FAQs
Troubleshooting: "Your Digital ID Name Cannot Be Found" error in Outlook
Overview
By following this article you will identify why Outlook shows the "Digital ID name cannot be found" error and apply the fix that lets you open encrypted email again. The error is almost always a certificate problem — most often a mismatch between an older Triple Data Encryption Standard (3DES) message and a newer Advanced Encryption Standard (AES-256) configuration, or a missing or corrupted Secure/Multipurpose Internet Mail Extensions (S/MIME) certificate. The article lists the symptoms and cause, gives a quick temporary workaround, then walks through three fixes: enabling server authentication in Internet Options, checking your signing and encryption certificate in Outlook, and deleting a corrupted sender certificate with the Microsoft Management Console (MMC). It closes with how to confirm the fix worked and what to do if the error continues.
Similar questions
- How do I fix "Your Digital ID name cannot be found by the underlying security system" in Outlook?
- Why can't I open an encrypted email in Outlook?
- Outlook won't open a secure/encrypted message — how do I resolve it?
- How do I remove a corrupted sender certificate in Outlook?
Symptoms
You are likely seeing this issue if one or more of the following is true:
- Outlook displays the message "Your Digital ID name cannot be found by the underlying security system.
- You cannot open encrypted or secure email.
- Only specific encrypted emails from certain senders fail to open
- Other encrypted emails from the same sender open successfully, but one message does not.
- The error appears inconsistently after you reopen Outlook.
Figure 1. Outlook error message shown when a Digital ID cannot be found.
Cause
This error is typically caused by an invalid, missing, or outdated encryption certificate on either the recipient's or the sender's side. The most common root cause is a mismatch between the sender's older Triple Data Encryption Standard (3DES) encrypted message and the recipient's newer Advanced Encryption Standard (AES-256)-based security configuration. A corrupted sender certificate stored on the local computer can also cause the error.
Quick workaround
Before changing any settings, try these quick checks. They can resolve the problem when it is temporary:
- Close the error message, wait a minute or two, then reopen the email.
- Open other emails from the same sender. If those open, ask the sender to forward the affected email again.
If the error continues, use one of the three fixes below.
How to fix the error
Method 1 — Enable server authentication in Internet Options
Turn on server authentication in Internet Options so that certificate verification works correctly.
- Press Windows + R.
- Type inetcpl.cpl and select OK.
Figure 2. Run dialog with inetcpl.cpl entered to open Internet Options.
- In Internet Properties, open the Content tab.
Figure 3. Internet Properties Content tab with the Certificates button highlighted.
- Select Certificates, then open the Personal tab, which lists your personal certificates.
Figure 4. Certificates window showing the Personal tab and the Advanced button.
- Select Advanced.
- Under Certificate purposes, enable Server Authentication and Secure Email.
Figure 5. Advanced Options dialog with Server Authentication and Secure Email selected.
- Select OK, then Close the Certificates window.
Figure 6. Certificates window with the Close button highlighted.
- Back in Internet Properties, select Apply, then OK.
Figure 7. Internet Properties with Apply and OK highlighted to save the changes.
- Restart Outlook and try opening the encrypted email again.
Method 2 — Check your signing and encryption certificate in Outlook
Confirm that Outlook has a valid certificate configured for signing and encryption.
- Open Microsoft Outlook.
- Go to File → Options.
Figure 8. Outlook File menu with Options selected.
- Select Trust Center → Trust Center Settings.
Figure 9. Outlook Options with the Trust Center page and Trust Center Settings button.
- Open the Email Security tab. Under Encrypted email, confirm that a certificate is listed.
Figure 10. Trust Center Email Security tab with the Settings button highlighted.
- Select Settings, then check whether a Security Settings Name is selected. If the field is blank, your certificate may have expired and needs to be replaced.
Figure 11. Change Security Settings dialog showing the Signing Certificate and Encryption Certificate fields.
- Use Choose to manually select a valid signing and encryption certificate if needed.
- Confirm the encrypted message now opens.
Method 3 — Delete the corrupted sender certificate
A corrupted sender certificate stored on your computer can trigger the error. Remove it with the Microsoft Management Console (MMC).
- Press Windows + R, type mmc, and press Enter.
Figure 12. Run dialog with mmc entered to open the Microsoft Management Console.
- In the console, select File, then choose certmgr to open Certificates – Current User.
Figure 13. Console File menu with the certmgr snap-in selected.
- Expand Certificates – Current User, then go to Other People → Certificates.
Figure 14. certmgr navigated to Other People → Certificates (certificate names redacted).
- Locate the sender's faulty certificate in the list.
- Right-click the certificate and select Delete.
Figure 15. Right-click menu on a certificate with Delete selected (certificate name redacted).
- Select File → Save to save the console configuration.
Figure 16. certmgr File menu with Save selected (certificate name redacted).
- Try opening the encrypted email again.
How to verify the fix worked
The issue is resolved when the previously affected encrypted email opens without the "Digital ID name cannot be found" error and its contents display normally. If you can open other encrypted messages as well, certificate verification is working correctly.
If the error continues
If none of the fixes above resolve the issue, the certificate mismatch is likely on the sender's side. Ask the sender to:
- Generate a new certificate signing request (CSR) using the CertReq tool instead of the Windows certificate snap-in.
- Obtain a newly issued certificate from their certificate authority.
A newly issued certificate ensures compatibility with modern encryption standards such as Advanced Encryption Standard (AES-256).
Need assistance?
Contact our team for help with your purchase or issuing your certificate.