Email

PEC verification

Italian certified email (PEC) is worth something because the provider signs the envelope. The PEC verification module checks that signature and everything it covers: anchoring of the certificate to AgID, validity at the PEC's date, revocation, and the certification data read only from the signed part and compared with the envelope and with the original message. It works on transport envelopes and receipts, saved as EML, EMLX or MSG.

What it does

What the PEC verification module does

Provider's signature

Cryptographic check of the S/MIME signature and content integrity, with the provider's certificate anchored to AgID CA1, the authority of the PEC circuit.

Validity at the PEC's date

What matters is that the certificate was valid when the PEC was signed: a later expiry or revocation doesn't invalidate it, and the report explains why.

Online revocation

The status of the provider's certificate is queried via OCSP. Without a network this is stated: “could not check” is not “not revoked”.

Only what is signed

daticert.xml and postacert.eml are read from the bytes covered by the signature. A part added afterwards — for example a fake daticert.xml next to the real one — makes the PEC invalid, even where a merely structural check would pass it.

Data consistency

Type, sender, subject, identifiers and date in daticert.xml are compared with the headers and with the original message. The envelope headers are not signed: the certification data is what counts, and the report states it.

Envelopes and receipts

Certified mail, acceptance, delivery (full, short, summary) and anomalies. The original message and its attachments are highlighted and open in a window of their own.

PECs saved by Outlook

If Outlook kept the S/MIME envelope, verification runs on the original envelope, byte for byte. If it didn't, the PEC is declared unverifiable, not “valid”.

PDF report

Outcome, verification record, signer and every check with its outcome and explanation.

Step by step

How it works

  1. Drop the envelope or the receipt (.eml, .emlx, .msg).
  2. Read the outcome — valid, valid with findings, invalid or unverifiable — with every check explained.
  3. Open the original message or the envelope in a window of its own and generate the PDF report.
FAQ

Frequently asked questions

How do you verify that a PEC is authentic?
By verifying the S/MIME signature the provider puts on the envelope: it must be intact, issued by a PEC-circuit certificate anchored to AgID and valid at the PEC's date, and it must cover daticert.xml and the original message. Probatio performs these checks and lists them one by one.
Can I verify a PEC saved by Outlook as MSG?
Yes, if Outlook kept the signed envelope: verification runs on the original envelope. If the envelope isn't there, the PEC is declared unverifiable.
The provider's certificate has expired: is the PEC no longer valid?
What counts is validity at the PEC's date. A certificate that expired or was revoked later doesn't invalidate a PEC signed before, and the report explains it.
Why aren't the envelope headers enough?
The envelope's From, To, Subject and Date are not covered by the signature. The certification data (daticert.xml) is what counts, and it is signed: Probatio reads it from the signed part and compares it with the headers.