Provider's signature
Cryptographic check of the S/MIME signature and content integrity, with the provider's certificate anchored to AgID CA1, the authority of the PEC circuit.
Italian certified email (PEC) is worth something because the provider signs the envelope. The PEC verification module checks that signature and everything it covers: anchoring of the certificate to AgID, validity at the PEC's date, revocation, and the certification data read only from the signed part and compared with the envelope and with the original message. It works on transport envelopes and receipts, saved as EML, EMLX or MSG.
Cryptographic check of the S/MIME signature and content integrity, with the provider's certificate anchored to AgID CA1, the authority of the PEC circuit.
What matters is that the certificate was valid when the PEC was signed: a later expiry or revocation doesn't invalidate it, and the report explains why.
The status of the provider's certificate is queried via OCSP. Without a network this is stated: “could not check” is not “not revoked”.
daticert.xml and postacert.eml are read from the bytes covered by the signature. A part added afterwards — for example a fake daticert.xml next to the real one — makes the PEC invalid, even where a merely structural check would pass it.
Type, sender, subject, identifiers and date in daticert.xml are compared with the headers and with the original message. The envelope headers are not signed: the certification data is what counts, and the report states it.
Certified mail, acceptance, delivery (full, short, summary) and anomalies. The original message and its attachments are highlighted and open in a window of their own.
If Outlook kept the S/MIME envelope, verification runs on the original envelope, byte for byte. If it didn't, the PEC is declared unverifiable, not “valid”.
Outcome, verification record, signer and every check with its outcome and explanation.
.eml, .emlx, .msg).daticert.xml and the original message. Probatio performs these checks and lists them one by one.daticert.xml) is what counts, and it is signed: Probatio reads it from the signed part and compares it with the headers.