Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To encrypt an email so its contents are protected for the intended recipient, use a method both of you can open—usually S/MIME, OpenPGP (often called PGP), or an eligible provider-managed encryption feature. The recipient needs compatible software and the matching key, certificate, or access method. Set that up before writing sensitive content, and confirm the recipient can open the message.

What does it mean to encrypt an email?

Message encryption protects the message content for its intended recipient. With S/MIME or OpenPGP, the sender encrypts the message using the recipient’s public key or certificate; the recipient decrypts it with the corresponding private key. The recipient must have compatible software and access to that private key.

This is different from TLS, which can protect a connection as email travels between mail systems. TLS is useful, but an encrypted connection does not by itself mean that only the recipient can read the message while it is stored or handled by mail providers. NIST’s Guidelines for the Secure Use of Transport Layer Security (TLS) and RFC 9787 describe transport security and end-to-end email security as distinct protections.

Encryption also does not protect a message after it is opened on a compromised device, prevent an intended recipient from sharing it, or secure every copy in backups. Which headers or other metadata are protected depends on the particular method and provider.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
  • Hardware encrypted drive
  • Simple to use pin access. RPM-5400
  • Administrator password feature
  • Bus powered
  • Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm

Which email encryption method should you choose?

Method What you and the recipient need Practical trade-off
S/MIME Compatible S/MIME-capable mail clients, certificates for the participants, and the sender’s access to the recipient’s public certificate. Often fits organizations that issue and manage certificates. Certificate trust, distribution, and private-key backup or recovery need attention.
OpenPGP / PGP OpenPGP-capable software for both people, plus the recipient’s public key, verified as belonging to the intended person. Can work between different mail providers, but key discovery and identity verification may fall to the users.
Provider-managed encrypted message An eligible account or plan, any required administrator settings, and a recipient able to follow the provider’s access flow. May simplify access for recipients who do not use the same mail client. Check what is encrypted, who controls the keys, and whether the recipient needs a portal or sign-in.
Gmail client-side encryption An eligible Google Workspace edition with the feature enabled by an administrator. External access depends on configuration and controls. Google says the message body, inline images, and attachments get additional encryption; headers such as the subject, timestamps, and recipients do not.

There is no universally best choice. An organization that already manages certificates and compatible clients may find S/MIME practical. OpenPGP may suit people willing to exchange and verify keys. A managed feature can reduce setup for an outside recipient, but its eligibility and opening process depend on the provider’s settings.

How do I encrypt an email? A safe sequence

  1. Decide what needs protection. Consider whether the recipient must be able to reply securely and whether the subject or other metadata is sensitive. Email encryption will not fix an unsafe device, backup, or recipient endpoint.
  2. Check compatibility with the recipient. Find out whether both of you can use S/MIME, OpenPGP, or the same provider-managed feature. You cannot make a recipient’s incompatible client decrypt an encrypted message simply by choosing a setting on your side.
  3. Set up the method before composing sensitive content. For S/MIME, get your certificate and obtain the recipient’s public certificate through a trusted exchange or directory. For OpenPGP, obtain the recipient’s public key and verify its identity through a trusted channel. For a managed feature, confirm the account eligibility and administrator configuration.
  4. Confirm the recipient’s opening steps. If the method is new to either of you, send a non-sensitive test message first. Make sure the recipient can open it before sending confidential material.
  5. Protect your private key. Follow your organization’s backup and recovery policy, if applicable. Losing the only usable private key can make old encrypted messages unreadable; recovery arrangements vary by provider and organization.
  6. Check what is protected. Do not assume that a lock icon means every header or piece of metadata is hidden. Google, for example, says Gmail client-side encryption does not additionally encrypt the subject, timestamps, or recipients.

How do I send an encrypted email in Gmail?

Personal Gmail users should not assume they can turn on Gmail client-side encryption. Google documents that feature for the Workspace editions Enterprise Plus, Education Plus, Education Standard, and Frontline Plus, and an administrator must make it available. Google also says Gmail uses TLS when communicating with other providers; that transport protection is not the same as client-side message encryption.

For an eligible Workspace account, Google’s documented compose flow is to start a message, open Message security, enable Additional encryption before entering sensitive content, then complete and send the message. The recipient’s access can depend on administrator settings and, in some configurations, identity-provider sign-in.

Google describes external-recipient options that vary with configuration. With Assured Controls, administrators can allow recipients to use an existing Google account or require a guest account. Without Assured Controls, S/MIME use requires exchanging certificates. Confirm the current settings with your Workspace administrator before relying on a particular recipient flow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do I encrypt an email in Outlook?

