Email Signature Software Buying Checklist
Drafted with AI assistance and reviewed before publishing. How we write and source articles →
TL;DR: Most email signature tools look interchangeable on a features page. The differences that actually matter — whether email routes through a third party, whether it works after migrating to new Outlook, what a Data Processing Agreement covers, whether directory sync updates automatically, whether the signature shows up on mobile, and what happens to pricing at renewal — only surface once you ask directly. This checklist gives you the questions to ask before a demo turns into a contract.
Why a features page doesn’t tell you what you need to know
Every email signature vendor’s website lists roughly the same things: directory sync, campaign banners, central deployment, GDPR-ready. Those words don’t mean the same thing from one vendor to the next, and the gap between “GDPR-ready” as a marketing claim and “here’s our DPA and sub-processor list” as a documented fact is exactly where evaluations go wrong.
This isn’t a vendor comparison — for that, see the honest, per-vendor breakdowns in Exclaimer Alternatives, WiseStamp Alternatives, and CodeTwo Alternatives, or the category overview in the three types of email signature software. This is the list of questions to take into any of those conversations, organised by the areas that consistently separate a tool that works from one that causes problems six months in.
Architecture: how does the signature actually get applied?
- Does email route through the vendor’s own servers before delivery, or is the signature inserted at compose time inside Outlook? These are two structurally different approaches with different implications for privacy, compose-time preview, and what happens if the vendor has an outage. The distinction — and why it matters more than it looks at first glance — is covered in full in server-side vs add-in: what’s the difference.
- If it’s server-side, what does the vendor’s infrastructure actually see? Full email body and attachments, or just headers and recipient metadata? Ask this directly rather than accepting “your data is safe with us” as an answer.
- Can the user see the signature before sending, or only after? No compose-time preview means the first time anyone sees a broken banner or wrong job title is in a sent email, not before.
Deployment: will it survive the next Microsoft platform change?
- Is the tool compatible with Microsoft 365 Centralised Deployment, so signatures push automatically to every licensed user without per-machine installation? If a vendor’s answer involves manual installation steps at scale, that’s a support burden that grows with headcount.
- Does it work in new Outlook for Windows, not just classic Outlook? Microsoft’s shift to a modern Office Add-ins framework has already broken tools built on the older COM/VSTO add-in model — covered in detail in new Outlook for Windows and email signatures. Don’t take “yes, we support new Outlook” at face value; ask when that support shipped and whether it’s been tested against your specific new Outlook build.
- What’s the actual propagation delay from a change in the admin console to it appearing in a user’s Outlook — minutes, hours, or dependent on a client restart?
Privacy and GDPR: what does the paperwork actually cover?
- Will the vendor provide a signed Data Processing Agreement, and does it name the actual sub-processors involved, not just a generic “we take security seriously” statement? Under UK GDPR, if a vendor processes personal data (including email content, if the tool is server-side) on your behalf, they are a processor and a DPA is a legal requirement, not a nice-to-have — see the ICO’s guidance on controllers, processors, and Article 28.
- Where is data hosted, and does that location matter for your regulatory requirements? EU/UK hosting is a genuine differentiator for some organisations and irrelevant for others — know which one you are before it becomes a negotiating point.
- If the tool is server-side, has anyone in your organisation actually confirmed what “server-side” means for email content specifically — not campaign click data, the email body itself? This is the single most consequential question in this entire checklist, and it’s covered at length in Email Signature Tools and GDPR: What Your DPO Needs to Know.
Directory sync: does it stay accurate without manual work?
- Does the tool pull employee data automatically from your directory (Entra ID, Active Directory), or does someone have to manually update a spreadsheet every time someone joins, leaves, or changes role?
- How quickly does a directory change propagate — a job title update, a new phone number, a department move? Same-day is reasonable; “next sync window, which runs weekly” is a real gap for anyone who changed role this morning.
- What fields does it actually support beyond name and title — department, office location, pronouns, direct dial versus mobile? Check this against what your signature template actually needs, not a generic list.
Mobile: does the signature show up everywhere people actually send email from?
- Does the signature appear when someone replies from the Outlook mobile app, or only from desktop? Mobile is a genuinely separate problem from desktop coverage, because Outlook mobile has its own local signature setting that most deployment methods don’t reach — worth testing directly with a vendor rather than assuming “central deployment” covers it.
- What happens on a native iOS or Android mail app, if anyone in your organisation uses one instead of the Outlook app?
- Ask for a live test, not a claim. Send a message from the Outlook mobile app during the demo and check whether the signature is there.
