FAQs
Resolving "Unable to decrypt message" in Outlook (S/MIME interoperability with Gmail)
Overview
By following this article you will configure Microsoft Outlook so that Secure/Multipurpose Internet Mail Extensions (S/MIME) signed and encrypted email is readable and verifiable by Gmail recipients, resolving the "Unable to decrypt message" error. These problems usually come from a certificate mismatch, a deprecated signing algorithm such as Secure Hash Algorithm 1 (SHA-1), or a signed-message format that Gmail cannot fully interpret. The article first lists the symptoms and root causes, then walks through three sender-side fixes in Outlook — validating certificate configuration, selecting compatible cryptographic algorithms (SHA-256 and Advanced Encryption Standard (AES-256)), and enabling clear-text signed messages — and closes with the certificate requirement for encrypted email and how to confirm the fix worked.
Similar questions
-
Why do Gmail recipients see "Unable to decrypt message" for email I send from Outlook?
-
How do I make Outlook S/MIME email work with Gmail?
-
Which signing and encryption algorithms should I use for S/MIME in Outlook?
-
How do I enable clear-text signed messages in Outlook?
Symptoms
Recipients using Gmail may see one or more of the following when they receive Secure/Multipurpose Internet Mail Extensions (S/MIME) email from Outlook:
-
The message "Unable to decrypt the message."
-
"This message could not be decrypted. The digital signature is missing."
-
The email cannot be opened, verified, or displayed correctly, even when certificates are installed on both sides.
Figure 1: Gmail showing "This message could not be decrypted. The digital signature is missing," with an smime.p7m attachment.
Root causes
This error rarely comes from a single setting. It usually results from one or more of the following:
-
Cryptographic algorithm mismatch — the message is signed with a deprecated algorithm such as Secure Hash Algorithm 1 (SHA-1), which Gmail and other modern systems may reject.
-
Message format compatibility — Outlook sends the S/MIME message in a format Gmail cannot fully interpret, so the signed or encrypted structure does not render.
-
Certificate or key issues — the recipient does not have the sender's current public certificate, the sender used an outdated recipient certificate, or the certificates were never exchanged before encrypted email was sent.
How to fix the error
Perform these three sender-side steps in Outlook, in order. All three are configured under File → Options → Trust Center → Trust Center Settings → Email Security.
Step 1 — Validate certificate configuration (most important)
Confirm the correct, current certificates are in use on both sides before changing any other setting. S/MIME depends on certificate exchange: if either side uses an outdated certificate, communication fails regardless of other settings.
On the sender side, open File → Options → Trust Center → Trust Center Settings → Email Security → Settings and confirm that:
-
The correct S/MIME certificate is selected for signing (and for encryption, if used).
-
The same certificate is used for signing and encryption where applicable.
-
The certificate is current, not expired or an old version.
On the recipient side, confirm that the recipient:
-
Has the sender's latest public certificate.
-
Has not stored an old or expired copy of the sender's certificate.
If the recipient uses an outdated public certificate, signature validation can fail, encrypted replies can break, and the message may show "Unable to decrypt message" or an invalid-signature warning.
Step 2 — Select compatible cryptographic algorithms
In File → Options → Trust Center → Trust Center Settings → Email Security → Settings, set the signing and encryption algorithms to modern, widely supported values. The hash algorithm signs the message digitally; Gmail and other modern systems may reject SHA-1-based signatures, so SHA-256 ensures proper validation and compatibility.
|
Setting |
Use |
Avoid |
|
Hash algorithm |
SHA-256 |
SHA-1 (deprecated) |
|
Encryption algorithm |
AES-256 |
— |
Step 3 — Enable clear-text signed messages
In File → Options → Trust Center → Trust Center Settings → Email Security, enable "Send clear text signed message when sending signed messages."
Without this option, Outlook sends messages in a strict S/MIME-encoded format that Gmail may fail to interpret. With it enabled, Outlook sends a multipart/signed message that contains the readable email content and a separate digital signature. This keeps the message readable even when Gmail cannot fully process the S/MIME format, improves interoperability across mail platforms, and preserves signature integrity.
Certificate requirement for encrypted email
For encrypted (not just signed) email to work, the sender must have the recipient's public certificate and the recipient must have their own private key installed. If this certificate exchange has not happened, decryption fails regardless of the algorithms or settings above.
How to verify the fix worked
The issue is resolved when the Gmail recipient can open the message without the "Unable to decrypt message" error and the digital signature validates. Send a test signed message (and, if used, an encrypted message) from Outlook to a Gmail recipient and confirm it opens and displays correctly.
Need assistance?
Contact our team for help with your purchase or issuing your certificate.