How to Send Encrypted Email in Gmail in 2026
Reviewed · Updated
Quick answer: A personal Gmail account can't send end-to-end encrypted email: every message uses TLS in transit, and confidential mode isn't encryption. Full encryption to any inbox needs Google Workspace Enterprise Plus with Assured Controls (checked 10/09/2026). For free, send a password-protected message from Proton Mail to the Gmail address.
- Every Gmail account already sends with TLS. Check the lock icon before you send anything sensitive.
- Confidential mode adds an expiry date and a passcode, but Google says recipients can still take screenshots. It isn't encryption.
- End-to-end encryption to any address takes Workspace Enterprise Plus with Assured Controls, priced through Google's sales team.
- Free way: a Proton Mail account and a password-protected message. The recipient opens it in a browser for up to 28 days.
What “encrypted” means in Gmail
Google’s help center describes three levels. All Gmail messages use TLS automatically, which Google marks with a gray lock and calls standard encryption. TLS protects the message on its way between providers, and Google says it works only if both providers use it. Once the message lands, each provider keeps its own copy, outside TLS.
The two stronger levels are only for work or school accounts. S/MIME, which Google calls enhanced encryption, shows a green lock. Client-side encryption (CSE) shows a blue shield, and Google says it never accesses the private keys or the decrypted content.
Step 1: Use what Gmail gives you for free
Check the lock before you send
On a computer or Android, open a new message and select Message security to see the level for each recipient. For mail you’ve received, open it and click Show details next to the recipient, then look at the “security” line.
A red open lock means the other provider doesn’t support TLS and the message goes unencrypted. Google’s advice is blunt: don’t send passwords or financial details that way. If you see it, use Step 3 instead.
Confidential mode: an expiry date, not encryption
Confidential mode is on every Gmail account and every Workspace edition. In a new message, click Toggle confidential mode at the bottom of the compose window. Set an expiry date, then pick No SMS passcode or SMS passcode and click Save. Recipients can’t forward, copy, print or download the message. You can cut access early from Sent with Remove access.
If the recipient isn’t on Gmail, they get an email with a link and a passcode. Google sends SMS passcodes to phone numbers in North America, South America, Europe, Australia, India, Korea and Japan.
That limit matters. Google’s admin help adds that people “might still use third-party applications to copy or download messages and attachments.” The EFF wrote in 2018 that confidential mode emails “are not end-to-end encrypted” and that Google can see their contents. Use it to keep a message from being forwarded, not to hide it.
At work or school: S/MIME and client-side encryption
If your employer or school runs Google Workspace, ask IT what’s turned on. Hosted S/MIME uses keys from you and your recipients, and Google hosts the keys. Both sides need S/MIME. On Google’s pricing page, S/MIME is listed only on the Enterprise plan, which has no public price, just Contact sales. With the annual option on, the three plans below it were $7, $14 and $22 per user per month on 10/09/2026, and none of them lists S/MIME.
Client-side encryption goes further: your organization holds the only key. Google lists four editions for it.
To use it, click Message security in a new message and turn on Additional encryption. Turn it on before you start writing, because Google says switching it on mid-draft deletes the draft. The subject line, recipients and timestamps stay outside the extra encryption.
Since 10/02/2025, CSE users can send end-to-end encrypted mail to people on any provider. Recipients outside Gmail read it in a restricted version of Gmail through a guest account. Mobile apps got it on 04/09/2026.
If the option isn’t there
- Personal @gmail.com account. There’s no S/MIME and no client-side encryption. You have TLS and confidential mode, and that’s all.
- Work account without the shield. Your edition may not include CSE, or your admin hasn’t turned it on. Google says the E2EE feature is off by default for admins and must be enabled.
- Gmail app on a phone. Confidential mode works there too. End-to-end encryption on Android and iOS needs the same Enterprise Plus license with Assured Controls, and an admin has to enable it.
