Frequently asked questions
Does Sigil work with Google Workspace?
Section titled “Does Sigil work with Google Workspace?”No. Sigil is built on Outlook add-ins and Microsoft Entra, so it requires Microsoft 365 with Exchange Online.
Does Sigil see the emails people send?
Section titled “Does Sigil see the emails people send?”No. Sigil writes into the compose window and does not sit in your mail flow. It has no access to message bodies, subjects or recipients. See data and privacy.
Can Sigil change anything in our directory?
Section titled “Can Sigil change anything in our directory?”No. It requests read-only Graph permissions and no write permission of any kind. See permissions.
That holds for profile fields too. What a colleague types on their own profile page is stored by Sigil and never written back to Entra, which is why those fields exist for the things the directory is the wrong home for rather than duplicating the things it already holds.
Can people keep their own signature details up to date?
Section titled “Can people keep their own signature details up to date?”Yes, for the fields you decide on. You define custom fields such as pronouns, a
booking link or a direct line, and colleagues fill in their own at
portal.usesigil.app/me. They cannot change anything that comes from your
directory, which stays your IT team’s to maintain.
It is off until you switch it on, and what people enter appears in their signature on their next message. See profile fields.
Do users see their own signature as they write?
Section titled “Do users see their own signature as they write?”Yes. The signature is applied in the compose window, so the sender sees exactly what the recipient will get. This differs from server-side products that stamp signatures in transit, where the sender never sees their own.
Can people delete or edit the signature after it is applied?
Section titled “Can people delete or edit the signature after it is applied?”The signature is placed in the compose window, so a determined person can edit it in that message like any other content. What they cannot do is change what appears next time, because the template is served fresh on every compose.
Do users need to install anything?
Section titled “Do users need to install anything?”No. An administrator deploys the add-in centrally through Integrated apps. Individual installation does not work for automatic signatures, because event-based add-ins only auto-launch when an administrator deploys them.
How long does deployment take?
Section titled “How long does deployment take?”6 to 72 hours to propagate after you upload the manifest. Nothing speeds it up. See deploy the add-in.
How quickly does a template change reach people?
Section titled “How quickly does a template change reach people?”Seconds. Publishing increments the template version, which invalidates every cached signature for it. Nothing is redeployed and nobody restarts Outlook. See limits and timings.
The first message somebody writes after a publish is the one exception worth knowing about, and it is a matter of appearance rather than of delivery. See below.
Why did somebody’s signature change while they were writing?
Section titled “Why did somebody’s signature change while they were writing?”Because that is the new version arriving. The add-in puts the copy it kept from that mailbox’s last message in straight away, so a signature is there before the network has answered, then reconciles it against the current one a second or so later. On the first message after a publish, that reconciliation is visible: the old signature is replaced with the new one in the editor.
What is sent is the current signature, since the check finishes before the message can leave. The exception is a compose where Sigil could not be reached at all, which sends the kept copy rather than nothing. See why it sometimes changes as you watch.
Can we try a new signature on some people before everyone?
Section titled “Can we try a new signature on some people before everyone?”Yes. A staged publish goes to 10% of mailboxes and steps up to 25%, 50% and then everyone as the add-in reports that the new version is applying. The version everyone else receives does not change until it promotes, so abandoning it takes effect at once and republishes nothing. See staged rollouts.
What happens if a staged rollout goes wrong overnight?
Section titled “What happens if a staged rollout goes wrong overnight?”It withdraws itself. An evaluation runs every 15 minutes, and a version failing to apply materially more often than the one it would replace is pulled without anyone being asked. The mailboxes in the slice go back to the signature everyone else has been on throughout.
Can we require changes to be approved before they go live?
Section titled “Can we require changes to be approved before they go live?”Yes, and it is off unless you turn it on. With publish approval switched on, anyone who can edit still edits, but only an admin puts a body in front of users, and that covers restoring an old version and staging a rollout as well as the publish button.
An admin can approve their own submission, because a strict two-person rule would lock an organisation with one admin out of its own signatures. Sigil records whether the submitter and approver were the same person, so the log evidences it either way.
Can we make a signature change go live at a particular time?
Section titled “Can we make a signature change go live at a particular time?”Yes. A scheduled publish books the change for an instant you choose and fires within fifteen minutes after it, never before. The body is captured when you book it, so an edit made in between cannot silently change what goes live overnight.
Can different departments have different signatures?
Section titled “Can different departments have different signatures?”Yes, using assignment rules that match on a directory attribute or Entra group membership.
Can we check which rule applies to somebody before we rely on it?
Section titled “Can we check which rule applies to somebody before we rely on it?”Yes. Test a user on the rules page dry-runs the saved rules against one mailbox and reports which rule decided their signature, which rules missed and why, and which matched but were beaten to it by a rule above. It reads the directory live, changes nothing and sends nothing. See simulating a mailbox.
