a locally operated Microsoft Exchange Server”
The certificate created this way contains no EKU restrictions (“clientAuth” limitations) and is therefore suitable for Exchange-specific configuration. The downloaded package also contains the Root CA certificate, which is needed during setup in the Exchange settings.
Option C – Mail server or hosted Exchange provider without support for dedicated client certificates
If your mail server or hosted Exchange provider does not allow the installation of a dedicated client certificate, enable the following option in the domain settings:
“Allow server authentication EKU for sending”
This allows IncaMail to accept certificates that contain a serverAuth EKU (i.e., issued for server authentication) when messages are sent from your domain.
Special case: Microsoft Exchange Online (Microsoft 365)
Exchange Online does not allow the installation of dedicated client certificates. Enable the corresponding toggle for Exchange Online in the domain settings. This automatically activates server authentication and adds the required CNs.
Create a Certificate – Step by Step
Prerequisite: You must be logged in as an administrator in the IncaMail management portal
- Open Admin Settings Navigate to the administrator settings in the IncaMail management portal: 👉 Mail Gateway Integration – Management Portal
- Edit Domain Entry Select the desired domain and open edit mode.
-
Select “Create Client Certificate” Choose the option that fits your infrastructure:
- Generate key pair in the browser, or
- Upload CSR
If needed, enable the option “I am using a locally operated Microsoft Exchange Server” (see Option B).
- Click “Create Certificate” The certificate is generated based on your inputs.
-
Download Certificate
- For the browser method: “Download certificate and key”
- For the CSR method: “Download certificate”
- Complete Finish the process. The CN of the created certificate is automatically entered into the “Sending Certificate CNs” field of your domain configuration.
- Install Certificate The downloaded certificate must be installed on the mail server by you or your IT team.
Overview of Options
| Situation | Recommended Option |
|---|---|
| Mail server supports dedicated client certificates | Option A – Create certificate in browser or via CSR |
| Locally operated Microsoft Exchange Server | Option B – Enable “Exchange On-Premises” option |
| Hosted provider without client certificate support (e.g., Exchange Online) | Option C – Enable “Allow server authentication EKU for sending” |
Need Support?
If you are unsure which option is suitable for your infrastructure or have questions about installing the certificate, the IncaMail support team is happy to assist you: