How to Encrypt Email in Outlook (2026): Every Method, Every Plan, and What Encryption Doesn't Do
Co-founder and CEO at Peony. I built the data room platform with a background in document security, file systems, and AI. Founded Peony in 2021 in San Francisco.
How to Encrypt Email in Outlook (2026): Every Method, Every Plan, and What Encryption Doesn't Do
Last updated: August 2026
TL;DR — To encrypt in Outlook: open a new message, choose Options > Encrypt, and pick Encrypt (Encrypt-Only) or Do Not Forward. The button only appears if your plan includes Microsoft Purview Message Encryption — Business Premium and E3/E5 include it; Business Basic and Business Standard do not. Encrypt-Only still lets the recipient forward, copy, and print. Do Not Forward removes those. Neither stops screenshots, and revocation almost never applies. Encryption protects the message in transit and gates access; it does not control what a trusted recipient does with the file afterward.
I'm Deqian Jia, co-founder of Peony, a data room company. People email us CIMs, financial models, and cap tables all day, and a striking number arrive marked "encrypted" — from a sender who is genuinely surprised, when I mention it, that the recipient can still forward the whole thing, print it, or photograph it on a phone. That gap between "I encrypted it" and "I controlled it" is the reason I wrote this guide.
This is the dedicated Outlook deep-dive. If you want the survey of every channel — Gmail Confidential Mode, S/MIME, password-protected PDFs, secure links — that lives in the 7-method roundup. Here I am going to stay narrow: exactly what to click in each Outlook client, which plans include encryption and which do not, what your recipient actually sees, and the honest limits of what email encryption can and cannot do. Where a fact is load-bearing, I link it to Microsoft's own documentation so you can verify it yourself.
How do I encrypt an email in Outlook?
Open a new message, go to Options, select Encrypt, pick the protection you want, and Send. The exact wording is nearly identical across clients. Microsoft's support page puts it plainly for the new Outlook for Windows: "In an email message, choose Options, and then select Encrypt. Pick the encryption that has the restrictions you want to enforce, such as Encrypt or Do Not Forward" (support.microsoft.com).
One naming note before the steps, because it trips up anyone reading older guides: the product used to be called Office 365 Message Encryption. That name is retired. Office 365 Message Encryption was deprecated on July 1, 2023 and automatically replaced with Microsoft Purview Message Encryption, built on Azure Rights Management. If a tutorial tells you to click "OME," it is out of date. The button in your ribbon just says Encrypt.
Here is the click-path for each client.
New Outlook for Windows
- Start a new email.
- On the Options tab, select Encrypt.
- Choose Encrypt (Encrypt-Only) or Do Not Forward depending on the restrictions you want.
- Finish the message and Send.
Classic Outlook for Windows
- Compose your message.
- Select Options > Encrypt.
- Choose the option with the restrictions you want — for example, Do Not Forward. Microsoft's phrasing: "In an email message, select Options > Encrypt. Choose the encryption option that has the restrictions you'd like to enforce, such as Do Not Forward" (support.microsoft.com).
- Send.
Outlook on the web
When composing, select the Encrypt option (your organization may also expose a sensitivity label configured for Encrypt-Only). Microsoft describes the entry point as "Outlook on the web with the Encrypt option or a sensitivity label that's configured for Let users assign permissions and the Encrypt-Only option" (learn.microsoft.com). The precise menu nesting varies by tenant configuration, so look for Encrypt in the compose toolbar or its overflow menu.
Outlook for Mac
Mac is supported through the same Encrypt option and sensitivity labels ("With the Encrypt option on Windows and macOS," per Microsoft). Choose Encrypt or Do Not Forward when composing.
One capability detail worth knowing: encrypt-only mail can be created in Outlook for PC 2019 and Microsoft 365, and it can be read in Outlook on the web, Outlook for iOS and Android, and Outlook for PC 2019 and Microsoft 365 (learn.microsoft.com). So even if you compose on desktop, your colleagues can read it on mobile.
