The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Gmail’s Workspace client-side encryption (CSE) lets eligible organizations send encrypted email from Gmail to people using other email providers, without asking users to exchange certificates or install custom encryption software. The convenience comes with an important qualification: administrators must configure the organization’s identity and key-access controls, and external recipients may need to authenticate to read a message.
What Gmail’s business encryption does
Gmail CSE encrypts message content in the browser before it is sent to or stored in Google’s cloud. The organization controls the encryption keys and the service that grants access to them; Google says the keys are stored outside Google’s infrastructure in a location chosen by the organization. That arrangement is intended to keep Google from holding the keys needed to decrypt the protected content.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive... | $349.00 | Buy on Amazon |
| 2 |
|
Kingston IronKey Vault Privacy 50 16GB Encrypted USB | $72.99 | Buy on Amazon |
Google announced a simpler Gmail CSE experience on April 1, 2025. Its stated goal was to make encryption available from the normal Gmail workflow without requiring end users to manage certificates or use custom software. Administrators can make the capability available to selected users or set it as a default for groups such as legal or finance teams.
How an encrypted message reaches its recipients
In Google’s technical description, Gmail creates a random data-encryption key for the message, encrypts the MIME message with it, then encrypts that data key using recipients’ public keys. A customer-controlled key-access service and an authenticated identity assertion are involved before Gmail delivers the message. This is client-side encryption: the content is protected before it reaches Google cloud storage, rather than being encrypted only after arrival.
#1 Best Overall
- Hardware encrypted drive
- Simple to use pin access. RPM-5400
- Administrator password feature
- Bus powered
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
Sending to someone outside Gmail is supported. Google announced general availability for sending CSE messages to recipients at other email providers on October 2, 2025. That does not guarantee that the recipient will see an ordinary, readable message directly in their usual inbox: Gmail’s documented flow can notify the recipient and direct them to a guest-account viewing experience, which may require authentication.
What administrators and users need
Administrator setup
A Workspace administrator must enable CSE and configure the organization’s identity and key-access controls. Google’s documentation also describes an option to permit encrypted mail to recipients who do not use S/MIME. Eligibility is not established by a complete edition-by-edition and region-by-region table in the reviewed official materials, so an organization should verify its Workspace edition, Assured Controls status, identity provider, and key service before planning a rollout.
Sending and reading
Once the organization has enabled the feature, users can encrypt messages through Gmail rather than switching to a separate encryption application. Google documents supported Gmail mobile workflows as well, though availability depends on the organization’s configuration. Supported organizational deployments can also use PIV and CAC smart cards; that does not mean any particular card or reader will work without checking the organization’s certificate issuer and setup.
For an external recipient, plan for an access step as well as delivery. The recipient may need to verify their identity through Gmail’s guest-account process to view the protected message. The exact experience depends on the configured identity and recipient flow, so confirm it with the organization’s administrator before sending time-sensitive material.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Rank #2
- FIPS 197 with XTS-AES 256-bit Encryption: Provides business-grade security with hardware-based encryption to protect your sensitive data
- Brute Force and BadUSB Attack Protection: Safeguards against unauthorized access attempts and malicious USB attacks with digitally-signed firmware
- Multi-Password Option with Complex/Passphrase modes: Offers flexible password configuration options to meet various security requirements and user preferences
- New Passphrase Mode: Enhanced security feature allowing users to create longer, more memorable password phrases for easier access without compromising protection
- Dual Read-Only (Write-Protect) Settings: Enables write protection functionality to prevent accidental data modification or deletion when needed
Client-side encryption versus Confidential mode
These features address different needs. CSE is about protecting message content with customer-controlled keys before it reaches Google’s cloud. Confidential mode offers controls such as restricting forwarding, copying, downloading, or printing, and setting an expiration. Those access restrictions are not a substitute for customer-controlled encryption keys.
| Feature | What it is for | Key or access model |
|---|---|---|
| Workspace client-side encryption | Encrypts message content before it reaches Google cloud storage; can be used with external email providers. | Organization controls the keys and key-access service. External recipients may need authentication to view the message. |
| Gmail Confidential mode | Applies message-use controls such as restrictions on forwarding, copying, downloading, or printing, and expiration. | The cited Gmail materials describe these access controls, not customer-controlled encryption keys as in CSE. |
Limits to weigh before using CSE
- Attachments and inline images: Gmail Help documents a 5 MB limit when additional encryption is enabled.
- Virus scanning: Google warns that Gmail cannot scan encrypted emails with attachments for viruses. This is a security and workflow trade-off, not merely a file-size inconvenience.
- Administration: CSE depends on organizational identity and key infrastructure, so it is not simply a setting each employee can turn on independently.
- Recipient experience: Cross-provider sending is available, but authentication or guest viewing can be less seamless than opening a normal email.
How to decide whether it fits your organization
CSE is most relevant when an organization needs stronger confidentiality for selected business communications and is prepared to operate the required identity and key-access controls. Before enabling it broadly, administrators should confirm eligibility and configuration, test the external-recipient viewing flow, and decide which groups should have access or use encryption by default. Teams that routinely exchange large attachments should account for the documented limit and the absence of virus scanning on encrypted messages with attachments.
The practical improvement is reduced friction: users can send protected mail from Gmail, including to recipients at other providers, without personally exchanging certificates or using a custom portal. It remains an administrator-led Workspace capability, not a universal Gmail feature that every account can enable.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