Legal compliance: does it actually cover what UK law requires?
- Does the template support the fields the Companies Act 2006 requires for a limited company — registered name, company number, and registered office address — and does it handle the FCA, SRA, or charity-specific variants if any part of your organisation needs them? The full requirements are covered in Email Signature Compliance for UK Businesses.
- Can different departments or entities have different legally required footers, if your organisation has more than one regulated entity or trading name under one Microsoft 365 tenant?
- Is there an audit trail showing who changed what and when — relevant if you ever need to demonstrate that a compliant footer was in place at a given date.
Pricing model: what does the number on the page actually mean?
- Per active user or per total licensed headcount? These produce very different bills for organisations with meaningful seasonal or contractor headcount variation.
- Annual contract or month-to-month, and what’s the actual renewal increase been for existing customers — ask this directly, not “what’s your typical renewal,” since published pricing and renewal pricing are not always the same thing.
- Is there a minimum seat count, and does it make sense for your current headcount plus reasonable growth over the contract term?
- What’s included at the tier you’re actually quoted, versus what’s gated behind the tier above it — campaign banners, analytics, and advanced directory rules are common upsells worth confirming up front. For a fuller per-vendor pricing breakdown, see Email Signature Software Pricing: Every Major Tool Compared.
Offboarding: what happens when someone leaves?
- Is signature access automatically revoked when a user is disabled in your directory, or does someone need to remember to do this manually as a separate step in the leaver process?
- What happens to that person’s data inside the vendor’s platform after offboarding — retained, deleted on a schedule, or dependent on you remembering to remove them from the vendor’s own admin console too?
- If your organisation ever needs to export historical signature configurations — for an audit, or a migration to a different tool — is that possible, or is the configuration locked into the vendor’s platform with no export path?
How to use this checklist
Not every question carries equal weight for every organisation. A five-person startup with no regulatory obligations can reasonably deprioritise the GDPR section; a 200-person FCA-regulated firm cannot. Work through the sections in order of what would actually cause a problem for your organisation if it went wrong — for most IT admins evaluating a tool for the first time, that’s architecture and privacy first, since those are the hardest to change after rollout, followed by deployment and directory sync, which determine the ongoing support burden.
The architecture and privacy sections are worth the most attention regardless of company size. A tool that routes email through third-party infrastructure isn’t automatically wrong for your organisation — but it’s a decision worth making deliberately, with the DPA read and the actual data flow understood, rather than discovered after the contract is signed.
Frequently asked questions
What questions should I ask before buying email signature software?
At minimum: does email route through the vendor’s own servers or get applied at compose time in Outlook; will they provide a signed DPA naming sub-processors; is it compatible with Microsoft 365 Centralised Deployment and new Outlook for Windows; does directory sync update automatically from Entra ID; does the signature appear on mobile, not just desktop; does the pricing model charge per active user or total headcount; and is access automatically revoked when someone is offboarded.
Is a Data Processing Agreement actually required for an email signature tool?
If the vendor processes personal data on your organisation’s behalf — which includes employee names and contact details at minimum, and full email content if the tool is server-side — they are a data processor under UK GDPR, and a DPA covering that processing is a legal requirement under Article 28, not an optional extra. See the ICO’s guidance on controllers and processors for the full detail.
Does email signature software work with new Outlook for Windows?
Not all of it, and this is worth confirming directly rather than assuming. Tools built on the older COM/VSTO add-in model do not carry over automatically to new Outlook’s modern add-in framework — see new Outlook for Windows and email signatures for what changed and why some existing deployments broke.
Why does per-user pricing vary so much between vendors?
Partly genuine differences in what’s included at each tier, and partly whether pricing is calculated per active user or per total licensed headcount — the latter can cost significantly more for organisations with contractors, shared mailboxes, or seasonal headcount that don’t need signatures applied to every account. Always ask which basis a quote uses. A full per-vendor comparison is in Email Signature Software Pricing: Every Major Tool Compared.
What’s the biggest mistake companies make when choosing an email signature tool?
Evaluating on features alone without asking the architecture and privacy questions directly. Most vendors’ feature pages look similar; the meaningful differences — whether email content passes through third-party infrastructure, what a DPA actually covers, how quickly directory changes propagate — only show up when asked directly, and they’re the ones hardest to unwind after a contract is signed and a rollout is complete.
SigHQ is building an add-in-first email signature management tool for Microsoft 365 organisations of 50–250 employees — signatures applied in Outlook at compose time, without email routing through third-party infrastructure. Join the waitlist to follow progress.