If you followed those steps and there was no Encrypt option to click, this is not a bug. It is a licensing gate — the subject of the next section.
Why is the Encrypt button missing in my Outlook?
Because encryption is a licensed feature, and not every Microsoft 365 plan includes it. If Encrypt is grayed out or absent, your plan almost certainly does not carry the entitlement — and adding it is a per-user decision, not a global toggle. Microsoft is explicit: "Each user benefiting from Microsoft Purview Message Encryption needs a license to use message encryption" (learn.microsoft.com).
Here is the split, straight from Microsoft's licensing FAQ.
| Plan | Purview Message Encryption |
|---|---|
| Office 365 E3 / E5 | Included |
| Microsoft 365 E3 / E5 | Included |
| Microsoft 365 Business Premium | Included |
| Office 365 A1 / A3 / A5 | Included |
| Office 365 Government G3 / G5 | Included |
| Microsoft 365 Business Basic | Add Azure Information Protection Plan 1 |
| Microsoft 365 Business Standard | Add Azure Information Protection Plan 1 |
| Office 365 E1 | Add Azure Information Protection Plan 1 |
| Office 365 F3 | Add Azure Information Protection Plan 1 |
| Exchange Online Plan 1 / Plan 2 | Add Azure Information Protection Plan 1 |
The single most common surprise on that list is Business Standard. Many small teams assume the mid-tier business plan includes encryption because it includes almost everything else — it does not. You need Business Premium (or an E-series plan), or you add Azure Information Protection Plan 1 to Standard. Microsoft's exact wording: message encryption is offered as part of "Office 365 Enterprise E3 and E5, Microsoft 365 Enterprise E3 and E5, Microsoft 365 Business Premium, Office 365 A1, A3, and A5, and Office 365 Government G3 and G5," and you can add Azure Information Protection Plan 1 to plans including "Exchange Plan 1, Exchange Plan 2, Office 365 F3, Microsoft 365 Business Basic, Microsoft 365 Business Standard, or Office 365 Enterprise E1" (learn.microsoft.com).
If you are on a consumer plan rather than a work or school one, the rules are different — jump to the Personal and Family section.
What does the recipient see when I send an encrypted Outlook email?
It depends entirely on where they read their mail. Microsoft 365 and Microsoft-account recipients get a seamless inline experience; everyone else — Gmail, Yahoo, any non-Microsoft provider — gets a portal-and-passcode flow. Knowing which your recipient will hit saves you a confused reply.
Gmail, Yahoo, and other non-Microsoft recipients. They receive a wrapper email that directs them to the encrypted message portal. Microsoft describes it directly: recipients on Gmail and Yahoo "receive a wrapper mail that directs them to the encrypted message portal where they can easily authenticate using a Microsoft account, Gmail, or Yahoo credentials" (learn.microsoft.com). In practice the recipient clicks Read the message, then chooses Sign in with Google (or their provider) or requests a one-time passcode that gets emailed to them. That passcode is short-lived: "Each passcode expires after 15 minutes" (support.microsoft.com). If your recipient says "it's asking me to sign in to read your email," this is why — it is expected behavior, not a phishing attempt.
Microsoft 365 and outlook.com recipients. No portal, no passcode. They read the message natively, inline, in a supported Outlook client. Microsoft: "Microsoft 365 and Microsoft account recipients (for example, outlook.com users) get an inline experience in supported Outlook clients. All other recipient types, such as Gmail and Yahoo recipients, get a link-based experience" (learn.microsoft.com).
This inline-vs-link distinction is not just cosmetic. It quietly determines whether you can ever revoke the message — which I cover in the limits section — because only the link-based, branded experience is revocable.
Encrypt-Only vs Do Not Forward: which one should I use?
Choose Encrypt-Only when you want privacy in transit but trust the recipient to handle the content. Choose Do Not Forward when you need to limit what they can do with it. Both encrypt the message and force the recipient to authenticate; the difference is the bundle of usage rights that ride along.
