How to Encrypt Email in Gmail (2026): What Actually Encrypts, What Doesn't, and What to Use Instead
Co-founder and CEO at Peony. I built the data room platform with a background in document security, file systems, and AI. Founded Peony in 2021 in San Francisco.
How to Encrypt Email in Gmail (2026): What Actually Encrypts, What Doesn't, and What to Use Instead
Last updated: August 2026
TL;DR — Gmail encrypts your mail in transit with TLS automatically, but that protection is opportunistic and stops at the inbox. Confidential Mode restricts forwarding, copying, printing, and download and lets you expire or revoke access — but it is not encryption, and Google states recipients "can still take screenshots or photos of your emails." True encrypted email in Gmail means Google Workspace Client-Side Encryption or hosted S/MIME — both edition-gated and admin-enabled. A free personal Gmail account has no true message-encryption option at all. And for documents that must not leak, no Gmail feature gives you per-viewer attribution or screenshot deterrence — a tracked link does.
I'm Deqian Jia, co-founder of Peony, a data room company. I wrote this because a version of the same conversation happens on our support channel almost every week: a founder sends an investor deck or a signed contract through Gmail, turns on "Confidential Mode" because it sounds like the secure option, and is genuinely shocked to learn how little it does. They think they encrypted the email. They didn't — Google never claimed they did — and the deck can still be screenshotted, photographed, or read by anyone the recipient hands the screen to.
Gmail's security is actually good for what it is built to do. The problem is naming. "TLS," "Confidential Mode," "Client-Side Encryption," and "S/MIME" all get flattened into the word "encryption" in people's heads, and three of those four are wildly different things. This guide separates them, gives you the exact steps for each, quotes Google's own fine print where it matters, and then draws an honest line: for private correspondence, Gmail's free defaults are the right answer, and for documents that must not leak, encryption is the wrong tool entirely.
What actually encrypts email in Gmail, and what doesn't?
The single most useful thing you can do is stop treating "encryption" as one feature. In Gmail there are four separate mechanisms, and only two of them are message encryption:
- Automatic TLS (transport encryption). Google says all Gmail messages use TLS automatically. This encrypts the connection between mail servers, but it is opportunistic — it only applies when the recipient's provider also supports TLS, and it protects nothing once the message lands. This is on for everyone, free, and invisible.
- Confidential Mode (action restriction, not encryption). Disables forward, copy, print, and download in the Gmail interface, adds an expiration date, and lets you revoke access. Google frames it as protection against accidental sharing. It is explicitly not encryption.
- Client-Side Encryption / CSE (true end-to-end). Encrypts the message in your browser before it reaches Google. Google servers and third parties cannot decrypt it. Google Workspace only, edition-gated, admin-enabled.
- Hosted S/MIME (true encryption via certificates). Certificate-based encryption and signing, managed by your Workspace admin. Also edition-gated.
So when someone asks "how do I encrypt email in Gmail," the honest answer depends entirely on the account. On a free personal account, there is no true encryption button — you get automatic TLS and Confidential Mode, and that's it. On Google Workspace, an admin can turn on CSE or hosted S/MIME, and only then does "send an encrypted email" become literally true. Everything below is just the detail behind that sentence.
How do I turn on Gmail Confidential Mode, step by step?
Confidential Mode is the feature most people mean when they search for this, so start here — just with clear eyes about what it is. It restricts what a recipient can do inside Gmail; it does not encrypt the message.
On the web, in the compose window: at the bottom of the compose window, click Toggle confidential mode (the lock-and-clock icon). If Confidential Mode is already on, click Edit at the bottom of the email to change the settings. From there you can:
- Set an expiration date for the email, after which the recipient can no longer open it.
- Revoke access to the email at any time, even after sending.
- Require an SMS passcode, so the recipient must enter a code sent to their phone to open the message.
On mobile, the flow is equivalent — open the compose menu in the Gmail app and choose Confidential mode before sending — though the exact labels move around across app versions, so follow the on-screen options rather than a fixed tap path.
One practical note on the SMS passcode: Google lists it as available to phone numbers from "North America, South America, Europe, Australia, Asia: India, Korea, and Japan." If your recipient is outside those regions, plan on the standard (no-SMS) flow. (Google's Confidential Mode help page has the full mechanics.)
What are the limits of Gmail Confidential Mode?
This is the part almost every "secure email" article skips, and it is the spine of this whole post. Confidential Mode is genuinely useful for one job — reducing accidental resharing — and genuinely misleading if you read it as encryption.
Here is Google's own language, verbatim from the Confidential Mode help page:
"While confidential mode can help prevent recipients from accidentally sharing emails, they can still take screenshots or photos of your emails. Recipients with malicious programs may still be able to copy or download your messages."
