Frequently Asked Questions

Quick answers to the questions that come up over and over.

Last reviewed: July 2026

Can I check my military email from home?

It depends on your service's current policy, and policies have tightened. Several services have restricted webmail and collaboration access from non-government computers in recent years, and rules differ between branches and even between applications. If your CAC setup is correct but a mail or Teams-style portal turns you away, check your service's current access policy before debugging further — the block may be intentional and no setting on your computer will change it.

The sanctioned workaround is usually a virtual desktop: your service streams you a real government machine and email works inside it. Air Force members should see our EITaaS VDI guide.

Do I need to buy any software?

No. The certificates are free from DISA, every OS's smart card support is built in or free (OpenSC), and Adobe Acrobat Reader's signing features are free. Be suspicious of anyone selling "CAC software" for basic access.

Why does the certificate picker show me two or three certificates?

Your card carries separate certificates for authentication, signing, and encryption. For website logins, pick the authentication certificate — usually the one displaying your 10-digit DoD ID number rather than an email address. More on the three certificates.

What's my DoD ID / EDIPI and where do I find it?

The 10-digit number printed on the back of your CAC (and encoded in your authentication certificate). Some systems display your identity as 1234567890@mil — that's the same number.

I got a new CAC and now nothing works.

Normal, annoying, and fixable. A new card means new certificates: fully restart your browsers so they enumerate the new card, re-select certificates where apps had cached the old ones (Outlook S/MIME settings especially), and re-register with portals that pinned your old certificate. To read old encrypted email you'll need to recover your previous encryption keys.

Can someone steal my identity if I lose my CAC?

The private keys are locked behind your PIN, and three wrong guesses freeze the card, so a lost card is not an instant compromise. Report the loss to your chain of command / security office promptly so the certificates get revoked, and get a replacement at a RAPIDS office.

Does my CAC work in a virtual machine?

Yes — VMware, VirtualBox, Parallels, and Windows VMs on Apple-silicon Macs can all pass a USB reader through to the guest. Attach the reader to the VM (not the host) in the VM's USB settings, then set up the guest OS normally. One gotcha: only one OS can own the reader at a time.

What about Windows on ARM, or Apple silicon?

Both fine. CCID readers are driverless and architecture-independent, and native smart card stacks on current Windows-on-ARM and Apple-silicon macOS work the same as on x86 machines.

Is it safe to enter my PIN on my personal computer?

The PIN prompt comes from your operating system or local software, and the PIN goes only to the card itself — that's by design. What you should never do is type your PIN into a website form. No legitimate DoD site asks for a CAC PIN in a web page.

Why did something that worked last month suddenly break?

The usual suspects, in order of likelihood:

  • A browser or OS update changed behavior — restart, then re-check browser settings.
  • DISA rotated certificate authorities — reinstall the current DoD certificates.
  • The website changed its requirements or its policy — check with that system's help desk.
  • Your certificates expired — check the dates on the card.

Who runs this site?

It's an open-source community resource — see About. It is not a DoD site, collects nothing from you, and exists because setting up a CAC at home shouldn't require archaeology.