With Encrypt-Only, Microsoft says recipients "have all usage rights except Save As, Export and Full Control. This combination of usage rights means that the recipients have no restrictions except that they can't remove the encryption. For example, a recipient can copy from the email, print it, and forward it" (learn.microsoft.com). Read that last line twice — Encrypt-Only is not a leak control. It scrambles the message on the wire and gates who can open it, and that is all.
With Do Not Forward, the rights are stripped: "the recipients can't forward it, print it, or copy from it. For example, in the Outlook client, the Forward button isn't available, the Save As and Print menu options are not available, and you can't add or change recipients in the To, Cc, or Bcc boxes" (learn.microsoft.com).
| Right | Encrypt-Only | Do Not Forward |
|---|---|---|
| Message content encrypted (not just the transport connection) | Yes | Yes |
| Recipient must authenticate | Yes | Yes |
| Forward the message | Allowed | Blocked |
| Copy from the message | Allowed | Blocked |
| Print the message | Allowed | Blocked |
| Change To / Cc / Bcc | Allowed | Blocked |
| Remove the encryption | No | No |
| Screenshot or photograph the screen | Not blocked | Not blocked |
Attachments behave differently depending on the option, and this is where senders get caught out:
- Do Not Forward attachments. Unencrypted Office documents attached to a Do-Not-Forward email "automatically inherit the same restrictions. The usage rights applied to these documents are Edit Content, Edit; Save; View, Open, Read; and Allow Macros" (learn.microsoft.com).
- Encrypt-Only attachments. Attached Office docs inherit the email's permissions and, per Microsoft, "when they're downloaded, they can be saved, edited, copied, and printed from Office applications by the recipients" (learn.microsoft.com). An admin can change this behavior with
Set-IRMConfiguration -DecryptAttachmentForEncryptOnly $trueso the attachment opens unencrypted. - Supported Office formats stay protected — even after download. For a supported format like Word, Excel, or PowerPoint, protection persists: "If a file format is supported ... the file is always protected, even after the recipient downloads the attachment." Microsoft's own example: if a Do-Not-Forward attachment is downloaded, re-attached, and mailed to someone new, "when the new recipient receives the file, they can't open it" (learn.microsoft.com).
That last point is the strongest protection in the whole feature — and it is worth crediting plainly. For supported Office formats sent Do Not Forward, the rights genuinely travel with the file. The gaps are everything that is not a supported Office format, everything the recipient can screenshot, and the Encrypt-Only case, where the whole point is that forwarding and copying stay on.
How do I encrypt email on a Microsoft 365 Personal or Family plan?
If you pay for Microsoft 365 Personal or Family, you get an Encrypt button in Outlook.com and Outlook, and the path mirrors the work version. Microsoft's steps: "compose a new message, select the Options ribbon, and then select Encrypt" (support.microsoft.com).
You get two choices, and Microsoft's own descriptions are the clearest way to tell them apart:
- Encrypt — "Your message stays encrypted and doesn't leave Microsoft 365."
- Do Not Forward — "Your message stays encrypted within Microsoft 365 and can't be copied or forwarded."
The catch is the subscription itself. Encryption is a paid-tier feature here too: "To use encryption, your account must have a qualifying Microsoft 365 subscription." A free outlook.com account has no Encrypt button at all — it falls back to "opportunistic Transport Layer Security (TLS) to encrypt the connection with a recipient's email provider" (support.microsoft.com). Opportunistic TLS only protects the hop when the other provider also supports TLS, and it does nothing once the message lands in the recipient's inbox. So on a free account, there is no message-level encryption to turn on — only transport encryption you do not control.
When should I use S/MIME instead?
Use S/MIME when you and your correspondent have already exchanged certificates and mail each other regularly — a pre-arranged, provisioned relationship. Do not reach for it to send one sensitive email to a Gmail user you have never mailed before; the setup overhead makes it the wrong tool for ad-hoc external mail.
