What Is Email Encryption | Microsoft Security (2024)

Email encryption masks the contents of your messages to prevent bad actors from intercepting sensitive data.

Discover Microsoft Purview Information Protection

What Is Email Encryption | Microsoft Security (1)

Email encryption defined

Email encryption is a security measure that encodes an email message so that only the intended recipients can read it. Encrypting, or obscuring, emails is a process designed to keep cybercriminals—especially identity thieves—from getting hold of valuable information that they can use for monetary gain.

It's common to use email to send sensitive or confidential information that could be exploited by thieves. When an email is in transit to your recipient, it can be intercepted by malicious actors looking for data such as:

  • Names, addresses, and other personally identifiable information (PII).
  • Financial account numbers and other data.
  • Customer or employee information.
  • Login credentials.
  • Legal contracts.
  • Intellectual property.
  • Patient health information.

Using encryption for email security ensures that only the authorized recipient can decode and consume messages containing sensitive information. If a bad actor were to intercept an encrypted message, they would open it only to find scrambled, unreadable text inside. Email encryption is an important way to protect your data because gaining access to confidential information through email is a primary tactic of cybercriminals.

How email encryption works

Basic email encryption involves an exchange of encryption keys that are generated by mathematical algorithms called one-way functions. Each encoded communication uses a paired public key, available to anyone on the internet, and a private key, known only to the recipient. This kind of email encryption system is called public key infrastructure, or PKI.

In a PKI model, an encrypted email’s journey typically works like this:

  • A message is sent using a public key, which transforms the contents from a readable format, or plaintext, into a scrambled format, or ciphertext.
  • The message remains in cyphertext while it’s in transit from server to server over the internet.
  • When the email gets to its destination, the intended recipient decrypts the ciphertext email back into plaintext using a unique private key.

The recipient’s machine will use the private key to decrypt the message unless the recipient has an enterprise-grade email encryption service. In that case, a central server may decrypt the message on behalf of the recipient after validating their identity.

Email encryption by itself doesn’t prevent malicious parties from intercepting messages. Without the private key, however, the data inside will appear jumbled and unreadable to the unauthorized person.

It’s possible to have multiple layers of encryption in place at the same time. For example, encrypting the communication channels through which your email flows will provide even better protection than email encryption alone.

The benefits of using email encryption

Email is such a common way to communicate that it’s easy to forget how incredibly vulnerable it is. Hackers who surveil or steal PII from your email traffic can not only gain access to information related to your business and employees, but to customer data as well.

Email encryption services can block a significant avenue of attack for cybercriminals and protect the privacy of those who have entrusted you with their sensitive information. Avoiding security breaches and building customer trust protects both your bottom line and your reputation.

Using email encryption will also keep you compliant with legal and industry regulations. Compliance guidelines vary based on where in the world your business operates. But no matter what industry you are in or where you do business, you’re likely to handle a combination of PII, financial data, transaction data, or even sensitive patient health information that is regulated. Protecting this data is the law in many countries based on applicable privacy regulations. And many compliance guidelines strictly require that emails containing sensitive data are encrypted.

Another way email encryption can protect you is that it helps employees identify which emails are genuine and which are phishing or spam schemes. An email encryption service that includes digital signing gives an extra layer of proof that an email comes from an authentic sender, lessening the risk that your system is infected through routine employee communications.

Types of email encryption

There are several different protocols email encryption services can use to protect sensitive information in transit.

What Is Email Encryption | Microsoft Security (2)

Pretty Good Privacy (PGP)

PGP has been around since the 1990s and was the first free encryption software available. It uses both asymmetric cryptography, or public/private key pairs, and symmetric cryptography, in which the same key is used for both encryption and decryption. It also uses hashing and data compression to achieve a level of encryption that is more secure than its “pretty good” name might suggest. Its main drawback is that it isn’t always easy to use.

What Is Email Encryption | Microsoft Security (3)

Secure Sockets Layer (SSL)

SSL is an encryption protocol first developed in 1995. It’s the predecessor of the modern Transport Layer Security (TLS) encryption used today. SSL initiates an authentication process called a handshake between two communicating devices to ensure their identities. SSL also digitally signs data to provide data integrity, verifying that it has not been tampered with in transit. There were several iterations of SSL over the years before it was updated to become TLS.

What Is Email Encryption | Microsoft Security (4)

Transport Layer Security

TLS is a widely adopted security protocol for email encryption. It was initially proposed by the Internet Engineering Task Force, an international standards organization. Built on SSL, it’s an updated version that protects more thoroughly against eavesdropping, tampering, and message forgery. Some TLS-based encryption services include STARTTLS, a command issued between an email program and a server that encrypts emails in transit and decrypts them on arrival, which means the recipient doesn’t need to take any special action to read the message.

