Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Gmail doesn’t give every user a universal “Encrypt” button. It uses TLS automatically when the receiving mail provider supports it, but TLS protects a message in transit—not end to end. With a personal Gmail account, Confidential mode can limit access and common sharing actions, but it is not end-to-end encryption. For message-level encryption, eligible Google Workspace accounts may use S/MIME or client-side encryption (CSE), if an administrator has configured it.
Choose based on what you need to protect: TLS is transport protection; Confidential mode is an access-control feature; S/MIME and CSE are stronger message-encryption options with account, setup, and recipient requirements.
Choose the right Gmail protection
| Option | What it protects or does | Who controls the keys or access | End-to-end encryption? |
|---|---|---|---|
| TLS | Protects a message while it travels between mail providers, when both support TLS. | The providers handle transport encryption. | No. It does not provide end-to-end protection. |
| Confidential mode | Sets an expiration and restricts common actions such as forwarding, copying, downloading, and printing through Gmail’s interface. | The sender sets expiration and passcode options and can revoke access. | No. It is an access-control feature, not message encryption. |
| Hosted S/MIME | Encrypts supported messages using S/MIME certificates. | Google hosts the keys in Gmail’s hosted S/MIME setup. | It provides message-level encryption, but is not the same as an organization-controlled, zero-access arrangement. |
| Client-side encryption (CSE) | Encrypts the body, inline images, and attachments before they are sent or stored in Google’s cloud environment. | The organization controls the encryption keys. | It provides end-to-end encryption for supported message content in the configured Workspace setup. Headers such as the subject and recipient list are not additionally encrypted. |
These protections solve different problems. TLS helps protect data in transit; Confidential mode limits ordinary access and sharing through Gmail; message-level encryption protects content cryptographically. None can protect information after it is exposed on a compromised device or deliberately captured by its recipient.
Google’s Gmail encryption overview explains transport security and the work-or-school encryption options. Confidential mode’s limits are described in Google’s help page.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Send a protected email with Confidential mode
Confidential mode is the built-in Gmail option most personal-account users can use to restrict access. It can be useful if you want a message to expire or want to make casual forwarding and downloading harder. It does not turn the message into end-to-end encrypted email.
On a computer
- Sign in to Gmail and select Compose.
- In the compose window, select the Confidential mode icon near the bottom. If it is already enabled, Gmail may show Edit instead. The icon and label can vary slightly as Gmail’s interface changes.
- Turn Confidential mode on, then choose an expiration period.
- Choose a passcode option: use the standard passcode/authentication flow, or require an SMS passcode. With the standard option, Gmail may authenticate the recipient through Google or email them a passcode.
- Select Save. Write your message, add any attachments, and send it.
The expiration and passcode settings apply to both the message text and attachments. A non-Gmail recipient may receive a link and need to view the message in a browser or verify their identity, rather than reading the full content in their usual mail app. See Google’s desktop instructions for current controls.
On Android
- Open the Gmail app and tap Compose.
- Tap More in the upper-right corner, then select Confidential mode.
- Turn it on, choose an expiration date and passcode option, then tap Save.
- Write the message, attach files if needed, and send it.
If you choose SMS authentication, enter the recipient’s phone number, not your own. The recipient’s ability to receive the code can depend on the number, country, and carrier.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
On iPhone or iPad
Gmail’s iOS app also supports checking the encryption type on received messages. For sending Confidential mode messages, use the controls available in your current Gmail app; labels and placement may differ by app version. Google’s Confidential mode help covers the feature and its mobile behavior.
Revoke access to a confidential message
On Android, open Gmail’s menu, choose Sent, open the confidential message, and tap Remove access. Revoking access prevents further viewing through Gmail’s confidential-message mechanism. It cannot erase content someone has already read, copied by hand, photographed, or captured in a screenshot.
Is Gmail Confidential mode actually encrypted?
Not in the end-to-end sense. Confidential mode restricts certain actions in Gmail’s supported viewing experience and lets you set an expiration or revoke access. It does not promise that a recipient cannot preserve the information: screenshots, photographs, transcription, malware, and other means of copying remain possible. Treat it as a way to reduce casual sharing—not as protection from a determined or untrusted recipient.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
It is not suitable on its own when you need to protect content from the mail provider, meet a specific regulatory control, obtain independently verifiable encryption or signatures, or defend against a compromised recipient device. Also avoid treating a confidential message’s subject as protected; use a neutral subject and put sensitive details in the message body or attachment only when the protection is appropriate.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Use S/MIME or client-side encryption in Google Workspace
Gmail’s message-level encryption options are primarily for eligible work or school accounts. They are not controls that every personal @gmail.com user can turn on. The Workspace administrator must enable and configure the relevant feature, and account edition, policy, certificates, and recipient compatibility affect what appears.