Can we have a shorter signature on replies?
Section titled “Can we have a shorter signature on replies?”Yes. Assign a separate template to the reply role. The add-in detects replies and forwards and requests the reply signature. Without one, replies get the new-message template.
What happens with shared mailboxes?
Section titled “What happens with shared mailboxes?”They get their own signature, rendered when somebody switches the sending account. They are unlicensed, so they are free.
A template can also name the person behind the send. The
sender placeholders resolve to whoever
pressed Send rather than to the mailbox, so sales@ can sign off “Jane Doe on
behalf of Sales” while the same template still reads “Jane Doe” from Jane’s own
mailbox. One template covers both, and nothing about the add-in changes. See
sending on behalf of a mailbox.
Do we have to pay for people who never send email?
Section titled “Do we have to pay for people who never send email?”No. A licensed mailbox can be excluded, which stops its signature and takes it off your seat count together. Frontline and shop floor staff, kiosk accounts and Teams-only users are the usual cases.
Sigil will tell you which mailboxes are candidates rather than leaving you to audit 400 licences by hand: it already records whether a signature was ever successfully applied, so it can list the billable mailboxes that have never once used one. Nothing is excluded until you choose it.
If those people are already a group in your directory, you can exclude the group instead of the mailboxes. Membership keeps up on its own, so a new warehouse starter never quietly appears on the bill.
Where it is the other way round, and only one team needs Sigil out of several hundred licences, the list can be turned around so that it names the mailboxes that should have Sigil rather than the ones that should not. See cost management.
Can Sigil tell us if it is actually working?
Section titled “Can Sigil tell us if it is actually working?”Yes, and this is one of the things it does that most client-side signature tools cannot. Activity records every request and every apply outcome per mailbox, and lists mailboxes that have never had a signature applied.
You do not have to go and look, either. A health digest emails your administrators the coverage figure, any apply failures and anything waiting on a decision, weekly by default.
Does link tracking identify individual recipients?
Section titled “Does link tracking identify individual recipients?”No. A click stores the link, the time, a device class, a browser family with no version number, and the referring page’s host name. No IP address, no recipient identity, no cookie, no pixel, and the raw user agent and referring URL are discarded rather than stored. Those descriptors are reported only in aggregate. Links containing a per-person placeholder are never rewritten, and the per-click records are deleted after 90 days. See link clicks.
Why does the signature not appear the very first time someone uses it?
Section titled “Why does the signature not appear the very first time someone uses it?”The automatic path runs in a part of Outlook with no user interface, so it can only sign somebody in silently. On a first use, or after an expired session or an MFA prompt, that can fail and the add-in stops quietly rather than interrupting somebody mid-message. Opening the “My signature” pane once completes the sign-in, and it works automatically from then on.
Why is there no manual button on mobile?
Section titled “Why is there no manual button on mobile?”Outlook mobile activates add-ins in read mode only. Event-based activation is one of a small number of documented exceptions; a compose task pane is not. Signatures still apply automatically on mobile.
Can we use SVG logos?
Section titled “Can we use SVG logos?”No. Outlook does not render SVG. Use PNG or JPG. See Outlook constraints.
Why has part of our signature vanished for some recipients?
Section titled “Why has part of our signature vanished for some recipients?”Almost always dark mode. Clients built on Outlook on the web recolour the text and background colours in a signature and leave its images alone, so light text laid over a dark picture turns dark against a picture that stays dark, and a faint grey disclaimer becomes hard to read.
Nothing in a signature can prevent it. The fix is to give the strip a real background colour, or to move the picture beside the text. The designer has a preview toggle and flags the blocks at risk. See dark mode.
Can we stop signatures without cancelling?
Section titled “Can we stop signatures without cancelling?”Yes. Delivery can be paused for the whole organisation, which stops what mailboxes receive and leaves the portal working, so templates can still be edited, previewed and tested. It changes nothing about seats or the subscription. See pausing delivery.
What happens if we stop paying?
Section titled “What happens if we stop paying?”Signatures stop being served. The add-in receives a 402 and applies nothing. Nothing is deleted, and restoring an active subscription restores signatures.
A failed payment is not immediate. Stripe retries the card for about three weeks and signatures carry on, with 21 days from the first failure before they stop. On invoice terms the same 21 days run from the invoice’s due date. See billing.
What happens at the end of the trial?
Section titled “What happens at the end of the trial?”Stripe converts it. With a card on file it charges the card. With no card on file it cancels the subscription, so an organisation that never adds a card stops rather than being billed unexpectedly.
On invoice terms it converts into a first invoice. There is no card to be missing, so nothing is asked for and nothing is cancelled.
Can we get our data out?
