S/MIME
Secure/Multipurpose Internet Mail Extensions: a standard (RFC 8551) that signs and encrypts email messages end to end using X.509 certificates issued through a PKI.
S/MIME (Secure/Multipurpose Internet Mail Extensions) protects the content of an email message itself, from sender to recipient, rather than the connection between mail servers. The current version is RFC 8551, and it offers two services, usable separately or together. A digital signature made with the sender’s private key gives integrity, origin authentication and support for non-repudiation. Encryption uses a random symmetric key for the message body and wraps that key with each recipient’s public key, so only the holders of the matching private keys can read it. X.509 certificates bind keys to identities, within a public key infrastructure.
S/MIME is often confused with the domain-level email controls SPF, DKIM and DMARC. Those let a receiving server check that mail really came from the sending domain; they give the reader no confidentiality. It also differs from TLS between mail servers, which protects each hop in transit but leaves the message readable on every server it passes through. PGP offers similar services with a web of trust instead. Headers such as the subject line commonly stay unencrypted.
Exam relevance: a scenario that requires only the named recipient to read a message, or proof of which individual sent it, is likely to point to S/MIME. Candidates are expected to tell message-level protection apart from domain authentication and from transport encryption.