Email encryption is the process of disguising the content of your email messages to protect them from being read by unwanted parties. Sensitive information such as social security numbers, passwords, login credentials and bank account numbers are vulnerable when sent via email.
When encrypting emails, it’s important to encrypt all of them, not just the ones with sensitive information. If only some of your emails are encrypted, it is a red flag for a hacker and could make your inbox even less secure. They will only have to hack into a few emails rather than sift through hundreds to find data they can use. We explain how to encrypt emails on multiple providers and summarize our tips in an infographic.
What is Email Encryption?
Email encryption is essentially mixing up the contents of an email so it becomes a puzzle that only you have the key to solve. The public key infrastructure (PKI) is used to encrypt and decrypt emails. Each person is assigned a public and private key in the form of digital code.
The public key is stored on a key server along with the person’s name and email address, and can be accessed by anyone. This public key is what is used to encrypt the email. If someone wanted to send you an email with sensitive information, they would use your public key to encrypt it. The private key is used to decrypt emails. It is stored somewhere safe and private on the person’s computer and only that person has access to it. The private key can also be used to digitally “sign” a message so the recipient knows it came from you.
Why is Email Encryption Important?
Email encryption is important because it protects you from a data breach. If the hacker can’t read your message because it’s encrypted, they can’t do anything with the information. Since 2013, over 13 billion data records have been lost or stolen. The average cost of a data breach in 2018 is $3.86 million. This number has grown by 6.4% since 2017. Data breaches can be costly because they take a while to identify. In 2018, the mean time to identify a breach was 197 days and the mean time to contain it was 69 days. Email encryption is a preventative measure you can take to avoid being part of a cybersecurity statistic.
Types of Email Encryption
The two main types of email encryption protocol are S/MIME and PGP/MIME. S/MIME (Secure/Multipurpose Internet Mail Extensions) is built into most OSX and iOS devices and relies on a centralized authority to pick the encryption algorithm. S/MIME is used most often because it is built into large web-based email companies such as Apple and Outlook.
PGP/MIME (Pretty Good Privacy/Multipurpose Internet Mail Extensions) relies on a decentralized trust model and was developed to address security issues facing plain text messages. Within this model, there is more flexibility and control over how well you want your emails to be encrypted, but it requires a third-party encryption tool.
How to Encrypt Emails in Gmail
Gmail already has S/MIME built into the app, but it only works if both the sender and receiver have it enabled.
- Enable hosted S/MIME.You can enable this setting by following Google’s instructions on enabling hosted S/MIME.
- Compose your message as you normally would.
- Click on the lock icon to the right of the recipient.
- Click on “view details” to change the S/MIME settings or level of encryption.
When changing the encryption levels note these color codes:
Green — Information is protected by S/MIME encryption and can only be decrypted with a private key.
Gray — The email is protected with TLS (Transport Layer Security). This only works if both the sender and recipient have TLS capabilities.
Red — The email has no encryption security.
How to Encrypt Emails in Outlook
Outlook is also compatible with the S/MIME protocol, but it requires additional setup.
- Enable S/MIME encryption.This process will involve getting a certificate or digital ID from your organization’s administrator and installing S/MIME control. Follow Office’s steps for setting up to use S/MIME encryption.
- Encrypt all messages or digitally sign all messages by going to the gear menu and clicking S/MIME settings. Choose to either encrypt contents and attachments of all messages or add a digital signature to all messages sent.
- Encrypt or remove individual messages by selecting more options (three dots) at the top of a message and choosing message options. Select or deselect “Encrypt this message (S/MIME).” If the person you are sending a message to doesn’t have S/MIME enabled, you’ll want to deselect the box or else they won’t be able to read your message.
How to Encrypt Emails on iOS
iOS devices also have S/MIME support built in as a default.
- Go to advanced settings and switch S/MIME on.
- Change “Encrypt by Default” to yes.
- When you compose a message and lock icon will appear next to the recipient. Click the lock icon so it’s closed to encrypt the email.
Note: If the lock is blue, the email can be encrypted. If the lock is red, the recipient needs to turn on their S/MIME setting.
Email Providers That Need Third-Party Encryption Tools
Email providers and devices that don’t have S/MIME compatibility built-in will need a third-party tool that allows them to use S/MIME or PGP/MIME protocol.
