Now and then, an email from [email protected], like a signing invitation or a notification, lands in a recipient's junk folder or opens with a warning that the digital signature is invalid or the message has been altered. This article explains why it happens, what to do in the moment, and how your IT team can stop it from happening again.
The short version
Connie digitally signs every email it sends. This lets your email program check that the message really comes from Connie and hasn't been changed on the way. Most of the time you never notice it.
When you do see a warning, it's almost always one of two things, both on the recipient's side:
The computer can't verify our certificate, usually because its list of trusted root certificates is out of date.
A company mail filter changed the email after we sent it, for example by adding a disclaimer, rewriting links or inserting a safety banner. Any change after sending breaks the signature.
Neither means something is wrong with the email from Connie. Most people you send consents, releases or signing invitations to never see this warning. It mainly shows up in some company IT setups.
What to do right now
If you've received a Connie email with a signature warning, or found one in junk, and you need to act on it:
Check the sender. It should be [email protected]. If it is, and you were expecting a document from the sender, the warning is about the email's signature, not the document you're being asked to view or sign.
Open the message. Click View message or similar in the warning and continue as normal.
Move it out of junk. Moving the email to your inbox helps future Connie emails arrive in the right place.
If you're not sure the email is genuine, don't click the link. Ask the person who sent you the document, or contact [email protected].
Sending to someone who can't open the email?
You can send the signing link another way. Open the document in Connie, click Copy Sign Link, and send it to the signer yourself. See People are not receiving my contract.
How your IT team can fix it
If the warning keeps appearing for people in your organisation, it's worth having your IT team fix the cause. Share this section with them.
Cause 1: Out-of-date root certificates
Connie signs its emails with an S/MIME certificate from SSL.com, a public Certificate Authority, issued to [email protected]. Every email includes the full certificate chain: our certificate, SSL.com's intermediate certificate and the root. To trust the signature, the mail client (Outlook, Apple Mail and so on) needs an up-to-date list of trusted root certificates on the computer.
Large organisations sometimes fall behind on these updates, especially on centrally managed computers. This is the most common cause of "invalid signature" warnings on Connie emails.
What to do:
Check that the affected computers get current operating system and security updates. On Windows, root certificates are updated through Windows Update. On macOS, they're part of the regular system updates.
If you manage root certificates centrally, for example through Group Policy or MDM, make sure the current set is being distributed.
The check happens on each computer, not on your mail server. Once a computer has current root certificates, the warning disappears for all future Connie emails.
Cause 2: A mail filter changes the email after sending
Security services like Microsoft Defender for Office 365, Mimecast and Proofpoint sometimes change incoming emails: they rewrite links to scanned proxy links, add disclaimers or insert warning banners. That's a useful protection, but our signature covers the body of the email, so any change after sending makes the signature fail.
What to do:
Check whether your mail security rewrites links, adds disclaimers or otherwise changes incoming mail from getconnie.com.
If it does, add Connie to an exception rule so our emails arrive unchanged, using the details below.
Our sending details
Item | Value |
Sending domain | getconnie.com |
From address | |
Mail server | mail.getconnie.com |
Sending IP | 77.243.135.11 (always listed in the SPF record at |
SPF | Published for getconnie.com |
DKIM | Every email is signed, selector |
DMARC | Policy |
S/MIME | Certificate from SSL.com, with the full chain attached to every email |
We recommend basing exception rules on the authenticated sending domain, getconnie.com, rather than only on the IP address. Our DMARC policy means mail claiming to be from getconnie.com that doesn't pass our checks is rejected, so the domain is a safe thing to trust.
Require authentication in the exception
Make sure the exception only applies to email that passes DKIM or DMARC for getconnie.com. Never base it on the From address alone, since a sender address can be faked.
Excluding Connie's emails from link rewriting and body changes fixes the warning for all future emails.
Help us help you
If your IT team has looked into it and the warning still appears, we're happy to help. The most useful thing you can send us is the raw email with full headers, saved as a file:
Outlook: open the email and save it as a file, for example with File → Save As.
Apple Mail: drag the email from the list to your desktop.
Gmail (web): open the email, click the three-dot menu and choose Download message.
Email the file to [email protected] with a short note about the warning you saw. From the headers we can tell exactly what happened: an out-of-date trust store, a change on the way, or something more unusual.
Good to know
Your signers are rarely affected. Most signing invitations are opened without any warning, including by people with ordinary personal email accounts. The warning mainly appears in some company IT environments.
Want to talk it through? If your IT team would like a technical conversation with ours, email [email protected] and we'll set up a call.