S/MIME is genuine end-to-end encryption, but it front-loads a lot of work. Before you can send anything, "you must first get a digital ID, otherwise known as a digital certificate, and add it to the keychain on your computer." Both sides need compatible software: "you and the recipient must have a mail application, such as Outlook, that supports the S/MIME standard." And certificates do not appear automatically — "New Outlook doesn't automatically import digital certificates. You must install the certificate manually or ask your administrator to configure policies to automatically install certificates" (support.microsoft.com).
Because S/MIME requires a certificate on both ends plus a prior key exchange, it is impractical for one-off external recipients. Microsoft Purview Message Encryption — the portal-based flow this guide has covered — is the right tool for ad-hoc external mail, since the recipient needs nothing pre-installed; they authenticate through the portal. Reserve S/MIME for pre-arranged, cert-provisioned correspondents where the one-time setup pays off over many messages.
One more piece of context, kept to a sentence: Microsoft Purview Message Encryption is "an evolution of the existing IRM and legacy OME solutions" (learn.microsoft.com), and the same Encrypt and Do Not Forward options can be applied by users directly or automatically through sensitivity labels, mail-flow (transport) rules, or DLP policies your admin configures.
What Outlook encryption does NOT do (and what to use instead)
Encryption protects the message in transit and gates who can open it. It does not control what a trusted recipient does with the content once they are in. That distinction is the whole reason a data room exists, so let me lay out the four specific gaps, quoting Microsoft's own docs, and then say plainly when built-in encryption is the right answer and when it is not.
1. Encrypt-Only recipients can forward, copy, and print. As covered above, Microsoft states outright that under Encrypt-Only "a recipient can copy from the email, print it, and forward it" (learn.microsoft.com). If you picked Encrypt over Do Not Forward, you have no control over redistribution.
2. Screenshots are not blocked — the Copy right explicitly includes them. The rights model's Copy usage right "enables options to copy data (including screen captures) from the item" (learn.microsoft.com). There is no per-recipient watermarking anywhere in the rights model, and nothing stops a recipient photographing the screen with a phone. Do Not Forward removes the in-app buttons; it does not defeat a camera.
3. Revocation is narrow — much narrower than most people assume. You can only revoke when "the recipient received a link-based, branded encrypted email. If the recipient received a native inline experience in a supported Outlook client, then you can't revoke the message" (learn.microsoft.com). Even that requires Advanced Message Encryption (a separate paid tier) plus a custom branding template. Sender self-revoke is more limited still: it works only from Outlook on the web, only for "a single recipient that uses a social account such as gmail.com or yahoo.com," via a Remove external access link in Sent — and "you cannot revoke a mail that you sent to a recipient that uses a work or school account from Microsoft 365 or a user that uses a Microsoft account, for example, an outlook.com account" (learn.microsoft.com). Revocation and expiration only work for messages sent outside your organization where "the recipients must access the email through the web portal" (learn.microsoft.com). In other words: the smoother the recipient's experience, the less you can undo.
4. There is a 25 MB ceiling. "The maximum message size you can send with Microsoft Purview Message Encryption, including attachments, is 25 MB" (learn.microsoft.com). A full board pack, a data-heavy model, or a CIM often will not fit.
Why does any of this matter? Because the most common way sensitive data goes to the wrong place is not a hacker — it is a slip. In the 2025 Verizon Data Breach Investigations Report, the human element was "hovering around 60%" of breaches, and among mistakes, "Errors remain a persistent issue, with Misdelivery in the lead" — sending data to the wrong recipient. Misdelivery is a recognized incident category with regulators too: the UK ICO tracks "Data emailed to incorrect recipient" as a distinct data-security incident type (ico.org.uk). Encryption exists precisely because email is easy to mis-send. But encryption fixes the wire, not the after-life of the file.
So here is the honest, segmented recommendation.
For everyday private correspondence — an HR note, a contract redline, a client update — Microsoft Purview Message Encryption is the right answer, and it is already in your plan (if your plan includes it). Use it. It is built in, the recipient experience is decent, and encrypting a routine sensitive email is strictly better than not. Credit where due: Microsoft built a solid feature for exactly this job. Pick Encrypt for privacy, Do Not Forward when you also want to discourage casual redistribution, and you are done.