Section titled “Can we get our data out?”Templates export as portable JSON bundles including images. Everything held about a single mailbox can be exported for a subject access request. See import and export and compliance.
Where is our data held, and who else processes it?
Section titled “Where is our data held, and who else processes it?”In the United Kingdom or the European Economic Area at rest. Three sub-processors are involved: Microsoft for identity and directory data, Cloudflare for hosting and storage, and Stripe for billing. The data processing agreement names all three and commits to 30 days’ notice before that list changes, with a right to object and leave.
Your directory is the one to be clear about. It stays in your own Microsoft tenant, in the region you chose when you bought Microsoft 365, and Sigil reads it there rather than copying it somewhere else. See sub-processors.
What happens if there is a data breach?
Section titled “What happens if there is a data breach?”You are told within 48 hours of Tophhie Cloud becoming aware of one, and the notice describes the nature of the breach, roughly how many people and records are involved, the likely consequences and what is being done. Where the whole picture is not known yet, it is sent in phases rather than held back.
Deciding whether to notify a regulator or the people affected stays with your organisation, because you are the controller. The 48 hours is shorter than the 72 you get for that decision on purpose, since your clock only starts when you are told. See if there is a personal data breach.
Can we audit Sigil, or send a security questionnaire?
Section titled “Can we audit Sigil, or send a security questionnaire?”One reasonable security questionnaire in any twelve-month period is committed to in the data processing agreement, along with the information needed to demonstrate Article 28 compliance. Where that is not enough to satisfy a supervisory authority, there is a right to audit on 30 days’ notice, once a year, during business hours, and without access to any other customer’s data. See auditing Sigil.
Can we see when Tophhie Cloud support does something to our organisation?
Section titled “Can we see when Tophhie Cloud support does something to our organisation?”Yes, in your own change log. Support actions appear in the portal’s Audit log view under the organisation, access and support half, badged as support and reading “Sigil operator” rather than naming the member of staff. The individual is recorded in Tophhie Cloud’s own copy, which is what an investigation would read.
That covers being looked at as well as being changed. A read-only support session is recorded as “Viewed your portal”, so the answer to “has anyone at Sigil been in our tenant” comes from your records rather than from asking. See actions taken by Tophhie Cloud support.
Can we script Sigil, or pull its numbers into a dashboard?
Section titled “Can we script Sigil, or pull its numbers into a dashboard?”Yes. An Admin can create an API key, which is a credential for a script rather than for a person, with the areas you choose and optionally read-only.
A key reaches a named list of operations rather than the whole portal API. The reporting and cost-management pulls people ask for are all on it. Sending mail, moving money, granting access and reading a mailbox you name are not. The portal shows the full list beside your keys, and offers it as an OpenAPI document you can generate a client from.
There are no webhooks, so anything that needs to know about a change polls for it.
Is there an uptime commitment?
Section titled “Is there an uptime commitment?”Not on a direct subscription. The terms of use aim at a reliable service without guaranteeing uninterrupted availability, and the support page states an aim of a response within one business day.
There is one for managed service providers. The partner agreement commits to 99.9% monthly uptime backed by service credits, and to a four business hour response on escalations, because a provider is asked for those commitments by its own clients. See support and service level.
Either way, an outage affects signature management rather than mail flow. Sigil never gates the sending of email.
How do we tell whether Sigil is having problems?
Section titled “How do we tell whether Sigil is having problems?”status.usesigil.app carries the current state of the service and any incident
that is open. It is hosted away from Sigil, so it is still readable when Sigil
is not.
Check it before raising a ticket for signatures that have stopped across a whole organisation, and check billing and pausing delivery too, which stop signatures for reasons of their own and would not show as an incident. See the status page.
Can we pay by invoice rather than by card?
Section titled “Can we pay by invoice rather than by card?”Yes, by arrangement. Ask support and your account is put on invoice terms: the invoice is emailed and payable within an agreed number of days, thirty by default, and no card is asked for anywhere.
There is no setting for it in the portal, because extending credit is a commercial decision rather than a preference. See invoices and credits.
Can a managed service provider run this for us?
Section titled “Can a managed service provider run this for us?”Yes. See the partner programme.
Where do we go for help?
Section titled “Where do we go for help?”Help in the portal sidebar. It links to this documentation, gives the support
address and what to put in the message, and starts an email with your
organisation name and Microsoft 365 tenant id already filled in. If a provider
manages Sigil for you, it names them and points you at them first, since they are
the ones configuring your signatures. The same details are on
portal.usesigil.app/support for anyone not signed in.
Can we run Sigil alongside our existing signature product?
Section titled “Can we run Sigil alongside our existing signature product?”Not usefully. A server-side product that stamps signatures in mail flow will add its own on top of Sigil’s, producing two signatures per message. Switch a pilot group over rather than running both. See planning a rollout.