Encrypting Emails With Yahoo
Yahoo uses SSL (Secure Sockets Layer) as a layer of security to protect the account but requires third-party services to encrypt with S/MIME or PGP/MIME.
Encrypting Emails With Android
Android emails can be encrypted through S/MIME and PGP/MIME, but both require extra setup and a third-party app.
Encrypting Emails With AOL
Encrypting emails in AOL can be done manually, but requires a third-party tool to implement the PGP/MIME criteria. You first must download the PGP implementation and then obtain a program that allows you to use PGP encryption with your webmail provider.
Email Encryption Services
Email encryption can be done manually or by a secure email service. These email service apps each have unique offerings such as encrypting emails, attachments and contact lists. They do this in the background so you don’t have to worry about doing it manually.
Some notable providers are:
ProtonMail
ProtonMail allows you to enable end-to-end encryption and has PGP compatibility. It has different price levels, depending on the number of domains needed and messages sent per day.
Ciphermail
Ciphermail supports encryption through S/MIME, OpenPGP, TLS and PDF. It is popular for its compatibility with Android devices.
- Price: free
- Apps: Android
Mailvelope
Mailvelope is an OpenPGP encryption service for webmail. It’s compatible with Gmail, GMX, Outlook, Posteo, WEB.DE and Yahoo.
Virtru
Virtru provides end-to-end email encryption services and is compatible with Gmail, Outlook, Hotmail, Yahoo and a few other providers.
Startmail
Startmail supports encryption through PGP and is compatible with email services such as Outlook and Gmail.
- Price: free and paid plans
- Apps: none
Send 2.0
Sendinc offers military-grade encryption and is compatible with Outlook and Gmail.
- Price: free and paid plans
- Apps: Outlook plugin
Enlocked
Enlocked allows you to send and receive encrypted emails using PGP. It is compatible with Gmail, Yahoo, AOL, Microsoft and Outlook.
- Price: free and paid plans
- Apps: Chrome
Protect yourself and your business from new cybersecurity threats by taking preventative measures. Implementing an advanced cybersecurity solution will help you find the best prevention techniques and instruct you on efficient ways to apply them to keep you safe from hackers.
Sources:
PC Mag I Comparitech I Digital Guardian I Difference Between I Paubox I Office I Virtru I Ponemon Institute I Forbes I Breach Level Index
Panda Security
Panda Security specializes in the development of endpoint security products and is part of the WatchGuard portfolio of IT security solutions. Initially focused on the development of antivirus software, the company has since expanded its line of business to advanced cyber-security services with technology for preventing cyber-crime.
FAQs
How do I encrypt an email in Gmail iOS? ›
- On your iPhone or iPad, open the Gmail app .
- Tap Compose.
- In the top right, tap More. Confidential mode. ...
- Turn on Confidential mode.
- Set an expiration date, passcode and other controls. These settings impact both the message text and any attachments. ...
- Tap Done .
- Tap Compose in the Gmail app.
- In the top right, click More and then Confidential mode.
- Set an expiration date, passcode, and other controls, which applies to the message's text and attachments. ...
- Tap Done.
Open a new message in Yahoo Mail as usual. Click the Mailvelope icon in the top-right corner. Write your message and click Encrypt. Send the encrypted message.
How do I Encrypt an email in iOS? ›Open the Settings app. Choose Mail > Accounts. Select the account that has messages that you want to encrypt by default. Choose Account > Advanced > Encrypt by Default, then turn on Encrypt by Default.
How do I Encrypt an Outlook email on my iPhone? ›- Go to advanced settings and switch S/MIME on.
- Change “Encrypt by Default” to yes.
- When you compose a message and lock icon will appear next to the recipient. Click the lock icon so it's closed to encrypt the email.
Yahoo finally enables HTTPS encryption for email by default.
Can Gmail emails be encrypted? ›Gmail is capable of encrypting the email it sends and receives, but only when the other email provider supports TLS encryption. In other words, encrypting 100% of all email on the Internet requires the cooperation of all online mail providers.
How do I encrypt an Outlook email? ›In message that you are composing, click File > Properties. Click Security Settings, and then select the Encrypt message contents and attachments check box. Compose your message, and then click Send.