For documents that genuinely must not leak — CIMs, financial models, client files, anything you would be fired for losing control of — an encrypted attachment is the wrong instrument. Once it downloads, you have zero visibility (you cannot see whether it was opened, by whom, or how many times) and zero control after send (no revocation for inline recipients, no watermark, no screenshot deterrent, and a 25 MB wall). The pattern that actually does that job is not an attachment at all — it is a tracked link to the file, gated by an NDA, watermarked per viewer, screenshot-protected, revocable at any moment, and instrumented with page analytics so you know exactly who read what.
That is the job Peony does, and it is why 6,800+ customers send deal documents as links instead of attachments. Concretely:
- Screenshot protection deters and logs capture attempts — available on the Business plan ($30/admin/month). Email encryption has nothing equivalent; see how it works.
- Dynamic, per-viewer watermarks stamp each viewer's identity across every page, so a leaked screenshot traces back to a person — on the Data Room plan ($52/admin/month). The Purview rights model has no watermarking at all.
- Link expiry and one-click revoke work on every tier, including Free — not just for Gmail recipients, not gated behind a branding template, and effective even after the document has been opened.
- Page-level analytics are free, showing who opened the file, when, and how long they spent on each page — the visibility an attachment can never give you.
This is not "encryption versus Peony." For most email, encryption wins and it is free in your license. Peony is for the narrow, high-stakes case where you need to keep controlling a document after it leaves your outbox. If you are weighing all the channels side by side, the 7-method roundup ranks each by what it actually protects, and across 6,800+ customers the deals that stay controlled are the ones shared as tracked links rather than mailed as files.
Frequently asked questions
How do I send a secure email in Outlook?
In a new message, choose Options, then select Encrypt, and pick the protection you want. Encrypt (Encrypt-Only) keeps the message encrypted and gates access behind authentication but leaves the recipient able to forward, copy, and print. Do Not Forward encrypts it and removes the forward, copy, and print rights. Both use Microsoft Purview Message Encryption, which is included in plans like Microsoft 365 Business Premium and E3/E5. If you also need to stop leaks after delivery, encryption alone will not do it.
How do I send an encrypted email in Outlook?
The path is the same across most Outlook clients: in an email message, choose Options, select Encrypt, then pick the encryption with the restrictions you want, such as Encrypt or Do Not Forward, and Send. In classic Outlook for Windows it is Options > Encrypt. Outlook on the web uses the same Encrypt option when composing. A Microsoft 365 Personal or Family subscriber gets the same Encrypt button in Outlook.com. If the Encrypt option is missing, your plan almost certainly does not include the license.
Why is the Encrypt button missing in my Outlook?
The Encrypt option is a licensed feature. Microsoft Purview Message Encryption is included in Office 365 E3/E5, Microsoft 365 E3/E5, Microsoft 365 Business Premium, Office 365 A1/A3/A5, and Office 365 Government G3/G5. It is NOT included in Microsoft 365 Business Basic, Business Standard, Office 365 E1, F3, or Exchange Online Plan 1/2 — those need Azure Information Protection Plan 1 added per user. Business Standard not including it is the single most common surprise. Each user who sends encrypted mail needs the license.
Can recipients forward an encrypted Outlook email?
It depends on which option you chose. With Encrypt-Only, Microsoft states the recipient "can copy from the email, print it, and forward it" — the only thing they cannot do is remove the encryption. With Do Not Forward, the Forward button is unavailable and the Save As and Print menu options are removed, and they cannot copy from it. If forwarding must be blocked, choose Do Not Forward, not Encrypt. Neither option stops a recipient from screenshotting or photographing the screen.
Can I revoke an encrypted email in Outlook?
