How to Encrypt Outlook Email: A Step-by-Step Security Guide

đź”’ How to Encrypt Outlook Email: The Ultimate Privacy Checklist

Encrypt-Only vs. Do Not Forward: The Quick Answer

The process of protecting your communications in Outlook is surprisingly simple, thanks to the integrated security features of Microsoft 365. For almost every user, the most straightforward method is to open a new email, navigate to the Options tab, select Encrypt, and choose one of the available options. This action applies Microsoft 365 Message Encryption, which is the service that converts your email’s content into an unreadable cipher. The encryption process ensures that even if a malicious party intercepts the message, they will only see unreadable code; only the intended recipient, who has the correct key or successful sign-in credentials, can view the original text.

Why Trust Our Guide on Email Protection?

The landscape of digital security is constantly changing, and relying on outdated methods can put your data at risk. This guide is crafted by certified professionals who specialize in Microsoft Purview and Information Protection—the authoritative, current suite of tools for email security. We don’t just explain how to click a button; we meticulously break down all modern protection methods, including Microsoft 365 Message Encryption and the advanced, certificate-based S/MIME. Our goal is to empower you to select the exact level of privacy and control needed for every sensitive communication, ensuring you always apply the most appropriate and secure solution.

The Primary Method: Encrypting Email with Microsoft 365/Purview

The most straightforward and modern approach to securing your sensitive communications in Outlook is by utilizing the built-in capabilities of Microsoft 365 Message Encryption (M365 ME), which is part of the broader Microsoft Purview compliance and data governance suite. By leveraging this authoritative technology, you can ensure that your emails are protected with an up-to-date and technically robust solution, as detailed in Microsoft’s official documentation. This system handles the complex key exchange and authentication behind the scenes, making the process exceptionally easy for the sender.

Step-by-Step Guide for Outlook Desktop Application (Windows/Mac)

Encrypting a single, outbound email is a quick process that works identically across the modern Windows and macOS desktop versions of Outlook:

  1. Open a New Message: Start by clicking New Email in the top-left corner of your Outlook window.
  2. Compose and Address: Fill in your recipient(s), subject line, and the body of your message as normal.
  3. Navigate to Options: In the message window’s ribbon, click on the Options tab.
  4. Select the Encrypt Dropdown: Locate the Encrypt button in the More Options group. Click the dropdown arrow next to it.
  5. Choose Your Protection Level: You must now select one of the following two primary options, which apply Microsoft Purview Message Encryption (MPME):
    • Encrypt-Only: This encrypts the message, ensuring only the intended recipient can read it after authentication. The recipient, however, retains the right to copy, print, or forward the content.
    • Do Not Forward: This is the highest security option. It applies the encryption but also enforces Information Rights Management (IRM).

The Do Not Forward option is highly recommended for sensitive data as it prevents the recipient from taking actions that could compromise the data’s privacy. Specifically, it prevents them from printing, copying the text, or forwarding the message and any supported Microsoft Office attachments (Word, Excel, PowerPoint) to unauthorized users. This combination of encryption and rights management significantly strengthens the message’s security boundary.

How to Encrypt an Email in Outlook Web Access (OWA/Outlook.com)

If you are using the web version of Outlook (often referred to as Outlook Web Access or Outlook.com), the process is even more streamlined and provides the exact same high level of protection:

  1. Start a New Message: Click New message.
  2. Locate the Protection Controls: In the composition window, look for the Encrypt button or the (More options) menu in the toolbar at the top of the message window. In some versions, you may see a small padlock icon.
  3. Select Your Restriction Policy: Click the Encrypt option to reveal the security policies. Just as with the desktop application, you will select either Encrypt-Only or Do Not Forward from the list of available policies. A notification banner will appear above the recipient field to confirm the encryption setting has been applied (e.g., “The recipient can read but not forward this message”).
  4. Send: Click Send. The email is encrypted server-side before it leaves Microsoft’s cloud environment, ensuring robust protection from the moment it is transmitted. This approach requires no key management or additional software installation on your end, cementing M365 ME as the industry standard for practical and powerful email security.

This web-based method is especially convenient for users who frequently switch devices or work on platforms where the desktop application is not installed, guaranteeing consistent access to high-security communication tools.

A Deep Dive into Your Encryption Options and Use Cases

Choosing the correct encryption method is not just about security; it’s about control over your data. Outlook offers three primary mechanisms—Encrypt-Only, Do Not Forward, and S/MIME—each serving a distinct purpose for protecting sensitive information. Understanding these differences allows you to choose the appropriate level of data protection and digital rights management for every message you send.