How do I turn on encryption in Gmail? ›- Sign in to your Google Admin console. ...
- In the Admin console, go to Menu Apps Google Workspace Gmail. ...
- On the left, under Organizations, select the domain or organization you want to configure. ...
- Scroll to the S/MIME setting and check the Enable S/MIME encryption for sending and receiving emails box.
When composing an email in Outlook for iOS and Android, the sender can choose to encrypt and/or sign the message. By tapping on the ellipses and then Sign and Encrypt, the various S/MIME options are presented.
Where is the Encrypt button in Gmail? ›
- On your computer, go to Gmail.
- Click Compose.
- In the bottom right of the window, click Turn on confidential mode . Tip: If you've already turned on confidential mode for an email, go to the bottom of the email, then click Edit.
- Set an expiration date and passcode. ...
- Click Save.
Click on the Security Settings button. First, check the box which says “Encrypt message contents and attachments.” Next, under Security, click on the dropdown under security settings, and select the S/MIME certificate. Lastly, choose the security label if applicable.
Are Outlook emails encrypted? ›If you have an Microsoft 365 Family or Microsoft 365 Personal subscription, Outlook.com now includes encryption features that let you share your confidential and personal information while ensuring that your email message stays encrypted and doesn't leave Microsoft 365.
How do I encrypt files on my Android phone? ›Encrypt Everything on Your Android Device
To do this, go to “Settings -> Security -> Encrypt phone.” If you're on Android 7.0 or higher, then you might find that this option isn't there. An alternative location for this is “Settings -> Storage -> Phone storage encryption.”
To enable iPhone encryption, open Settings, tap Face ID & Passcode, and make sure passcode is enabled. Data protection is enabled should be displayed at the bottom of the Face ID & Passcode screen. iPhone's data encryption does not prevent authorities from accessing your backup on Apple's servers.
Does iPhone have app encryption? ›You can passcode lock any app on your phone except for the Phone app. There is no option to turn off access to the Phone app at all. For apps like Messages or FaceTime, you need to edit the "Always Allowed" section of Screen Time to remove them for the limit to be enabled.
Can iPhone Encrypt messages? ›End-to-end encryption protects your iMessage and FaceTime conversations across all your devices. With watchOS, iOS, and iPadOS, your messages are encrypted on your device so they can't be accessed without your passcode.
Does Outlook Mobile Support Smime? ›Understanding S/MIME
S/MIME in Outlook for iOS and Android is supported with Microsoft 365 or Office 365 accounts using the native Microsoft sync technology. For a general overview of S/MIME, see S/MIME in Exchange Online.
Is there any other safer way to encrypt e-mails? You can use public-key encryption. In public-key encryption, two keys are created, one key for encoding and the other for decoding.
Is AOL email secure? ›AOL Mail. AOL Mail is another email provider that is considered bad for user privacy and data security.
How do I encrypt Gmail 2021? ›
Choose User Settings. Navigate to Organizations and choose the organization or domain you want to configure. Scroll to the S/MIME setting, and check the box that says “Enable S/MIME encryption for sending and receiving emails” Choose Save.
How do I encrypt Gmail 2022? ›In the dropdown menu, select “confidential mode.” Choose “confidential mode” to add an expiry date and a password. Set your expiry date and password settings and tap “save” to set the email as confidential. Configure the security settings and press “save.”
Is Outlook to Gmail encrypted? ›A relatively easy and inexpensive way to accomplish this goal is for both you and your recipients to use either Google's free Gmail service or Microsoft's free Outlook.com service (previously called Hotmail) because both of these solutions automatically encrypt your email messages from the moment they are sent to the ...
How do I send documents securely via email? ›- Protect Your Documents and Files Using a Strong Password. ...
- Use End-to-End Mail Encryption. ...
- Microsoft Office 365 Message Encryption (Information Rights Management) ...
- Use Encrypted File-Sharing Services to Link to Secure Files.
Go to the Gear Menu and click S/MIME settings. You can either encrypt the entire message and the attachments or you can add a digital signature to all the emails. Click on the three dots box and it will allow you to encrypt the message.