Read that twice. The recipient can screenshot the content. They can photograph the screen with a phone. The disabled "download" and "forward" buttons are UI restrictions inside Gmail's own web client, not a cryptographic lock on the data. Confidential Mode never encrypts the message — Google does not describe it as encryption anywhere, and neither should you.
So where does it help? If your worry is a well-meaning recipient who might forward your email to the wrong person, or accidentally leave a downloaded attachment in a shared folder, Confidential Mode meaningfully lowers that risk, and it costs nothing. If your worry is a recipient who wants to keep or leak the content, Confidential Mode does essentially nothing — and no amount of expiry or passcode changes that, because the screen is still a screen.
What is Google Workspace Client-Side Encryption, and who gets it?
Client-Side Encryption (CSE) is the real thing — the one feature in this article that lets you say "I sent an encrypted email in Gmail" and mean it. Google's own description, from the admin documentation, is that CSE provides end-to-end encryption:
"CSE helps to keep your organization's data private with end-to-end encryption that Google servers and third parties can't decrypt."
The key word is client-side: encryption happens "in your browser before any data is transmitted or stored in Google's cloud-based storage" (Gmail CSE help). Because Google never holds the decryption keys, Google itself cannot read the message — a materially stronger guarantee than TLS or Confidential Mode.
Three things you need to know before you get excited:
- It is edition-gated. Per Google, the supported editions are Frontline Plus, Enterprise Plus, Education Standard, and Education Plus. If your Workspace plan is not on that list, CSE is not available to you.
- It is admin-provisioned, not a personal toggle. An administrator must turn CSE on in the Admin console, and it requires an external key service plus identity-provider (IdP) integration. This is real infrastructure, not a checkbox — it is aimed at organizations with a compliance mandate, not at an individual who wants one encrypted email.
- It does not encrypt everything. CSE covers the message body, inline images, and attachments — but headers such as the subject line, timestamps, and recipients stay unencrypted. There is also roughly a 5 MB attachment ceiling noted on Gmail's CSE help page. When it is enabled and you compose a message, you turn encryption on via a Message Security control, and the recipient sees an "Encrypted message" indicator under your name.
Google has also been simplifying this: some Workspace configurations can now send encrypted email without full S/MIME certificate provisioning, though the exact product naming moves around — treat that as "the capability exists" rather than a specific label to quote.
How does hosted S/MIME encryption work in Gmail?
Hosted S/MIME is the other true-encryption option in Gmail, and it is certificate-based rather than key-service-based. Like CSE, it is a Google Workspace feature that an administrator enables — there is no personal-account version.
The edition list is deliberately different from CSE, and this trips people up. Per Google's hosted S/MIME admin documentation, the supported editions are Frontline Plus, Enterprise Plus, Education Fundamentals, Education Standard, and Education Plus. The practical difference from the CSE list is that hosted S/MIME adds Education Fundamentals — so an Education Fundamentals tenant can enable hosted S/MIME but not CSE. Keep the two lists straight when you plan.
Setup is an admin job: in the Admin console, go to Apps > Google Workspace > Gmail > User settings and enable "Enable S/MIME encryption for sending and receiving emails." User certificates must be in PKCS #12 format and meet current cryptographic standards. Once it is on and both sides have valid certificates, encrypted S/MIME messages correspond to the green padlock (enhanced encryption) covered in the next section.
S/MIME shines for pre-arranged, certificate-provisioned correspondents — two organizations that have exchanged certificates and communicate regularly. It is a poor fit for a one-off email to an external recipient who has no certificate, which is exactly the ad-hoc case most people are actually trying to solve.
What do the padlock icons in Gmail mean?
Gmail shows a small padlock to signal a message's encryption level, and once you know the code it is a quick sanity check. Per Google's encryption support page:
- Gray lock — standard encryption (TLS). This is what most messages show, because TLS is automatic. It means the connection is encrypted in transit to a provider that also supports TLS.
- Green lock — enhanced encryption (hosted S/MIME). The message is protected by S/MIME, the certificate-based encryption described above.
- Red open lock — unencrypted. Google states plainly that a red open lock "means the message is unencrypted." This is your warning sign: the connection to that recipient was not encrypted at all.
A useful habit is to glance at the icon when you're about to send something sensitive. A red open lock is a genuine red flag. But even a green lock is a statement about the channel, not about what the recipient does with the content once it arrives — a fully encrypted message can still be screenshotted, forwarded by photo, or printed by the person who legitimately received it.
Can I encrypt Gmail on a free personal account?
No — and it's better to hear that plainly than to chase a setting that doesn't exist. On a free, personal Gmail account you have exactly two protections: automatic TLS in transit and Confidential Mode. Client-Side Encryption and hosted S/MIME are both Google Workspace features that only an administrator can enable, so they are simply not present on a consumer account.