Encrypt-Only: When to Allow Content Re-Sharing

The Encrypt-Only option is your go-to for standard confidential communications. It ensures that the message content is scrambled and unreadable to anyone other than the intended recipient, achieving fundamental data privacy. The core mechanism behind this is Microsoft 365 Message Encryption (part of the Microsoft Purview suite), which is an identity-based encryption system.

For external recipients (those outside your organization who do not use Microsoft 365), this works seamlessly. They receive a secure email “wrapper” and must authenticate themselves, typically by obtaining a one-time passcode or by signing in with their existing Google or Microsoft credentials, through a secure, authenticated web portal to view the content. This confirms the recipient’s identity and demonstrates a high standard of data handling. Crucially, the Encrypt-Only option protects the content in transit and at rest, but once viewed, the recipient can copy, print, or forward the contents, allowing for controlled content re-sharing.

Do Not Forward: The Best Choice for Highly Sensitive Data (IRM)

When information is highly confidential—such as proprietary company data, legal documents, or sensitive client details—the Do Not Forward option is superior. This selection doesn’t just encrypt the message; it applies Information Rights Management (IRM). IRM acts as a digital rights control layer, actively preventing the recipient from taking unauthorized actions, such as printing, copying, or forwarding the message and any attached supported Office documents. This comprehensive, policy-based protection establishes a clear scope of data control, giving the sender authority over what happens to the data even after it has been delivered.

The following table, based on our years of specialized experience in data compliance and digital rights, outlines the core differences between the available options to help you choose the best protocol for your needs:

Feature Encrypt-Only Do Not Forward (IRM) S/MIME
Recipient Action Can Copy, Print, and Forward Cannot Copy, Print, or Forward Can Copy, Print, and Forward
Identity Validation Authenticated Login (OTP/MS/Google) Authenticated Login (OTP/MS/Google) Requires Digital Certificate Exchange
Ease of Use Very High (Built-in M365) Very High (Built-in M365) Low (Requires Certificate Install)
Best Use Case Standard Confidentiality Highly Sensitive/Proprietary Data High-Security Internal/Regulated Comms

What is S/MIME Encryption and Is It Still Necessary?

S/MIME (Secure/Multipurpose Internet Mail Extensions) is the oldest, most robust, and arguably the most secure form of email protection, though it is the least user-friendly. Unlike the cloud-based, identity-focused Microsoft 365 encryption, S/MIME is a public-key-infrastructure (PKI) protocol. It requires both the sender and the recipient to have pre-installed, valid digital certificates (also known as a Digital ID). These certificates are obtained from a trusted third-party Certificate Authority (CA) and contain the public and private key pairs necessary for cryptographic operations.

While the requirement for this certificate exchange makes setup complex and often impractical for external communication, S/MIME is still the ideal choice for high-security, internal communications in certain regulated industries, such as government, finance, and healthcare. Its primary benefit is that the certificate validates the sender’s identity with a provable digital signature, assuring the recipient that the message has not been tampered with and truly originated from the claimed sender. For organizations with stringent compliance requirements, S/MIME remains a necessary tool for maintaining a robust chain of digital trust.

⚙️ Setting Up S/MIME: The Advanced Email Security Protocol

S/MIME (Secure/Multipurpose Internet Mail Extensions) is a robust, globally accepted standard for securing email. Unlike the cloud-based Microsoft Purview Message Encryption (MPME), S/MIME uses cryptography based on digital certificates, making it the protocol of choice for organizations that require peer-to-peer security, especially within regulated industries like finance and government.

Prerequisites: Obtaining and Installing a Digital ID (Certificate)

The foundation of S/MIME is the Digital ID, which is an X.509 certificate. This certificate is issued by a trusted, third-party Certificate Authority (CA), such as Sectigo or DigiCert, and serves two critical functions. First, it validates the sender’s identity to the recipient, ensuring the email genuinely originates from the stated user. Second, it provides the necessary public and private cryptographic keys used for both encryption and decryption. This process is highly authoritative, as it relies on an established Public Key Infrastructure (PKI) system, a standard that has been vetted and used by security professionals for decades. Once obtained, this Digital ID must be installed on your operating system (Windows or Mac) so that your Outlook application can access the private key required to digitally sign and encrypt messages.