Step 2: When Gmail’s encryption isn’t enough
TLS protects the trip, not the stored copy. It stops someone intercepting the message in transit. Google’s help page puts it this way for client-side encryption: “Not even Google can open your briefcase.” A personal account doesn’t have that option, and the recipient’s provider stores its own copy too.
The real fix is priced for big companies. Sending end-to-end encrypted mail to any address needs Enterprise Plus plus a paid add-on. On Hacker News, a user summed up the launch thread on 10/03/2025: “Only available for Google Workspace: Enterprise Plus with the Assured Controls add-on.”
Recipients need a Google guest account. Another commenter in the same thread noted that recipients “would be forced to create a guest account.” A third called it “a pastebin with a login.” Those are opinions, but they describe the same flow Google’s help page lays out.
Confidential mode is easy to misread. The passcode and the expiry date make it look like encryption. Google’s own warning says otherwise. In an r/ITManagers thread from 03/03/2026, a poster’s new director argued confidential mode was enough to send patient health data. The top-voted reply was “Absolutely not.”
Links in secure-mail notices look like phishing. In an r/sysadmin thread on Google’s E2EE (04/27/2026, 93 comments), the top reply called it “a workflow built entirely on clicking unexpected links.” That applies to any service that sends a link instead of the message, Proton included, so tell your recipient to expect it.
So for a one-off tax form, lease or medical letter from a personal Gmail, Gmail alone won’t encrypt it. You need a second tool.
Step 3: Send a password-protected email with Proton Mail
The simplest free option I found is Proton Mail. Its free plan includes password-protected emails to any address, Gmail included. Proton says these are end-to-end encrypted. You write in Proton, the Gmail user reads in a browser.
Create a free account
On 10/09/2026, Proton’s sign-up asked for a username, a password and the password again. No card and no phone number on this screen.
Then came an offer: Mail Plus for $1 for the first month, renewing at $4.99. No, thanks keeps you on the free plan.
Proton then checks you’re human, with a puzzle or a code sent to another email. The email code failed for our test address’s domain with “Email address verification temporarily disabled for this email domain,” so I solved the puzzle instead.
Create your free account on Proton’s site:
Create a free Proton Mail accountAffiliate link · how it works →
Set a password on the message
Write the email to the Gmail address as usual. Click the lock button in the composer’s bottom toolbar. In Encrypt message, enter a password and an optional hint, then click Set encryption.
A lock appears next to the recipient, with a banner showing the expiry date. Proton caps it at 28 days. Share the password by phone or text, not in another email, and mention that a notice from Proton is coming.
What the recipient sees
I sent the test from my new Proton account to a test inbox at another provider, not Gmail. It arrived within a minute as a notice from Proton. The notice showed my address, the expiry date, my hint in plain text and a link, with none of the message text. Keep the hint vague for that reason.
The link opened a Proton page that asked for the password.
After Read message, the email showed in the browser with Reply securely and an “Expires in 28 days” label. Proton allows up to five replies per message. When you answer their reply, Proton’s help page says encryption is off by default, so click the lock again.
Limits of the free plan
- Expiry. 28 days at most. After that, the recipient can’t open it.
- Size and volume. Attachments up to 25 MB, and 150 messages a day on the free plan (Proton pricing page, 10/09/2026).
- Storage. Our new free account showed 500 MB. Proton’s pricing page said 1 GB on the same day.
- Plain mail to Gmail. Without a password, Proton says mail to Gmail is protected by TLS only once it leaves Proton.
Mail Plus was $4.99 a month, or $47.88 billed every 12 months (10/09/2026).
If you’d rather use another service
- Tuta and Mailfence also send password-protected mail to people outside their own service.
- Proton is the one I ran end to end on 10/09/2026. I haven’t run Tuta or Mailfence, so there’s no score for them yet.
