The TLS/SSL certificate market is limited to the number of websites, approximately 200 million globally. The S/MIME certificate market, however, is limited only by the global Internet population, over 5 billion people. Every person has multiple email addresses, and every email deserves automated encryption.
This is a market opportunity dozens of times larger than TLS/SSL certificates.
The SSL certificate market is undergoing fundamental restructuring. Let's Encrypt now command over 54% of the global SSL certificate market. Combined with cloud platform giants like Google, Amazon, and Microsoft, free and platform-affiliated CAs have captured over 90% of the market. Traditional CAs have seen their SSL certificate revenues sharply decline, and the industry is urgently searching for new growth avenues.
At the same time, S/MIME email encryption adoption remains extremely low. A 27-year academic study covering over 81 million emails found that only 5.46% of users had ever used S/MIME or PGP, with encrypted emails accounting for just 0.06%. S/MIME standards have existed for nearly three decades, yet the actual number of users employing email encryption is minimal.
The SSL market is a red ocean. The email certificate market is a blue ocean. Opportunity is right here.
On July 2, 2025, the CA/Browser Forum S/MIME Certificate Working Group officially passed Ballot SMC012, formally introducing RFC 8823 (ACME automation for email certificates) into the S/MIME certificate domain:
The standards are in place. The market is waiting. Now is the perfect time to enter.
ZTmail provides an open marketplace where global users can freely choose email certificates from CAs worldwide in one place. Users compare prices, compare services, and select the certificate that best fits their needs. Purchase it, and it‘s automatically configured — no manual application, no manual installation. Buy it, and email encryption just works.
ZTmail is the world’s first email client with automated encryption + bring-your-own AI. Through this platform, email certificates issued by global CAs can directly reach a massive number of end users who need email encryption.
ZTmail has built-in ACME capabilities. Users apply with one click; certificates are automatically configured. CAs only need to provide certificate services; user acquisition is handled by ZTmail.
With just a traditional certificate application API, ZTmail provides free technical integration. CAs simply need to change to send validation email in RFC 8823-compliant format.
Partner CA logos and certificate application entry points will be prominently displayed throughout the AutoCert Marketplace and the client-side user journey. Each partner CA‘s brand is presented independently, and users can clearly see which CA issued their certificate at the point of selection — the issuer is always transparent to the user.
Specific commercial terms are negotiated on a case-by-case basis to ensure mutual benefit. The first CAs to join will receive the most favorable support terms.
CAs do not need to build an ACME service. They simply provide traditional APIs. ZTmail provides the complete ACME service capability, and both parties coordinate through APIs to complete automated certificate issuance.
What the CA needs to provide:
This is the simplest way for CAs to enter the email certificate automation space, minimal development, fast to launch.
CAs build their own RFC 8555 and RFC 8823 compliant ACME services. ZTmail users can directly select the CA's ACME service URL, with the entire certificate application, validation, and issuance process handled by the CA's ACME service.
What the CA needs to provide:
Partner CAs must create a dedicated page on their website, or add an automation option to their email certificate sales page, allowing users to choose automated certificate application.
Users choose the automated option bypassing the traditional complex application process. Users simply complete payment and, depending on certificate type (MV/IV/OV/SV), cooperate with the required identity verification steps.
The CA's automation page must provide a clear link to direct users to download ZTmail to experience the "one-click apply, auto-configure certificate" process.
Users can first experience automated certificate configuration through ZTmail free edition before deciding to purchase the paid version. This "try before you buy" model significantly lowers the user's decision barrier.
The S/MIME certificate automation market is just getting started, with the CA/B Forum standards freshly established. Early entrants will gain significant first-mover advantage.
With ZTmail's public beta and promotional efforts, user awareness that "email should be encrypted by default" is rapidly increasing. Demand is about to surge.
ZTmail is building the world's first S/MIME certificate ACME ecosystem platform for S/MIME certificates. Early partners will become core ecosystem collaborators, helping define the market rules.
The first CAs sign up will receive the most favorable support terms.
Partner CAs can now receive early access to ZTmail beta version for evaluation and provide feedback for improvement.
The following technical documents detail the specifications for CAs to integrate with the ZTmail ecosystem. To request the full documents, please email us with your company name and preferred partnership model, and we will send the complete technical documents within 24 hours.
The ZTmail ecosystem partnership platform is open to all global CAs. Regardless of size, whether CA already has ACME service capability or just has traditional API, as long as CA can issue publicly trusted S/MIME certificates, you are welcome to join.