If you genuinely need end-to-end encrypted email from a personal address, that need is met by a different category of product — PGP-based add-ons or dedicated secure-email services that operate outside Gmail's native feature set. I'm deliberately not naming a specific vendor here, because the honest answer for most people asking this question is that they don't actually need to encrypt the email at all. They need the contents — usually a document — to be protected and trackable, and that is a different problem with a better solution than email encryption.
What does none of this protect, and what should I use instead?
Let me be fair to Gmail first, because the honest framing matters. For the overwhelming majority of email you send — a note to a colleague, a message with mildly sensitive details, ordinary business correspondence — Gmail's built-in protections are the right answer, and they're free. Every message rides TLS automatically. Confidential Mode is a real, no-cost way to reduce accidental oversharing and to expire access. Credit where it's due: you do not need to buy anything to send private mail responsibly, and you should not overcomplicate the common case.
But there is a specific class of thing email was never built to protect: documents that must not leak. An investor deck. A confidential information memorandum. A client's financial file. A signed agreement with a counterparty. For those, look at what none of the Gmail options give you, no matter how "encrypted" they are:
- Per-viewer attribution — knowing exactly who opened the file, not just that it was delivered.
- Read visibility — which pages were viewed, for how long, and by whom.
- Screenshot deterrence tied to identity — Confidential Mode can't stop screenshots (Google says so); an encrypted attachment certainly can't either.
- Per-viewer watermarking — the recipient's identity stamped into every page, so a leaked screenshot points back to its source.
The reason encryption doesn't solve this is structural. Encryption protects a message in transit and at rest. The moment the recipient legitimately decrypts and opens the file, it becomes an ordinary document on their machine — forwardable, printable, photographable. Encryption protects the envelope; it was never designed to protect the behavior of an authorized reader.
The tool that actually fits this job is a tracked link instead of an attachment. Rather than emailing the file, you email a link to it behind an access gate: the recipient verifies their identity, optionally accepts an NDA, and views the document in a browser with a per-viewer watermark, screenshot protection, and an expiry or revoke switch you control — while you see, page by page, who read what.
That is exactly what we built Peony to do, and I'll be specific about the tiers so you can judge it honestly. Link expiry and revoke are on every plan, including the Free tier — you can pull access back with one click even after sending, which is more than Gmail's recall or Confidential Mode reliably gives you. Page-level analytics are also free. Screenshot protection — which blocks and logs capture attempts — is on the Business plan at $30 per admin per month (billed annually). Dynamic per-viewer watermarks, stamped with the reader's identity in every frame, are on the Data Room plan at $52 per admin per month. We're used by 6,800+ customers who send exactly these kinds of documents, and viewers you share with are always free.
To be clear about the boundary: if you're writing an email, encrypt or Confidential-Mode it and move on. If you're sending a document that must not leak, stop attaching it and send a tracked link instead. That single change buys you the attribution, visibility, and control that no email-encryption feature — Gmail's or anyone else's — can provide.
Why does this matter? The data on email mistakes
The everyday risk with email isn't a movie-style interception of ciphertext — it's a person. In the 2025 Verizon Data Breach Investigations Report, the human element was involved in about 60% of breaches:
"Although the involvement of the human element in breaches remained roughly the same as last year, hovering around 60%…"
And within the category of plain human error, the same report is blunt about which mistake leads:
"Errors remain a persistent issue, with Misdelivery in the lead."
Misdelivery means sending data to the wrong recipient — the classic autocomplete-picked-the-wrong-name email. It's also a category regulators watch closely: the UK's Information Commissioner's Office tracks "Data emailed to incorrect recipient" as one of the incident types in its data security incident trends, defined as "where an email containing personal data is sent to the wrong email address."
Two things follow. First, Confidential Mode's expire-and-revoke controls are genuinely valuable precisely because misdelivery is so common — being able to pull back access after a wrong-recipient send is real protection. Second, none of that helps once a correctly delivered document leaves your control. Encryption addresses the wire; a tracked link with revoke, watermarking, and analytics addresses the far more common failure mode of the document itself walking out the door — which is why the 6,800+ customers who send decks and client files through Peony share a link, not an attachment.
Frequently asked questions
How do I send an encrypted email in Gmail?
On a personal Gmail account there is no true message-encryption button — you get automatic TLS in transit and Confidential Mode, which restricts forwarding and download but is not encryption. Real encrypted email in Gmail requires Google Workspace: an admin turns on Client-Side Encryption (CSE) or hosted S/MIME, both edition-gated and requiring setup. In a CSE-enabled account you compose the message, open the Message Security control, and turn encryption on before sending. Without Workspace and admin enablement, the encrypted-email option simply is not there.
How do I send a secure email in Gmail?