What Is Email Encryption | Microsoft Security (5)

Advanced Encryption Standard (AES)

AES is a symmetric encryption protocol that the U.S. and other governments use to safeguard classified information. It’s also the encryption method of choice for financial institutions. Its cyphers rely on exceptionally long keys, making them difficult to hack. AES is complicated to use but the right email encryption service can do most of the work for you. It’s one of the world’s most frequently used free, open-source encryption software.

What Is Email Encryption | Microsoft Security (6)

Secure/Multipurpose Internet Mail Extensions

Secure/Multipurpose Internet Mail Extensions (S/MIME) is a certificate-based encryption solution that allows you to both encrypt and digitally sign a message. To use S/MIME, you must have public keys on file for each recipient. Recipients have to maintain their own private keys, which must remain secure. If a recipient's private keys are compromised, the recipient needs to get a new private key and redistribute public keys to all potential senders.

Choosing an email encryption service

When you choose an email encryption service, consider your broader cybersecurity needs, the compliance requirements in your industry, and the size of your organization. Your employees may only deal with sensitive information a few times a day—or perhaps all your emails are highly sensitive and subject to complex regulations.

First, look at the available features within the email platforms you already use. You may have a certain level of encryption available by default, and it may only take a modest subscription upgrade or a plug-in to meet or exceed your privacy requirements. Building on tools that are already familiar to your employees has the advantage of reducing your training needs.

Second, consider ease of use. Try to find a cost-effective way to encrypt emails that doesn’t involve having employees logging in to a portal to read encrypted messages or follow complicated steps to attach files to an email.

Last, consider the size of your company. Larger organizations are best served by an enterprise-level encryption solution that provides end-to-end email protection. Enterprise-grade communication, collaboration, and security platforms sometimes have advanced message encryption included. These types of solutions can automate much of the encryption process for admins and users alike.

Some enterprise-grade solutions can fortify your email security posture by automatically encrypting sensitive emails. They may also send and request digital signatures to thoroughly verify identity or offer users advanced options such as prohibiting the forwarding, printing, or copy/pasting of emails.

Protect against email threats

Choosing an email encryption service is an important way to improve your overall security posture. Start by reviewing the types of email encryption available to you, the security needs of your organization, and what email protections can integrate with the platforms and solutions you already use. Consider how your needs can be met by:

  • The features available in your current productivity suite, such as Microsoft purview message encryption.
  • The email protections available in a comprehensive threat protection solution such as Microsoft Defender.
  • Advanced message encryption included in an enterprise solution such as Microsoft 365 Enterprise E5.

Learn more about Microsoft Security

Understand email threats

Read about cyberattacks that target email—and how to stop them.

Learn more

Strengthen password protection

Find out about password spray attacks and strategies to avoid them.

Learn more

Shield against email breaches

Learn email best practices to protect against business email compromise and phishing attacks.

Read the blog

Microsoft Purview Message Encryption

Explore the email encryption capabilities already included in Microsoft 365.

Learn more

Frequently asked questions

|

  • Email encryption is used to encode messages containing sensitive information so it can’t be intercepted by malicious actors. An encrypted email will appear scrambled and undecipherable to anyone other than the intended recipient.

  • Emails are not protected by encryption unless you have an email encryption service and deliberately use it. Your email provider might furnish some level of protection, and some productivity solutions have encryption capabilities built in.

  • Hacking encrypted emails is extremely difficult and time consuming, requiring advanced expertise on the part of the hacker. Certain email encryption protocols make it virtually impossible. Encrypting dramatically reduces the likelihood that a hacker will try to access information from your emails.

  • Email encryption with AES or S/MIME are both exceptionally safe. The safest practice is to encrypt data both in transit and at rest—that is, when it’s stored on your email platform—and to encrypt the connection itself.

  • Encryption gives a very high level of protection against hackers. Email encryption ensures that hackers who intercept a message will be forced to spend a great deal of time to glean any information other than the sender, the recipient, and the send time—making it likely they will give up and turn their attention to an easier target.

Follow Microsoft Security

What Is Email Encryption | Microsoft Security (2024)

FAQs

What Is Email Encryption | Microsoft Security? ›

When you need to protect the privacy of an email message, encrypt it. Encrypting an email message in Outlook means it's converted from readable plain text into scrambled cipher text.

What does email encryption do? ›

Email encryption is an authentication process that prevents messages from being read by an unintended or unauthorized individual. It scrambles the original sent message and converts it into an unreadable or undecipherable format . Email encryption is necessary when sharing sensitive information via email.

What happens if you don't encrypt email? ›

When an email is not encrypted, its contents are transmitted as plain, readable text. This leaves the information vulnerable to interception by malicious actors, such as hackers or even your internet service provider.

