What email encryption actually does and which method you need

Email encryption scrambles your message so that only the person you send it to can read it. The two main approaches are end-to-end encryption (where only you and the recipient hold the key to decode it) and transport layer encryption (where your email provider encrypts it in transit but can still read the contents themselves). Which one you use depends on what you're protecting against and which email service you have.

Most people already have transport layer encryption without doing anything — Gmail, Outlook, and Yahoo all encrypt emails in transit by default. But if you want encryption that even your email provider cannot break, you need end-to-end encryption, which requires either a tool built into your email service or a separate process.

The practical difference: transport layer encryption protects your message while it travels between servers. End-to-end encryption protects it everywhere — in transit, on your provider's servers, and on the recipient's device. End-to-end is stronger but requires the recipient to have compatible software and usually means you cannot search your own sent mail for keywords.

Key Takeaways

  • Gmail, Outlook, and Yahoo encrypt emails in transit automatically, but your provider can still read the contents — this is transport layer encryption.
  • End-to-end encryption (available through Gmail's confidential mode, Proton Mail, or PGP tools) scrambles messages so your provider cannot read them, but requires the recipient to have compatible software.
  • Gmail's confidential mode is the easiest option for most people: set an expiration date and revoke access anytime, and recipients do not need special software.
  • PGP encryption is stronger but has a steep learning curve and requires both sender and recipient to manage encryption keys.
  • If you use Outlook or Yahoo, your best option for end-to-end encryption is switching to Proton Mail or using a third-party PGP tool.

Using Gmail's confidential mode for straightforward end-to-end encryption

Gmail's confidential mode is the easiest way to send encrypted emails if you use Gmail. Open a new email, click the lock icon in the bottom toolbar (it appears next to the trash can), and select "Confidential mode." You will see two options: set an expiration date for when the recipient can no longer read the message, and choose whether to require a passcode.

If you require a passcode, Gmail sends it separately from the email itself — usually as a text message or through a second email. The recipient receives a link instead of the actual message and must enter the passcode to read it. You can revoke access at any time by opening the email in your sent folder, clicking the lock icon again, and selecting "Turn off confidential mode."

The limitation: confidential mode only works when both sender and recipient use Gmail. If you send to an Outlook or Yahoo address, the recipient will see a notification that they need a Gmail account to read it. Also, confidential mode does not encrypt attachments — those are still readable by Google.

Setting up Proton Mail for end-to-end encryption with any email address

Proton Mail is a free email service built around end-to-end encryption. Every email you send is encrypted by default, and recipients do not need a Proton Mail account to read encrypted messages — they receive a link and enter a password you set. To start, go to protonmail.com, click "Create account," and choose a username and password.

Once you are logged in, click "Compose" to write a new email. Enter the recipient's address and your message. Before sending, look for the lock icon next to the recipient's name. If it shows a green lock, the message will be end-to-end encrypted. If it shows an open lock, the recipient does not have Proton Mail and will receive a link instead — you will be asked to set a password they must enter to read it.

Proton Mail also lets you set an expiration date on emails: click the three-dot menu in the compose window, select "Expiration time," and choose how long the message stays readable. After that time, it disappears from both your inbox and the recipient's. This is useful for sensitive information you do not want sitting in an inbox indefinitely.

Using PGP encryption for maximum control and stronger security

PGP (Pretty Good Privacy) is the oldest and most widely supported encryption standard. It works with any email service — Gmail, Outlook, Yahoo — but requires you and your recipient to both install software and manage encryption keys. A key is a long string of characters that locks and unlocks your messages; you keep your private key secret and share your public key with anyone who wants to send you encrypted mail.

The most common PGP tool for Windows and Mac is Thunderbird with the Enigmail extension. read Thunderbird from mozilla.org, then go to the add-ons menu and search for "Enigmail" to install it. Once installed, Enigmail adds encryption options to your email compose window. Click "OpenPGP" in the menu bar and select "Key Management" to generate your first key pair.

When you generate a key, Thunderbird asks for a name, email address, and passphrase (a password that protects your private key). Choose a passphrase you can remember but that is not a word in the dictionary. Once your key is created, you can share your public key with anyone — they import it into their key management software, and then they can send you encrypted mail. You decrypt it by entering your passphrase.

The drawback: PGP has a steep learning curve. Both sender and recipient must manage keys, and if someone loses their private key or forgets their passphrase, encrypted messages become unreadable. It is the strongest option but requires more technical knowledge than Gmail's confidential mode or Proton Mail.

Encrypting emails in Outlook and Yahoo Mail

Outlook does not have a built-in encryption feature like Gmail's confidential mode. Your best option is to use Proton Mail instead, or to use a third-party PGP tool like Thunderbird with Enigmail (described above). If you must stay in Outlook, you can use Microsoft 365's Information Rights Management, but it requires a paid subscription and only works when both sender and recipient use Outlook.

Yahoo Mail also lacks native encryption. Like Outlook, your options are to switch to Proton Mail or use PGP through Thunderbird. Some Yahoo users also use browser extensions that add encryption, but these are less reliable than dedicated email services or PGP tools.

What happens when you send an encrypted email to someone without the right software

If you send a PGP-encrypted email to someone who does not have PGP installed, they will receive a message that looks like random characters — it is unreadable without the decryption key. They cannot open it, and there is no way for them to decrypt it on their own. This is why PGP requires coordination: both people must set up the software before encrypted mail can work.

Gmail's confidential mode and Proton Mail handle this more gracefully. If you use confidential mode and send to a non-Gmail address, the recipient gets a notification explaining that they need to access the message through a link. With Proton Mail, non-Proton recipients receive a link and are asked to set a password — no special software needed.

Choosing between the three approaches

Use Gmail's confidential mode if you use Gmail and most of your recipients do too. It is the easiest option and requires no setup from the recipient. Use Proton Mail if you want end-to-end encryption that works with any email address, or if you use Outlook or Yahoo and want a straightforward encrypted option. Use PGP if you need the strongest possible encryption and are willing to learn how to manage encryption keys — it is common among journalists, lawyers, and security professionals.

For most people, Gmail's confidential mode or Proton Mail covers the actual need: keeping sensitive information away from your email provider and making sure old messages disappear. PGP is overkill unless you are protecting against threats that include your email provider itself.

Frequently Asked Questions

Can someone forward an encrypted email to another person?

With Gmail's confidential mode and Proton Mail, no — the recipient cannot forward the message. With PGP, they technically can forward the encrypted text, but the new recipient would need the sender's public key to decrypt it, which makes forwarding impractical. This is one reason encrypted email is useful for sensitive information.

What if I forget my Proton Mail password?

You cannot recover a Proton Mail password because Proton does not store it. If you forget it, you lose access to your account and all your encrypted emails. Write your password down or use a password manager like Bitwarden or 1Password to store it securely.

Does encrypting an email slow it down?

No. Encryption happens on your device before the email is sent, so it does not affect delivery speed. The recipient may take a few extra seconds to decrypt it, but the difference is not noticeable.

Can my email provider see encrypted emails if I use their service?

With Gmail's confidential mode and Proton Mail, no — your provider cannot read the contents. With PGP, your email provider sees the encrypted text but cannot read it without your private key. Transport layer encryption (the default on Gmail, Outlook, and Yahoo) does allow your provider to read your emails, even though they are encrypted in transit.

Is encrypted email safe from hackers?

Encryption protects the contents of your email, but not your account itself. If a hacker gets your password, they can read your emails just like you can. Use a strong, unique password and enable two-factor authentication on your email account for the best protection.