For everyday private mail, Gmail already sends over TLS automatically, so most messages are protected in transit at no cost. To also stop a recipient from forwarding, copying, printing, or downloading in the Gmail interface, use Confidential Mode — click Toggle confidential mode at the bottom of the compose window, set an expiration date, and optionally require an SMS passcode. Just remember Google's own caveat: Confidential Mode is not encryption, and recipients can still take screenshots or photos of your emails.
Is Gmail Confidential Mode actually encryption?
No. Google positions Confidential Mode as a guard against accidental sharing, not as encryption. It disables the forward, copy, print, and download buttons in Gmail, lets you set an expiration date, and lets you revoke access at any time. But Google states plainly that recipients "can still take screenshots or photos of your emails," and that recipients with malicious programs may still copy or download messages. Calling Confidential Mode "encrypted email" is the single most common mistake people make about Gmail security.
Does Gmail encrypt email automatically?
Partly. Google says all Gmail messages use TLS automatically, which encrypts the connection to the recipient's mail provider. But TLS is opportunistic — it only protects the hop when the other provider also supports TLS, and it does nothing once the message is sitting in an inbox. Automatic TLS is not the same as end-to-end message encryption. For content that must stay encrypted at rest and unreadable to intermediaries, you need Workspace Client-Side Encryption or hosted S/MIME, neither of which is on by default.
Can Gmail Confidential Mode stop screenshots?
No, and Google says so directly. The Confidential Mode help page states that while the feature can help prevent recipients from accidentally sharing emails, they "can still take screenshots or photos of your emails," and recipients with malicious programs may still be able to copy or download messages. Disabling the download and forward buttons raises the friction of casual resharing, but it cannot stop a determined recipient from photographing the screen. If you need real screenshot deterrence tied to a viewer's identity, that lives in a document platform, not in Gmail.
What is Google Workspace Client-Side Encryption and who gets it?
Client-Side Encryption (CSE) is Google's true encrypted-email option for Gmail. Google describes it as end-to-end encryption "that Google servers and third parties can't decrypt," because the message is encrypted in your browser before it ever reaches Google's storage. It is available on these Workspace editions: Frontline Plus, Enterprise Plus, Education Standard, and Education Plus. It is not automatic — an admin must turn it on, and it requires an external key service plus identity-provider integration. Message headers such as subject, timestamps, and recipients stay unencrypted.
How do I encrypt Gmail on a free personal account?
You cannot get true message encryption on a free personal Gmail account. Personal Gmail gives you automatic TLS in transit and Confidential Mode, but Client-Side Encryption and hosted S/MIME are Google Workspace features that only an administrator can enable. If you genuinely need end-to-end encrypted email from a personal address, people typically turn to a separate category of tools — PGP add-ons or dedicated secure-email services — rather than anything built into Gmail itself. For sending documents that must not leak, a tracked link is usually the better answer than encrypting the email.
What do the padlock icons in Gmail mean?
Gmail uses a small padlock to show the encryption level of a message. Per Google's help documentation, a gray lock means standard encryption (TLS), a green lock means enhanced encryption (hosted S/MIME), and a red open lock means the message is unencrypted. The gray lock is what most mail shows, because TLS is automatic. A red open lock is your signal that the connection to that recipient was not encrypted at all — a useful cue, but even a green lock protects the message channel, not what the recipient does with the content afterward.
How can I send private information through email for free?
For most private correspondence, Gmail's free defaults are enough: messages travel over TLS automatically, and Confidential Mode lets you disable forwarding and download and set an expiration date at no cost. That combination genuinely reduces accidental oversharing. What free email cannot do is show you who opened a document, tie a screenshot warning to a viewer's identity, or watermark each page. For that, a free tracked-link tool works better than an attachment — Peony's free tier includes page analytics plus link expiry and revoke, with screenshot protection on the Business plan.
Related resources
- How to send confidential documents via email (7 methods) — the full survey if you want to compare all seven approaches side by side, from Confidential Mode to S/MIME.
- How to encrypt email in Outlook — the sibling deep-dive for Microsoft 365 and Outlook.com, including Purview Message Encryption and its limits.
- How to send a password-protected PDF — when the thing you're protecting is a single file and a password is enough.
- Screenshot protection — how blocking and logging capture attempts works, and why it's tied to viewer identity.
- Dynamic watermarks — per-viewer watermarks that stamp the reader's identity into every page.
- Peony pricing — the Free, Business ($30/admin/month), and Data Room ($52/admin/month) tiers in full; expiry, revoke, and analytics are free on every plan.
You might also like
Aug 20, 2026
How to Encrypt Email in Outlook (2026): Every Method, Every Plan, and What Encryption Doesn't Do
Jul 17, 2026
How to Deliver Phase 1 ESA Reports: View-Only, Reliance Control (2026)
Jul 17, 2026
Stop Clients from Uploading Your Reports to ChatGPT (2026 Guide)

