S/MIME Certificate Automation Global Ecosystem Partnership

From the SSL Red Ocean to the S/MIME Blue Ocean,
Welcome to join ZTmail S/MIME Certificate Automation Innovation Ecosystem

A Market Far Larger Than SSL/TLS Certificate

The TLS/SSL certificate market is limited to the number of websites, approximately 200 million globally. The S/MIME certificate market, however, is limited only by the global Internet population, over 5 billion people. Every person has multiple email addresses, and every email deserves automated encryption.

This is a market opportunity dozens of times larger than TLS/SSL certificates.

The Challenge Facing Global CAs

The SSL certificate market is undergoing fundamental restructuring. Let's Encrypt now command over 54% of the global SSL certificate market. Combined with cloud platform giants like Google, Amazon, and Microsoft, free and platform-affiliated CAs have captured over 90% of the market. Traditional CAs have seen their SSL certificate revenues sharply decline, and the industry is urgently searching for new growth avenues.

At the same time, S/MIME email encryption adoption remains extremely low. A 27-year academic study covering over 81 million emails found that only 5.46% of users had ever used S/MIME or PGP, with encrypted emails accounting for just 0.06%. S/MIME standards have existed for nearly three decades, yet the actual number of users employing email encryption is minimal.

The SSL market is a red ocean. The email certificate market is a blue ocean. Opportunity is right here.

The Standards Are Ready, The Market Is Waiting

On July 2, 2025, the CA/Browser Forum S/MIME Certificate Working Group officially passed Ballot SMC012, formally introducing RFC 8823 (ACME automation for email certificates) into the S/MIME certificate domain:

The ballot received 15 votes from Certificate Issuers and 2 votes from Certificate Consumers, passing with 0 dissenting votes
ACME is now the industry standard for S/MIME certificate automation
CAs can provide automated email certificate services based on the ACME standard
The global S/MIME certificate market is poised for an automation-driven transformation

The standards are in place. The market is waiting. Now is the perfect time to enter.

What ZTmail Offers Global CAs?

  AutoCert Marketplace

ZTmail provides an open marketplace where global users can freely choose email certificates from CAs worldwide in one place. Users compare prices, compare services, and select the certificate that best fits their needs. Purchase it, and it‘s automatically configured — no manual application, no manual installation. Buy it, and email encryption just works.

  Direct Access to a Massive End-User Base

ZTmail is the world’s first email client with automated encryption + bring-your-own AI. Through this platform, email certificates issued by global CAs can directly reach a massive number of end users who need email encryption.

  No Need to Build Your Own User Channels

ZTmail has built-in ACME capabilities. Users apply with one click; certificates are automatically configured. CAs only need to provide certificate services; user acquisition is handled by ZTmail.

  Minimal Development Effort

With just a traditional certificate application API, ZTmail provides free technical integration. CAs simply need to change to send validation email in RFC 8823-compliant format.

  Clear Brand Visibility

Partner CA logos and certificate application entry points will be prominently displayed throughout the AutoCert Marketplace and the client-side user journey. Each partner CA‘s brand is presented independently, and users can clearly see which CA issued their certificate at the point of selection — the issuer is always transparent to the user.

  Flexible Partnership Models

Specific commercial terms are negotiated on a case-by-case basis to ensure mutual benefit. The first CAs to join will receive the most favorable support terms.

Platform Operation Commitments

Neutral Operation: The platform does not favor any CA. All access standards are open and transparent.
Open Access: Any eligible CA can join. Rules apply equally to all.
Full Control Remains with the CA: Mailbox validation, identity vetting, and final certificate issuance are always handled by the CA. ZTmail serves only as the user entry point and automated configuration tool, never overstepping its role.
Privacy and Data Security: ZTmail do not access or store any user identity documents. User orders are directed to the CA via API or ACME service to complete the transaction. ZTmail is only responsible for submitting the order and retrieving the issued certificate for automatic configuration.

Partnership Models

Model One: Traditional API Integration (Recommended, minimal CA effort)

CAs do not need to build an ACME service. They simply provide traditional APIs. ZTmail provides the complete ACME service capability, and both parties coordinate through APIs to complete automated certificate issuance.