How do I mark an email as safe in Outlook app? ›Click Settings > Options > Block or allow. 2. To add an entry to Safe senders and recipients, type the email address or domain that you want to mark as safe in the Enter a sender or domain here text box, and then press Enter or click the plus icon new next to the text box.
How do I protect my email on Android? ›- Disable apps from installing via outside sources.
- Protect your devices with strong password security.
- Set the phone to lock immediately when not in use.
- Disable cloud backups and storage.
All communication between the Outlook app and the Microsoft 365 or Office 365-based architecture is through an encrypted TLS connection. The Outlook app is capable of connecting with the Microsoft 365 or Office 365-based architecture and nothing else.
How do I know if Outlook email is encrypted? ›Open the email you received from outside, click File > Properties. And look through the Internet headers section. If you see the word TLS in there somewhere you can safely tell your email is safe during the transition.
Is Gmail more secure than Outlook? ›Gmail is much more secure out of the box
Both Gmail and Outlook both offer more or less the same security features: multi-factor authentication, encryption in transit, spam, phishing, and malware detection.
How do I know if my Outlook is encrypted? ›
You should see “TLS” or a TLS version identifier in the header. It may say “TLS1. 2” or “TLS1. 3.” If you see this, TLS was used to secure this message.
What is the best way to encrypt my phone? ›To get started, go to Settings > Security > Encryption > Screen lock. Select the PIN option and enter a PIN. The Android device is ready to be encrypted. Use the settings menu to open the encryption screen below by following Settings > Security > Encryption > Encrypt tablet or Encrypt phone.
How do I fully encrypt my phone? ›- If you haven't already, set a lock screen PIN, pattern, or password. ...
- Open your device's Settings app.
- Tap Security & Location.
- Under "Encryption," tap Encrypt phone or Encrypt tablet. ...
- Carefully read the information shown. ...
- Tap Encrypt phone or Encrypt tablet.
- Enter your lock screen PIN, pattern, or password.
Select Settings > Security > Encrypt Device. On some phones, you may need to choose Storage > Storage encryption or Storage > Lock screen and security > Other security settings to find the encrypt option.
Is Gmail on iPhone encrypted? ›Gmail uses TLS, or Transport Layer Security, by default for all email communications, so all of your emails will use the standard encryption as long as the recipients also support TLS. But there's a way to add even more security to your Gmail emails, and you can use your iPhone's Mail app to do it.
How do I Encrypt a single email in Gmail? ›- On your computer, go to Gmail.
- Click Compose.
- In the bottom right of the window, click Turn on confidential mode . Tip: If you've already turned on confidential mode for an email, go to the bottom of the email, then click Edit.
- Set an expiration date and passcode. ...
- Click Save.
Start composing a message. Add recipients to the "To" field. To the right of your recipients, you'll see a lock icon that shows the level of encryption that is supported by your message's recipients. If there are multiple users with various encryption levels, the icon will show the lowest encryption status.
How do I enable encryption in Gmail? ›- Sign in to your Google Admin console. ...
- In the Admin console, go to Menu Apps Google Workspace Gmail. ...
- On the left, under Organizations, select the domain or organization you want to configure. ...
- Scroll to the S/MIME setting and check the Enable S/MIME encryption for sending and receiving emails box.
AOL Mail. AOL Mail is another email provider that is considered bad for user privacy and data security.
How do I encrypt an Outlook email? ›In message that you are composing, click File > Properties. Click Security Settings, and then select the Encrypt message contents and attachments check box. Compose your message, and then click Send.
Is Yahoo email secure? ›
"Anytime you use Yahoo Mail — whether it's on the web, mobile web, mobile apps, or via IMAP, POP or SMTP — it is 100 percent encrypted by default and protected with 2,048 bit certificates," Jeff Bonforte, Yahoo SVP of communication products, wrote in a company blog post.
Does Gmail have end to end encryption? ›Gmail is still not truly end-to-end encrypted, where only the communicators can read the contents of the email. It only works when the encrypted email is sent to a Gmail address. It's been three years and Google still has no updates for its end-to-end encryption tool.
How do I send documents securely in Gmail? ›- On your computer, go to Gmail.
- Click Compose.
- Click Attach .
- Choose the files you want to upload.
- In the bottom right of the window, click Turn on confidential mode . ...
- Set an expiration date and passcode. ...
- Click Save.