Trust Model for e-mail No, self-signed certificate not much better than the From: header address Sender creates both Either might be fake But Certificate can be widely published Claimed to belong to me If fake hope someone will notice expose the forgery Better than nothing Better still If I know you You tell me that is your certificate I can sign it for you You tell other friends They also sign your certificate