en-US office user

Set Maximum Certificate Size Limit for Signed Emails in Reply Scenarios.

Verified with Microsoft 365/Office 5568.1000 — updated on September 4, 2026

Microsoft 365/Office 5568.1000

Supported on: At least Windows Server 2008 R2 or Windows 7

Path in the GPO console

User Configuration\Administrative Templates\Microsoft Outlook 2016\Outlook Options\Mail\Compose Messages

Description

This policy setting controls the maximum limit for the size of the stored certificate in Exchange server when replying to a digitally signed email using Outlook. If you enable this policy setting, you can configure the maximum limit for the size of the stored certificate, up to a maximum of 16384 kb. This helps to avoid issues where a reply to a digitally signed email may not be delivered or saved in the sent items due to large certificate sizes of the original sender. By disabling this policy setting, the maximum limit will be the default set at 12921 kb, limiting the ability of administrators to adjust the maximum size of the stored certificate. If you do not set the policy setting, it is treated as enabled and the default maximum limit for the size of the stored certificate is set at 12921 kb.

Registry

HKCU software\policies\microsoft\office\16.0\outlook\options\mail

More options available

Options

In bytes:
maxcertlengthtostamp decimal - range 0-16384 - default: 12921

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO.

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Set Maximum Certificate Size Limit for Signed Emails in Reply Scenarios.
; State: Enabled
; Supported on: At least Windows Server 2008 R2 or Windows 7

[HKEY_CURRENT_USER\software\policies\microsoft\office\16.0\outlook\options\mail]
"maxcertlengthtostamp"=dword:00003279
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Set Maximum Certificate Size Limit for Signed Emails in Reply Scenarios.
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.

$path = 'HKCU:\software\policies\microsoft\office\16.0\outlook\options\mail'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'maxcertlengthtostamp' -Value 12921 -Type DWord

Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.

Open the Builder

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview