How to Send Encrypted Email in Gmail (2026 Guide)
How to send an encrypted email in Gmail: confidential mode step by step, hosted S/MIME setup, and why Google says confidential mode is not actually encryption.
Last updated: July 2026
Gmail is one of the most widely used email platforms in the world, with over 1.5 billion active users sending emails through Gmail every month. Businesses, healthcare providers, and financial teams rely on Gmail daily to share sensitive information.
But standard Gmail messages aren’t always fully protected.
That’s why understanding how to send encrypted emails in Gmail is critical. Encrypting emails in Gmail helps protect sensitive data, prevents unauthorized access, and ensures confidential messages stay secure when sent through Gmail.
Updated May 2026 — how to send encrypted email in Gmail. Gmail supports confidential mode (link-based, with optional SMS passcode), S/MIME encryption (paid Workspace tiers), and end-to-end Client-Side Encryption (Workspace Enterprise Plus). For most knowledge workers, confidential mode is the simplest option; for healthcare orgs needing HIPAA-grade controls, Strac Gmail DLP adds the data-layer protection. See Strac Gmail DLP →
Gmail gives you three options, and they are not equally protective. Start here:
Recipients cannot forward, copy, print, or download the message or its attachments, and you can revoke access at any time before it expires.
The catch, in Google’s own words: confidential mode is not encryption. Google’s documentation states plainly that it “doesn’t prevent recipients from taking screenshots or photos of your messages or attachments.” It is a sharing control, not a cryptographic one — useful, but do not mistake it for protection of regulated data.
Hosted S/MIME is available on Frontline Plus, Enterprise Plus, and Education Fundamentals, Standard, and Plus editions. If you are on Business Starter or Standard, this option is not available to you — which is why so many teams end up relying on confidential mode and assuming it encrypts.
Tools like FlowCrypt (PGP), Virtru, and SendSafely add encryption on top of Gmail without an Enterprise Plus license. They work, but they add a plugin and a key-management burden, and recipients often need to do something on their end.
| Option | Actually encrypted? | Who can use it | Setup | Main limitation |
|---|---|---|---|---|
| TLS (default) | In transit only | Everyone, automatically | None | Only works if the receiving server also supports TLS |
| Confidential mode | No — Google says so explicitly | Any Gmail account | 30 seconds, per message | Screenshots defeat it; Google can still read the content |
| Hosted S/MIME | Yes | Frontline Plus, Enterprise Plus, Education editions | Admin setup + certificates | Both sides need S/MIME; not on Business tiers |
| Third-party (FlowCrypt, Virtru) | Yes | Any plan | Plugin + key management | Recipient friction; another tool to run |
| DLP (Strac) | Complements encryption | Any plan | Agentless, API-based | Stops the sensitive data going out at all — encryption does not |
The distinction the table makes is the one most teams miss: encryption protects a message from the wrong eyes; it does nothing about the wrong message. An SSN encrypted perfectly and sent to the wrong customer is still a breach. That gap is what Gmail DLP closes — detecting PII, PHI, and card data in the body and attachments and redacting it before the message leaves.
Email encryption is the process of transforming the content of an e-mail into a coded format that can only be read by the intended recipient. This is crucial for protecting sensitive information, such as personal data, financial details, and confidential communications, from unauthorized access.
Email encryption typically employs cryptographic techniques to ensure that even if an email is intercepted during transmission, its contents remain secure and unreadable to anyone without the appropriate decryption key.
Email encryption matters because it protects sensitive information from being accessed, stolen, or misused. As cyber threats get more advanced, encryption acts as a basic but critical layer of defense.
For businesses, it’s often not optional. Regulations like HIPAA and PCI DSS require you to protect customer and financial data; not doing so can lead to fines and serious reputational damage.
Encryption also ensures that emails aren’t altered in transit, so what’s sent is exactly what’s received; this is especially important for legal and financial communication.
Finally, it helps verify who the sender actually is, reducing the risk of phishing and email fraud.
By implementing email encryption, organizations can enhance their data security posture and demonstrate a commitment to protecting their clients’ and employees’ privacy.
There are two main types of email encryption protocols:
An email encryption solution is a software or service that automatically encrypts outgoing emails and decrypts incoming encrypted messages. These solutions typically use advanced encryption algorithms to scramble the content of emails, making them unreadable to anyone who doesn’t have the decryption key.
Organizations need email encryption solutions for several reasons:
Strac Email Outbound Agentless DLP Office365 and Gmail
By implementing a robust email encryption solution, organizations can greatly reduce the risk of data breaches & ensure the confidentiality of their communications.

Opening an encrypted email typically involves a few steps, which may vary depending on the encryption method used:
It’s important to note that the process of opening encrypted emails can be simplified with the use of integrated encryption solutions that work seamlessly with popular email clients.
Gmail employs several security measures to protect emails:

Third-Party Plugins: Users can enhance their email security with third-party tools like Flowcrypt or Mailvelope, which provide additional encryption options.
Gmail uses TLS to encrypt emails in transit. This leaves emails vulnerable to unauthorized access on reaching the destination server, especially if they linger in the recipient's inbox. You can encrypt emails using S/MIME, Confidential Mode, and other third-party plugins to protect sensitive information. Learn how to use these options to secure your email communications.
S/MIME, or Secure/Multipurpose Internet Mail Extensions, is a security protocol that encrypts emails using public key cryptography. When sending an S/MIME encrypted email, the sender encrypts it using the recipient's public key, ensuring only the recipient with the corresponding private key can decrypt it.
You can also use S/MIME to digitally sign emails, verify your identity, and ensure the email has not been tampered with. To digitally sign an email, the sender uses their private key to create a digital signature and attach it to the email. When the recipient receives the email, they can use the sender's public key to verify the digital signature. This can help prevent phishing attacks and other forms of fraud.
Supported editions for S/MIME in Google Workspace:
S/MIME offers robust security but has intricacies and dependencies that warrant careful consideration. Let's explore its pros and cons.
Confidential mode in Gmail is a feature that restricts the forwarding, copying, printing, or downloading of emails and their attachments. Senders can set message expiration dates, revoke access at any time, and require an SMS verification code to allow message access.
This mode is available for personal Gmail and Google Workspace (formerly G Suite) accounts.
Confidential mode doesn't prevent recipients from taking screenshots or utilizing malicious software to copy or download the email content.

5. Click "Save."
Confidential mode, while not an encryption method, adds an extra layer of security to your emails. Let’s look at its pros and cons:
Related: Learn what constitutes confidential data.
To send confidential emails in Gmail:
To open a confidential email:
Here's how you can verify email encryption:
.webp)
Follow the steps below to check whether you’ve received an encrypted email:
Regardless of whether you use email encryption, implementing security best practices is essential:
By following these guidelines and utilizing available encryption methods, you can significantly enhance your email security and protect your sensitive information from potential threats.
Strac’s Data Protection tools provide comprehensive control over email security, enabling you to:
✅ Automatically encrypt emails without leaving your email app.
✅ Intercept, block, or quarantine emails containing sensitive data in the body, subject, or attachments.
✅ Scan email attachments to detect and flag sensitive data before they’re sent.
✅ Remove sensitive attachments to prevent unauthorized sharing, even if the email itself is secure.
✅ Encrypt attachments to ensure they remain protected.
✅ Revoke email access at any time to maintain security.
✅ Block email forwarding to prevent unintended data exposure.
✅ Keep confidential emails private with seamless security controls.
With Strac, you can proactively protect sensitive email communication while ensuring compliance with HIPAA, PCI, SOC 2, and more. 🚀
Email encryption protects messages in transit, but it does not stop employees from copying email content or uploading attachments into tools like ChatGPT, Gemini, Claude, or Copilot.
This is becoming one of the biggest data security risks for modern organizations. Teams often download invoices, contracts, payroll files, support tickets, source code, or customer records from Gmail and paste them directly into AI tools to summarize or analyze them.
The problem is that S/MIME, TLS, and Confidential Mode do not prevent this type of exposure. Once a user can access the email, the data can still leave the organization through AI prompts, browser uploads, screenshots, or copied text.
That’s why many companies now combine Gmail encryption with Browser DLP and GenAI DLP controls. This helps security teams:
For organizations handling regulated or sensitive data, encryption alone is no longer enough. You also need visibility into where that data moves after the email is opened.
Besides Gmail’s native security features, third-party plugins can enhance your email security further.
Strac does encryption and also offer other remediation actions like Blocking, Quarantining, Redaction and Encryption.

For files that are too sensitive for email, Strac also offers Secure Share — a safer way to send documents without attachments.
✅ End-to-end encrypted before upload
✅ Passcodes, expiration dates, and download limits
✅ Full audit trail of file access
✅ Ideal for IDs, contracts, payroll, and customer files
Flowcrypt is a desktop extension available for Firefox and Chrome. It seamlessly integrates with Gmail and introduces a "Secure Compose" button to your interface. Flowcrypt secures your messages using industry-standard Pretty Good Privacy (PGP) encryption. Here's how to use Flowcrypt:



SendSafely is an end-to-end encryption platform that ensures only you and your intended recipients can access shared information. It eliminates the need for pre-shared encryption keys or passwords. Here are the steps to send encrypted emails using SendSafely:
.webp)
.webp)
Mailvelope is a Chrome extension offering PGP encryption for Gmail. It provides robust end-to-end encryption. However, it may require some technical knowledge to set up.
Here's how to use Mailvelope:
Related: How to share sensitive documents with end-to-end encryption?

While Gmail provides basic encryption for emails in transit, users often require additional security measures. Here are some secure sharing tools that can be used to encrypt emails in Gmail:
Sometimes, the safest way to send encrypted email in Gmail is not to send sensitive files as attachments at all. Strac Secure Share gives teams a safer option for sharing confidential documents outside of inboxes and SaaS apps.
When choosing a secure sharing tool, it’s essential to consider factors such as ease of use, compatibility with recipients’ systems, and the level of encryption provided. Organizations should also ensure that their chosen solution complies with relevant data protection regulations and integrates well with their existing data discovery and classification processes.
For businesses using AI-powered tools like ChatGPT, it’s crucial to implement DLP solutions that can protect sensitive information across various communication channels, including encrypted emails.
Strac’s Gmail DLP solution uses advanced algorithms to promptly detect and redact sensitive content in emails, protecting you from accidental data exposure.
When sending an email with sensitive content (in the body or attachment), you can choose from a variety of data protection measures, including:

Encrypting an email does not eliminate the risk of sensitive data exposure.
Once an email is opened, attachments can still be downloaded, copied, forwarded, uploaded into SaaS apps, or shared through collaboration tools like Slack, Google Drive, Jira, Zendesk, or ChatGPT.
This creates a major compliance challenge for organizations handling PII, PHI, PCI, financial records, or confidential customer data.
For example:
Encryption protects the email during delivery. It does not control what happens after access is granted.
That’s why modern security teams combine email encryption with SaaS DLP, Data Lineage DLP, and real-time remediation controls to continuously monitor where sensitive data moves across cloud apps, endpoints, and AI tools.
This approach helps organizations:
If you need to send encrypted email in gmail consistently and pass audits, use a simple model: CSE for external recipients, S/MIME for trusted partners, TLS for routine mail, and treat Confidential Mode as access control, not encryption. Build rules that nudge or require users to send encrypted email in gmail when sensitive data appears, and pair that with Strac Gmail DLP to detect and redact PII, PHI, PCI, secrets, and source code before anyone clicks Send. Outcome: fewer incidents, cleaner audits, and a repeatable way to send encrypted email in gmail without slowing work.
On Microsoft 365 instead? See the companion guide: how to encrypt email in Outlook & Office 365.
Use client-side encryption (CSE). In compose, tap the lock/shield icon and choose additional encryption, then send. It keeps message body and attachments encrypted, and non-Gmail recipients can view through a secure flow. Add a short policy so users know when to toggle it.
No. Confidential Mode limits forwarding, copy, print, and download, and can add passcodes, but it does not provide end-to-end encryption. For regulated content, send encrypted email in gmail with CSE or S/MIME.
Combine two controls:
Both. With CSE or S/MIME, attachments are encrypted along with the message. For high-risk files, pair with Strac to auto-redact sensitive fields inside PDFs, images, and spreadsheets before encryption.
.avif)
.avif)
.avif)
.avif)
.avif)


.gif)