What does it mean recipient can't remove encryption? ›

Encrypt-Only – The message is encrypted in transit and at rest in the recipient's mailbox, including any attachments. Recipients cannot remove the encryption, so forwards and replies to the message remain encrypted.

Should my emails be encrypted? ›

Encryption in transit helps protect your emails from being snooped on while they travel between you and your intended recipients.

Are my emails automatically encrypted? ›

First of all, the Gmail server is automatically protected by network-level encryption. This layer of encryption protects your emails within Google's network or while they're in transit from sender to recipient. However, once your email leaves Google's network, it is no longer protected.

How do I know if my email is encrypted? ›

Check if your message is encrypted

At the top left, click Compose. In the "To," "Cc," or "Bcc" field, enter your recipient's email address. To the right of your recipient, hover over Message security : Message security: standard encryption: The message is encrypted with TLS.

Can an encrypted email be hacked? ›

Email encryption by itself doesn't prevent malicious parties from intercepting messages. Without the private key, however, the data inside will appear jumbled and unreadable to the unauthorized person.

What are the negatives of encryption? ›

While encryption can be an important tool to keep data secure, it also comes with a few cons. The primary downside of data encryption is cost. Encryption requires advanced hardware and software to be implemented, and this can be expensive.

Why would someone send me an encrypted email? ›

Encryption is a digital process that shields information from non-intended parties. In the case of email, it scrambles the details in the message to prevent scammers from accessing the data as it travels from the sender to the recipient — and all the servers in-between.

Can the recipient open an encrypted email? ›

Web portal encryption is the most common delivery method for encrypted emails. Encrypted emails are delivered via a secure webpage. Users can send an encrypted email directly from their email client, then the recipient has to sign in to view the encrypted messages.

How can I turn off encryption? ›

  1. Type and search [Device encryption settings] in the Windows search bar①, then click [Open]②.
  2. On the Device encryption field, set the option to [Off]③.
  3. Confirm whether you need to turn off device encryption, select [Turn off] to disable the device encryption function④.
Oct 24, 2023

How do I turn off email encryption? ›

Open Outlook and navigate to the File button. Select Info then moves to the Properties option. After executing the above step, you can view Encrypt message contents and attachments option. Uncheck this option and close the Properties dialog box.

How do I make sure my email is secure? ›

Email privacy and security start when you first create the email account.
  1. Use Non-Identifying Information. ...
  2. Use a Password No One Else Knows. ...
  3. Use Two-Step Verification. ...
  4. Review Security Notifications. ...
  5. Use Secure Devices. ...
  6. Always Log Out. ...
  7. Don't Allow Your Browser or Mobile Phone to Remember Your Email Account or Passwords.

Is it bad if an email is not encrypted? ›

If an email is sent without encryption and accidentally sent to the wrong recipient, an unauthorised individual may read the content. For this reason, such a mistake constitutes a data breach. Threat actors may also intercept email communications or enter email accounts illegally.

What does an encrypted email look like? ›

Encrypted emails look like gibberish to any unauthorized person who tries to read them. Email encryption means that both the sender and receiver have a key (digital code) so that the email is encrypted when sent and then decrypted when opened by the intended recipient.

What is the point of encrypted messages? ›

Encrypted text messaging is a method of secure communication that converts your messages into code. This means that only the recipient with the correct decryption key can read it. It's a way to keep your conversations private from prying eyes, whether they're hackers, advertisers, or even government agencies.

Can encrypted emails be hacked? ›

Email encryption by itself doesn't prevent malicious parties from intercepting messages. Without the private key, however, the data inside will appear jumbled and unreadable to the unauthorized person.

What is the difference between secure email and encrypted email? ›

It ensures that the information within the email is encoded and can only be deciphered by the intended recipient. Secure email on the other hand encompasses a broader range of security measures beyond encryption, and includes additional features, and protective measures to safeguard against various email-based threats.

Top Articles
Steam Support :: CS2 - I've been game banned
What Is an Importer of Record (IOR)? | Definition & FAQs | TecEx
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Selly Medaline
Latest Posts
Article information

Author: Kimberely Baumbach CPA

Last Updated:

Views: 5656

Rating: 4 / 5 (41 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Kimberely Baumbach CPA

Birthday: 1996-01-14

Address: 8381 Boyce Course, Imeldachester, ND 74681

Phone: +3571286597580

Job: Product Banking Analyst

Hobby: Cosplaying, Inline skating, Amateur radio, Baton twirling, Mountaineering, Flying, Archery

Introduction: My name is Kimberely Baumbach CPA, I am a gorgeous, bright, charming, encouraging, zealous, lively, good person who loves writing and wants to share my knowledge and understanding with you.