SMIME certificates use asymmetric cryptography involving a pair of keys: a public key and a private key. When an email is signed using the sender’s private key, the recipient can use the sender’s public key to verify the signature. For encryption, the sender uses the recipient’s public key to encrypt the email, which can only be decrypted by the recipient’s private key.