Microsoft documents two routes: S/MIME and Microsoft Purview Message Encryption. Eligibility depends on the Microsoft 365 subscription and organization settings. S/MIME additionally requires setup and a digital certificate; Microsoft says an organization’s IT administrator or helpdesk may provide one, and it may be stored on a smart card or as a file.

With S/MIME, the recipient needs the matching private key and compatible support. Microsoft Purview encrypted messages can be read directly in listed Outlook clients and Microsoft 365; recipients using another mail service receive instructions for opening the message.

Setup steps differ among new Outlook, classic Outlook, and Outlook on the web, and can be controlled by organizational policy. Use Microsoft’s instructions for your exact Outlook version rather than treating one click path as universal. A qualifying subscription alone does not remove S/MIME’s certificate and recipient-compatibility requirements.

Rank #2
Kingston IronKey Vault Privacy 50 16GB Encrypted USB
  • FIPS 197 with XTS-AES 256-bit Encryption: Provides business-grade security with hardware-based encryption to protect your sensitive data
  • Brute Force and BadUSB Attack Protection: Safeguards against unauthorized access attempts and malicious USB attacks with digitally-signed firmware
  • Multi-Password Option with Complex/Passphrase modes: Offers flexible password configuration options to meet various security requirements and user preferences
  • New Passphrase Mode: Enhanced security feature allowing users to create longer, more memorable password phrases for easier access without compromising protection
  • Dual Read-Only (Write-Protect) Settings: Enables write protection functionality to prevent accidental data modification or deletion when needed
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can I encrypt an email to someone who uses a different provider?

Yes, if you use a compatible cross-provider method and the recipient can access the required key or opening flow. OpenPGP can work across providers when both people use compatible software and you verify the recipient’s public key. S/MIME can also work across mail services when both sides have compatible clients and certificates. A provider-managed message may offer an external-recipient flow, but the sender’s account and administrator settings determine whether it is available.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the recipient cannot use the chosen method, arrange a supported alternative or use another secure channel. Do not send the sensitive content as ordinary email on the assumption that the recipient will somehow be able to decrypt it.

How does S/MIME work in Apple Mail?

Apple documents per-message S/MIME in Mail on iOS, iPadOS, macOS, and visionOS. Mail can encrypt a message when it has the recipient’s email encryption certificate or can discover the certificate in an Exchange global address list. Apple’s locked indicator denotes a message sent encrypted with the recipient’s public key.

In organizations, certificates may be delivered through managed configuration, SCEP, or an Active Directory Certificate Authority. Apple also documents PIV smart cards for managed deployments, where a card can hold certificates and private keys used for signing or encryption. These are organization-managed setups, not a reason for a typical user to buy a smart card without an issued identity and compatible configuration.

How can I use OpenPGP with webmail or another mail client?

Use an OpenPGP-capable client or extension that supports your mail service, and verify the recipient’s key through a trusted channel before sending. The OpenPGP project’s software directory, marked updated July 30, 2025, lists options including Mailvelope for webmail and desktop and mobile software. Treat that directory as a compatibility starting point, not a security endorsement: the project says it has not audited the listed third-party applications and cannot guarantee their security. Check current availability and support before installing one.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does email encryption hide the subject line?

Not necessarily. Protected fields differ by method and provider, so check the specific service rather than inferring coverage from an “encrypted” label. Google explicitly says Gmail client-side encryption does not provide additional encryption for the email header, including the subject, timestamps, and recipients. Avoid putting sensitive details in a subject line when its exposure would matter.

What is the difference between encryption and signing?

Encryption limits who can read message content. A digital signature can help a recipient verify the sender’s identity and detect whether signed content was modified, but signing alone does not hide the message. S/MIME supports signing as well as encryption; use the appropriate feature for the protection you need.

Quick Recap

Bestseller No. 1
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
Hardware encrypted drive; Simple to use pin access. RPM-5400; Administrator password feature
$332.95

What to check before sending

  • Both sender and recipient can use the selected method and open the message.
  • The recipient’s certificate or public key is the right one, obtained through a trusted route.
  • Account, license, and administrator requirements are met for any provider-managed feature.
  • You know whether the subject and other metadata receive protection.
  • Your private key is protected and covered by an appropriate recovery plan.
  • You are not relying on encryption to protect an already compromised device or to control what the recipient does after reading.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.