Which way fits your situation
| Option | Who can use it | Cost | How the recipient opens it | Who can read it besides the recipient |
|---|---|---|---|---|
| Gmail TLS (gray lock) | Every Gmail account | Free | In their inbox as usual | Not protected once stored by either provider |
| Confidential mode | Every Gmail account | Free | Link, optional SMS passcode | Google, per the EFF |
| Hosted S/MIME (green lock) | Workspace accounts where IT turned it on | Listed on Enterprise, price through sales | Needs S/MIME and your certificate | Google hosts the keys |
| Client-side encryption (blue shield) | Enterprise Plus, Education Plus or Standard, Frontline Plus | Price through sales; any address needs Assured Controls | Guest account in a restricted Gmail | Not Google, by Google’s help page |
| Proton Mail password-protected email | Anyone with a free Proton account | Free plan | Link plus a password you share | Anyone who has the password |
Is it worth paying? See what’s actually free
For an occasional sensitive email to a Gmail address, Proton’s free plan covered everything in my test. Pay only if you need more storage or Proton inside a desktop email app. More: what Proton Mail’s free plan includes · Proton Mail pricing · Proton Mail review · best secure email providers.
See also
- How to send secure email in Outlook
- Best secure email providers
- Password generator for the message password
What we checked
- Google's help center pages on Gmail encryption, encryption icons, confidential mode, client-side encryption and the Workspace admin page on confidential mode — read 10/09/2026
- Google Workspace Updates posts of 10/02/2025 and 04/09/2026, and the Workspace pricing page in US dollars — captured 10/09/2026
- We have no Workspace Enterprise account and no Gmail test account, so Gmail's own menus weren't tested by us; those steps follow Google's help pages
- Proton Mail: free account created 10/09/2026; a password-protected test message sent to a test inbox at another provider and read there in the browser
- Owners: Hacker News thread on Gmail's E2EE launch (81 comments, 10/03/2025) and a comment from 01/23/2026; Reddit threads in r/ITManagers (03/03/2026), r/sysadmin (04/27/2026, 93 comments) and r/degoogle (02/01/2026); EFF's 2018 analysis of confidential mode
- Where the run stopped: Gmail side from Google's help center and Workspace pages (no Workspace Enterprise account, no own Gmail test account); Proton Mail free account run end to end
FAQ
Are Gmail emails encrypted?
In transit, yes. Google's help center says all Gmail messages use TLS automatically, shown as a gray lock (checked 10/09/2026). TLS protects the trip between providers when both sides support it. It doesn't keep the message locked once it's stored. Google says only client-side encryption, on some Workspace plans, keeps the key away from Google.
Is Gmail confidential mode encrypted?
Not end to end. Confidential mode adds an expiry date, a passcode and blocks forwarding or printing. Google's help page warns that recipients can still take screenshots or photos. The EFF wrote in 2018 that confidential mode emails are not end-to-end encrypted and that Google can see their contents.
Can I send an end-to-end encrypted email from a free Gmail account?
Not with Gmail's own tools. On 10/09/2026, Google listed client-side encryption only for Workspace Enterprise Plus, Education Plus, Education Standard and Frontline Plus. Sending it to people on any provider needs Enterprise Plus with the Assured Controls add-on. A free Proton Mail account can send a password-protected email to a Gmail address instead.
What does the red lock in Gmail mean?
Google says a red open lock means the message is unencrypted, because the other provider doesn't support TLS. Don't send passwords or financial details to that address. Google adds that you may see a warning even when the email is encrypted, for example when you send from a custom domain.
How does a Gmail user open a Proton password-protected email?
They get a notice email with a link, the expiry date and your password hint. The link opens a Proton page in the browser, where they type the password you sent another way. They can reply securely from that page, up to five times per message, by Proton's help page.
Can I send encrypted attachments from Gmail?
Confidential mode applies its limits to attachments too, but it isn't encryption. Client-side encryption covers the body, inline images and attachments, on eligible Workspace plans. With Proton's password-protected email, attachments go inside the encrypted message, up to 25 MB on every plan.