Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Email encryption turns protected email content into unreadable ciphertext. The intended recipient—or, in some services, a provider that verifies the recipient—needs the right key or access method to read it. The important distinction is whether encryption protects only the connection carrying the email or keeps the message content protected until the recipient opens it.

What happens when an email is encrypted?

  1. The sender prepares the message. The email client or service applies a protection method. Depending on the design, this happens on the sender’s device or on a central service.
  2. The method encrypts the protected content. The result is ciphertext: data that is not readable without the required key or access method.
  3. The email travels through mail systems. Transport Layer Security (TLS) can encrypt a connection between systems. This protects a transport hop, not necessarily the message content from the services handling it.
  4. The recipient opens the message. In an end-to-end setup, the recipient’s client uses a private key to decrypt it. In a hosted encryption flow, a service may verify the recipient and display or decrypt the message through a protected viewer.

Encryption protects confidentiality, but it does not automatically authenticate the sender. Digital signing is a separate capability: it can help a recipient check who sent a message and whether it was altered. Microsoft describes S/MIME as a certificate-based solution that can both encrypt and digitally sign messages in its Microsoft 365 email encryption documentation.

What does “encrypted in transit” mean?

“Encrypted in transit” usually means TLS protects a connection while email moves between systems. Email may pass through multiple systems, and protection can apply separately to each connection. TLS is valuable, but it does not mean the message remains unreadable to the mail services that receive or process it after a connection ends.

That is why a security indicator for TLS is not proof of end-to-end encryption. Google’s Gmail encryption guidance distinguishes TLS transport protection from S/MIME message encryption. A TLS indicator says something about the connection under the provider’s stated conditions, not who can ultimately access the message content.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do the main email encryption methods differ?

Method What it protects and who handles keys What the recipient needs
TLS Encrypts a connection or transport session between mail systems; it does not by itself keep message content unreadable to those systems after delivery. No special recipient key is implied by TLS alone.
S/MIME Uses certificates for message encryption and digital signing. The recipient’s public key is used for encryption, while the recipient protects the corresponding private key. Compatible mail support and certificate/key exchange. See Microsoft’s S/MIME documentation and Outlook’s sending guidance.
PGP/MIME (OpenPGP) An end-to-end email security approach alongside S/MIME, as described by the IETF. Compatible software and successful key discovery and handling. Use with non-cryptographic mail clients can add friction. See IETF RFC 9787.
Provider-managed message encryption A service encrypts a message and may verify the recipient before decrypting or displaying it. The provider’s service is part of the trust model. May require signing in or entering a passcode to use a protected viewing flow. Availability depends on account and organization configuration; Microsoft describes options in its Microsoft 365 documentation.
Client-side encryption Encryption is applied in the browser before data is transmitted or stored in the provider’s cloud. In Gmail Workspace CSE, additional encryption covers message bodies, inline images, and attachments. Availability depends on supported Workspace editions and configuration. Gmail CSE’s additional encryption does not cover headers such as subject, timestamps, and recipient addresses. See Google Workspace’s Gmail CSE documentation.

Can an email provider read an encrypted email?

It depends on the method and who controls the keys. With TLS alone, the connection is protected in transit, but that does not establish that the provider cannot access message content while handling or storing it. With provider-managed encryption, the service may be able to decrypt or display a message after it verifies the recipient. With an end-to-end design, the intended recipient’s private key is needed to decrypt the message; a client-side design can keep key control with the user or organization rather than the provider.

Do not infer key custody from the word “encrypted.” Check the service’s specific documentation for where encryption happens, who can access the keys, and what the recipient must do to open the message.

What does email encryption leave exposed?

Encryption does not necessarily conceal email metadata. For example, Google says Gmail CSE’s additional encryption does not cover headers including the subject, timestamps, or recipient addresses. The exact exposure depends on the method, so sensitive subject lines and addressing information deserve care even when the body and attachments are protected.

Encryption also cannot control what an authorized reader does after opening a message. Microsoft notes that message encryption cannot prevent forwarding or printing in every case. A recipient may also copy or photograph content, so encryption is not a substitute for limiting disclosure to trusted recipients.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What can go wrong, and what should you check?

  • The recipient cannot open the message: S/MIME requires compatible support and certificates or keys; a hosted service may require a sign-in or passcode. Confirm the recipient’s access method before sending time-sensitive information.
  • A private key is lost or exposed: S/MIME depends on the recipient safeguarding the private key. Microsoft says a compromised private key requires a new key and redistribution of public keys to potential senders.
  • The security indicator shows an unencrypted message: Gmail’s red open-lock indicator means the message is unencrypted. Gmail advises against sending sensitive information in that case.
  • You need more than confidentiality: Use a signing capability when sender identity and message integrity matter; encryption alone does not prove who sent a message.

Before sending sensitive material, check the actual security indicator, make sure the intended recipients can use the protection method, and consider whether the subject line or other metadata itself is sensitive.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.