Hosted S/MIME
S/MIME uses certificates and keys associated with senders and recipients. In Gmail’s hosted S/MIME setup, Google hosts the encryption keys. The administrator must configure the feature, and recipients need compatible certificates or a supported arrangement. Communication with an external recipient may require exchanging digitally signed messages first so certificates and public keys are available. This is a stronger message-encryption mechanism than TLS alone, but it is not equivalent to the organization retaining exclusive control of keys.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Client-side encryption (CSE)
CSE encrypts the message body, inline images, and attachments before transmission or storage in Google’s cloud environment. The organization controls the keys; Google says it cannot access the organization’s private keys or the decrypted message content. CSE does not additionally encrypt message headers such as the subject, timestamps, or recipients.
As of September 24, 2026, Google’s current documentation lists Enterprise Plus, Education Plus, Education Standard, and Frontline Plus among the editions that support CSE. Eligibility and availability can change, and an administrator still has to configure the feature. Check Google’s current CSE requirements or ask your organization’s administrator.
Free tools Windows power users keep installed
One-click scans. No signup required.
CSE can change the normal Gmail workflow. External recipients may have to authenticate through an identity provider or a Google Guest Account, depending on the organization’s setup. For external S/MIME communication, digital signatures and certificates may need to be exchanged; a certificate change may require exchanging signatures again. Some ordinary Gmail features are unavailable when additional encryption is on, including Confidential mode, signatures, printing, layouts, multi-send, Groups as recipients, delegated accounts, proposing meeting times, pop-out/full-screen compose, emojis, Google AI products, Gmail smart features, and some mobile screen-capture features.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
CSE also imposes a 5 MB upload limit for attachments and inline images. Certain executable, script, disk-image, and installer file types are blocked, and encrypted attachments may not receive ordinary virus scanning. Review Google’s CSE limitations and recipient guidance before relying on it for a particular file or workflow.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Check whether a Gmail message is encrypted
On a computer, open a received message, then click the arrow or Show details beside the recipient information. Look for Security. On Android, open the message and tap Show details. Gmail’s status may report:
- Standard encryption (TLS): the message used transport encryption. This is not end-to-end encryption.
- Enhanced encryption (S/MIME): the message has the supported S/MIME protection.
- No encryption supported: Gmail cannot confirm encrypted transport for that message.
A red or open-lock warning means Gmail cannot confirm TLS protection. Do not send passwords, financial details, identity documents, medical information, or similarly sensitive content under that warning. Use an appropriate secure alternative, or ask the recipient’s mail provider or administrator to support TLS. Google documents these status checks for desktop, Android, and iPhone and iPad.
These steps describe checking a received message’s status; the status of one message does not prove that every email in a conversation or future message has the same protection. If you need CSE or S/MIME, look for the relevant message-security controls in the supported Workspace compose workflow or confirm the setup with your administrator.
If the encryption option is missing or the recipient cannot open the message
- You use a personal Gmail account: TLS is automatic when supported by the recipient’s provider. Confidential mode is the Gmail-native option for restricted access, but it is not end-to-end encryption. Personal accounts do not generally have the Workspace S/MIME or CSE controls.
- You use a work or school account: Ask the administrator whether hosted S/MIME or CSE is enabled and whether your account, edition, and recipient are supported. Missing controls may reflect organization policy, account eligibility, certificates, or the recipient relationship.
- CSE is unavailable: Google directs users to contact their administrator. CSE is administrator-managed, not a setting an individual user can necessarily enable.
- A Confidential mode recipient cannot get in: Confirm the email address, selected passcode method, and recipient’s phone number if SMS was chosen. Check spam or filtering for an emailed passcode, and make sure the message has not expired or had access revoked. The recipient may need to open a browser link, sign in, or complete verification.
- An external CSE recipient is blocked: Check whether the organization requires sign-in through an identity provider or Google Guest Account. For S/MIME, confirm that compatible certificates and public keys are available.
- You see a red or open lock: Do not proceed with sensitive content. Choose a suitable secure sharing method or resolve TLS support with the recipient’s provider or administrator.
When Gmail isn’t enough
If you need end-to-end encryption but do not have Workspace encryption configured, consider an organization-approved encrypted-mail or secure file-sharing service. A separate service can be a better fit when both parties can use its workflow, but it is not automatically more private or convenient. Consider what metadata remains visible, how account recovery works, whether the recipient will adopt it, and whether it meets organizational policy. For business or school users already on Gmail, Workspace’s administrator-managed S/MIME or CSE may fit better than introducing a separate mailbox or service.
For highly sensitive files, choose the method based on the information’s risk and your organization’s requirements. Confirm the recipient and delivery channel, keep sensitive details out of exposed subject lines, and do not assume encryption can compensate for an insecure device or an untrusted recipient.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

