Unable to Verify Message Signature in Mail.app
/Fact #1: When you send an email from Mail.app, if you have a certificate in your keychain that matches the “from” email address, that certificate is used to sign the message.
Fact #2: When Mail.app receives a signed email message, it adds the sender’s attached certificate to the user’s keychain.
So far so good. But there’s an issue that can manifest as a result of those two facts.
If you send yourself a signed email from Mail.app, Mail treats the incoming message just like any received email in Fact #2 above.
That becomes an issue if the message in question was improperly signed with an invalid certificate. Mail sees the received email’s certificate and adds it to your keychain. Then, when you go to send the next email, Mail sees the certificate in your keychain and uses it to sign the new outgoing email.
If the signature is invalid, the recipient sees a banner at the top of the received message:
The solution is much trickier than one might think…
Read More