Only in narrow cases. Revocation requires Advanced Message Encryption plus a custom branding template, and it works only when the recipient received a link-based, branded encrypted email. If they got the native inline experience in a supported Outlook client, you cannot revoke it. Sender self-revoke is limited to Outlook on the web, for a single external social-account recipient (gmail.com or yahoo.com), via a Remove external access link in Sent. You cannot revoke mail read by Microsoft 365, work or school, or outlook.com recipients.
What does a Gmail recipient see when I send an encrypted email from Outlook?
A Gmail or Yahoo recipient receives a wrapper email that directs them to the encrypted message portal, where they authenticate using a Microsoft account, Gmail, or Yahoo credentials, or a one-time passcode emailed to them. They click Read the message, choose Sign in with Google or request a passcode, and each passcode expires after 15 minutes. Microsoft 365 and Microsoft account recipients (like outlook.com users) instead get a native inline experience in supported Outlook clients, with no portal and no extra step.
Does Outlook email encryption stop screenshots?
No. Microsoft Purview Message Encryption has no capability to block screenshots or photos. The Copy usage right in the rights model explicitly covers "screen captures," and there is no per-recipient watermarking in the rights model at all. Do Not Forward removes the in-client forward, copy, and print buttons, but a recipient can still capture the screen with a phone or a screenshot tool. If you need to deter and log capture attempts, that is a document-security capability, not an email-encryption one.
What is the difference between Encrypt-Only and Do Not Forward?
Both encrypt the message and require the recipient to authenticate; the difference is usage rights. Encrypt-Only gives recipients all rights except Save As, Export, and Full Control — so they can copy, print, and forward, but cannot strip the encryption. Do Not Forward removes forwarding, printing, and copying, and prevents changing the To, Cc, or Bcc recipients. Attachment behavior differs too: with Do Not Forward, unencrypted Office documents inherit the same restrictions. Choose Encrypt-Only for privacy in transit; choose Do Not Forward when you need to limit what the recipient can do.
How do I encrypt email with a Microsoft 365 Personal or Family subscription?
Compose a new message, select the Options ribbon, then select Encrypt. Subscribers get two choices: Encrypt, where your message "stays encrypted and doesn't leave Microsoft 365," and Do Not Forward, where your message "stays encrypted within Microsoft 365 and can't be copied or forwarded" (Microsoft's wording). A qualifying Microsoft 365 subscription is required; free outlook.com accounts have no Encrypt button and rely only on opportunistic TLS to encrypt the connection with the recipient's provider.
Is there a size limit on encrypted Outlook email?
Yes. The maximum message size you can send with Microsoft Purview Message Encryption, including attachments, is 25 MB (per Microsoft's documentation). That is a real constraint if you are trying to send a data-heavy file such as a financial model, a full board pack, or a CIM as an encrypted attachment. When a document is too large for the cap, or when you need visibility and control after it leaves your outbox, a tracked link to the file rather than an attachment is the more workable pattern.
Related resources
- How to send confidential documents via email (7 methods) — the full survey that ranks Outlook encryption against Gmail Confidential Mode, S/MIME, password-protected PDFs, and secure links by what each actually protects.
- How to encrypt email in Gmail — the sibling deep-dive for Google Workspace and personal Gmail: Confidential Mode, Client-Side Encryption, hosted S/MIME, and their limits.
- How to send a password-protected PDF — when the file, not the email, is what needs locking, and how to deliver the password safely.
- Screenshot protection — deter and log capture attempts on shared documents; the control email encryption lacks.
- Dynamic watermarks — stamp every viewer's identity across every page so a leak traces back to a person.
- Peony pricing — Free, Business ($30/admin/month), and Data Room ($52/admin/month) tiers, with expiry, revoke, and page analytics available from the free tier.
You might also like
Aug 20, 2026
How to Encrypt Email in Gmail (2026): What Actually Encrypts, What Doesn't, and What to Use Instead
Jul 17, 2026
How to Deliver Phase 1 ESA Reports: View-Only, Reliance Control (2026)
Jul 17, 2026
Stop Clients from Uploading Your Reports to ChatGPT (2026 Guide)