What the CA needs to provide:

APIs to receive CSR and verification code
RFC 8823-compliant verification code emails
Callback notification after certificate issuance
Automated MV certificate issuance; for IV/OV/SV, the CA performs identity verification before issuance

This is the simplest way for CAs to enter the email certificate automation space, minimal development, fast to launch.

Model Two: ACME Service Integration

CAs build their own RFC 8555 and RFC 8823 compliant ACME services. ZTmail users can directly select the CA's ACME service URL, with the entire certificate application, validation, and issuance process handled by the CA's ACME service.

What the CA needs to provide:

An ACME service compliant with RFC 8555 and RFC 8823
Support for email-reply-00 challenge (and the email-dns-01 extension challenge)
Correct parsing of certificate policy OIDs and key usage in CSRs to issue the appropriate certificate types

Model comparison

Comparison
Model One: Traditional API
Model Two: ACME Service
CA Development Effort
Minimal
Significant (requires ACME service)
Time to Launch
Days
Weeks to months
Automation Level
Automated (ZTmail + ZoTrus ACME service)
Automated (ZTmail directly connects to CA's ACME service)
Control
CA controls validation and issuance
CA has full independent control
Platform Fee
API integration + listing fee, per-order commission
Listing fee, per-order commission
Best For
CAs wanting to launch quickly
CAs with existing or planned ACME capability

Partnership Requirements

1CAs must set up an automation landing page

Partner CAs must create a dedicated page on their website, or add an automation option to their email certificate sales page, allowing users to choose automated certificate application.

2Simplified user experience

Users choose the automated option bypassing the traditional complex application process. Users simply complete payment and, depending on certificate type (MV/IV/OV/SV), cooperate with the required identity verification steps.

3Guide users to download ZTmail

The CA's automation page must provide a clear link to direct users to download ZTmail to experience the "one-click apply, auto-configure certificate" process.

4Free experience drives paid conversion

Users can first experience automated certificate configuration through ZTmail free edition before deciding to purchase the paid version. This "try before you buy" model significantly lowers the user's decision barrier.

Why Join Now?

First-mover advantage:

The S/MIME certificate automation market is just getting started, with the CA/B Forum standards freshly established. Early entrants will gain significant first-mover advantage.

User awareness is growing:

With ZTmail's public beta and promotional efforts, user awareness that "email should be encrypted by default" is rapidly increasing. Demand is about to surge.

An ecosystem is being built:

ZTmail is building the world's first S/MIME certificate ACME ecosystem platform for S/MIME certificates. Early partners will become core ecosystem collaborators, helping define the market rules.

The first CAs sign up will receive the most favorable support terms.

Partnership Onboarding Process

1 CA submits partnership application
2 ZTmail evaluation and commercial discussion
3 Sign partnership agreement (early partners receive special terms)
4 Technical integration and joint testing
5 CA automation landing page goes live
6 Officially listed on ZTmail, available for users to select

Partner CAs can now receive early access to ZTmail beta version for evaluation and provide feedback for improvement.

Technical Documentation

The following technical documents detail the specifications for CAs to integrate with the ZTmail ecosystem. To request the full documents, please email us with your company name and preferred partnership model, and we will send the complete technical documents within 24 hours.

Document
Description
For CAs
Traditional-API-Integration-Technical-Specification.pdf
Detailed Model One specification
CAs choosing traditional API integration
ACME-Service-Integration- Technical-Specification.pdf
Detailed Model Two specification
CAs choosing ACME service integration
Automatic-Certificate- Management-Protocol_Email-Certificate-Quick-Application-Mode- Guide.pdf
Simplified English version of the draft Chinese cryptography industry standard - 'Automatic Certificate Management Protocol'
Reference for all CAs

Join Now

The ZTmail ecosystem partnership platform is open to all global CAs. Regardless of size, whether CA already has ACME service capability or just has traditional API, as long as CA can issue publicly trusted S/MIME certificates, you are welcome to join.

Contact Us