What encrypting an email actually does
Encrypting an email scrambles the message so that only someone with the right password or key can read it. Without encryption, your email travels across the internet in plain text — anyone intercepting it along the way can read what you wrote. Encryption turns your message into code that looks like gibberish to anyone except the person you intended to receive it.
The two main methods are end-to-end encryption (where only you and the recipient can read the message) and transport encryption (where the email service itself can still read it, but outsiders cannot). Most everyday email uses transport encryption by default. End-to-end encryption requires extra steps and usually means the recipient needs to know a password or have a matching key.
Key Takeaways
- Gmail, Outlook, and Yahoo all offer built-in encryption features that work without extra software, though setup varies by email provider.
- End-to-end encryption requires the recipient to have a matching key or password, which you must share separately from the email itself.
- PGP (Pretty Good Privacy) and S/MIME are the two encryption standards that work across different email providers, but both require more setup than built-in options.
- For most people, your email provider's standard encryption is enough; end-to-end encryption is mainly for messages containing sensitive financial, legal, or health information.
Using Gmail's built-in confidential mode
Gmail's Confidential Mode is the simplest encryption option if you use Gmail. It lets you set an expiration date on a message and remove the ability to forward, copy, or download it. The recipient still needs to verify their identity to read it, usually through a code sent to their phone.
To send a confidential email in Gmail: open a new message, click the lock icon with a clock at the bottom of the compose window, set an expiration date (anywhere from one hour to five years), and optionally require a passcode. Gmail will ask the recipient to verify their identity when they open the message. This is not true end-to-end encryption — Gmail can still read the message — but it prevents the recipient from easily sharing it.
The limitation is that Confidential Mode only works if the recipient has a Google account or a compatible email address. If you send it to someone with a non-Google email, they will receive a link instead of the message itself, and they must click through to read it on Google's servers.
Encrypting email in Outlook and Microsoft 365
Outlook offers Office 365 Message Encryption, which works similarly to Gmail's confidential mode. You can set expiration dates, prevent forwarding, and require the recipient to verify their identity. The feature is built into Outlook on the web and the desktop app.
To use it in Outlook: open a new message, click the "Encrypt" button in the toolbar (or look for "Options" and then "Encrypt"), and choose your settings. You can prevent copying and printing, set an expiration date, and revoke access to the message even after sending it. Like Gmail, this is not true end-to-end encryption, but it does prevent casual sharing.
Outlook's encryption works with any email address, not just Microsoft accounts. The recipient receives a link and can read the message in their browser after verifying their identity.
Setting up PGP encryption for maximum security
PGP (Pretty Good Privacy) is the standard for true end-to-end encryption that works across any email provider. With PGP, you create a pair of keys: a public key that you share with others, and a private key that you keep secret. When someone encrypts a message using your public key, only your private key can decrypt it.
Setting up PGP requires installing software. Popular options include Thunderbird (free email client with built-in PGP support), GPG4Win (for Windows), or Mailvelope (a browser extension that works with Gmail, Outlook, and others). The process involves generating your key pair, uploading your public key to a key server so others can find it, and then importing other people's public keys before you can read their encrypted messages.
PGP is powerful but has a learning curve. You must keep your private key safe, remember its password, and manage other people's keys. It is most common among people who regularly exchange sensitive information — journalists, lawyers, security researchers — rather than everyday users. If you choose PGP, plan to spend an hour or two learning the basics before sending your first encrypted message.
Using S/MIME for corporate and professional email
S/MIME (Secure/Multipurpose Internet Mail Extensions) is another end-to-end encryption standard, often used in corporate environments. It works by attaching a digital certificate to your email account. Once you have a certificate, encryption and signing happen automatically in Outlook, Apple Mail, and some other clients.
S/MIME certificates cost money (usually $50 to $200 per year) and must be issued by a trusted certificate authority. Your organization may provide one for free if you use corporate email. To set up S/MIME: obtain a certificate from a provider like Sectigo or DigiCert, import it into your email client, and enable signing and encryption in your email settings.
The advantage of S/MIME is that it works transparently once set up — you do not have to think about it for each message. The disadvantage is the cost and the fact that the recipient must also have S/MIME set up to read encrypted messages. It is most practical in organizations where everyone uses the same email system.
What to do if the recipient cannot decrypt your message
If you send an encrypted email and the recipient cannot open it, the most common cause is that they do not have the right key or software. If you used PGP, they need your public key imported into their email client. If you used S/MIME, they need their own certificate. If you used Gmail Confidential Mode or Outlook encryption, they may need to verify their identity or use a supported browser.
Before sending encrypted email to someone for the first time, ask them what encryption method they use or what their email provider supports. If they do not use encryption, you have two choices: send the message unencrypted and accept the risk, or use your email provider's built-in encryption (Gmail Confidential Mode or Outlook Message Encryption) and have them read it through a link instead.
For truly sensitive information and someone who does not use encryption, consider sending the message in two parts: send the encrypted message through email, and send the decryption password through a separate channel like a phone call or text message. This way, even if someone intercepts the email, they cannot read it without the password.
When you actually need to encrypt an email
Most everyday email does not need encryption. Your email provider already encrypts messages in transit (transport encryption), which protects them from casual interception. Encryption becomes important when the message contains information that would be harmful if read by the wrong person: passwords, financial account numbers, health information, legal documents, or anything you would not want your email provider to see.
If you are sending something sensitive to a lawyer, doctor, accountant, or financial advisor, ask them what encryption method they prefer. Many professionals have a standard process. If you are sending sensitive information to a friend or family member, Gmail Confidential Mode or Outlook Message Encryption is usually enough — it prevents the message from being forwarded or screenshotted easily, and it expires after a set time.
Frequently Asked Questions
Can I encrypt an email after I send it?
With Outlook Message Encryption, yes — you can revoke access to a message you already sent, which prevents the recipient from reading it even if they have not opened it yet. With Gmail Confidential Mode, you cannot unsend, but the message will automatically expire on the date you set. With PGP or S/MIME, once sent, the message cannot be recalled.
What if I forget my encryption password?
If you forget a password for PGP or S/MIME, you cannot recover it — the encryption is designed that way. You will need to generate a new key pair and ask people to use your new public key for future messages. For Gmail Confidential Mode and Outlook Message Encryption, you can revoke the message and resend it with a new password.
Does encryption slow down email?
Transport encryption (what your email provider does by default) is invisible and adds no noticeable delay. End-to-end encryption like PGP or S/MIME adds a few seconds to the sending and reading process as your computer encrypts and decrypts the message, but the difference is usually not noticeable on modern computers.
Can my email provider read encrypted messages?
With Gmail Confidential Mode and Outlook Message Encryption, yes — your email provider can read the message because they hold the decryption key. With PGP and S/MIME, no — only the recipient's private key can decrypt it, so your email provider cannot read it even if they wanted to.
What if the recipient uses a different email provider than me?
Gmail Confidential Mode and Outlook Message Encryption both work across different email providers — the recipient receives a link and reads the message in their browser. PGP and S/MIME also work across providers as long as both people have the software or certificates set up. Your email provider's built-in encryption is usually the easiest option for cross-provider communication.