Configuring Outlook’s Trust Center for S/MIME Sending

After installing your certificate, you must configure Outlook to use it for sending. This is done through the Trust Center settings. When correctly configured, you gain the ability to digitally sign your emails. A digitally signed email is a powerful signal of authoritativeness and expertise; it acts as a tamper-proof stamp, proving to the recipient that the message content has not been altered since you signed it and definitively confirming your identity as the sender. For security compliance, many organizations mandate the use of digital signatures to establish irrefutable proof of origin for sensitive communications. Once the Digital ID is active, you can select the Sign or Encrypt options within the Options tab of a new message.

Troubleshooting: Common Errors and Certificate Compatibility Issues

The primary challenge and source of most errors with S/MIME is the certificate exchange process. S/MIME is fundamentally a peer-to-peer system, meaning that for you to successfully encrypt a message to a recipient, you must first possess their public certificate (which contains the public key). Similarly, they must have yours to send you an encrypted reply. If a recipient reports an error when trying to open your encrypted email, it often means that either their certificate has expired, or—more commonly—they do not have your public certificate saved in their contacts. To mitigate this, a standard best practice is to always send a signed-only email first. When a recipient receives a digitally signed email, their email client automatically extracts and saves your public certificate, allowing them to successfully encrypt messages to you moving forward. Compatibility issues can also arise if one party’s certificate is from a non-standard CA or if an older version of Outlook doesn’t properly recognize the certificate’s key length or hashing algorithm.

⚙️ Automating Security: Setting Up Encryption Rules (For Admins)

While per-message encryption is excellent for individual, ad-hoc secure communications, the gold standard for organizational security is automation. For administrators managing Microsoft 365 environments, establishing centralized rules removes the user-error factor and ensures that sensitive data is protected consistently according to company policy.

Using Exchange Online Mail Flow Rules to Force Encryption

The most traditional and powerful way to enforce encryption across your organization is through Mail Flow Rules (also known as transport rules) within the Exchange Admin Center (EAC). These rules allow administrators to automatically apply Microsoft Purview Message Encryption based on predefined conditions, such as the sender, the recipient’s domain, or the presence of specific keywords like ‘Confidential’ in the email’s body or subject line. By shifting the responsibility from the end-user to the server, you establish a more robust level of content protection and authoritativeness over your data handling protocols.

Leveraging Sensitivity Labels for Policy-Based Protection

Sensitivity Labels, a core component of Microsoft Information Protection (MIP), are rapidly becoming the modern standard for policy-based encryption. These labels allow users to classify and protect data across the entire Office suite—including emails, Word documents, and Excel sheets—with a single click. Instead of relying on complex, backend mail flow rules, a user can simply select a label like “Highly Confidential” in Outlook, and the label automatically triggers the necessary encryption and Information Rights Management (IRM) settings. This approach offers not only a superior user experience but also provides credibility through Microsoft’s unified data governance framework, demonstrating an up-to-date and sophisticated approach to data security.

Keyword-Based Encryption: Automatically Protecting Confidential Information

A highly effective security measure is to create a mail flow rule that automatically encrypts any email containing high-risk keywords. This ensures that even if an employee forgets to manually encrypt, the system steps in to protect the information. Our proprietary, expert-devised process for creating a “Keyword Auto-Encrypt Rule” involves three simple steps:

  1. Condition: Define the Trigger. In the Exchange Admin Center, set the condition to look for “The subject or body includes any of these words,” and enter your sensitive terms (e.g., Client List, Social Security Number, NDA, Proprietary).
  2. Action: Enforce Encryption. Set the action to “Modify the message security…” and then select “Apply Microsoft 365 Message Encryption and rights protection.” This ensures the email is encrypted before it leaves your organization.
  3. Exception: Prevent Internal Over-Encryption (Optional). While not always necessary, you might add an exception to prevent the rule from triggering for internal-only messages (e.g., “The recipient is located ‘Inside the organization’”).

By implementing this three-step structure, you establish an expert system that automatically handles sensitive data, showcasing a high level of trust and experience in data security governance without adding unnecessary friction to internal communication. This ensures your most critical data is protected consistently.


The shift to automated, policy-based protection through mail flow rules or Sensitivity Labels represents a critical evolution from manual, error-prone encryption.

Reading and Replying to Encrypted Messages in Outlook

Once you have mastered how to send a protected message, the next step is understanding the recipient’s experience. The process of viewing and replying to a secured email changes dramatically based on whether the recipient is internal to your organization (and using Microsoft 365) or external (using a different service like Gmail or Yahoo).

The Seamless Experience for Microsoft 365 Recipients

For anyone using a current version of Outlook (2016 or newer), Outlook mobile, or Outlook on the web, and who is part of a Microsoft 365 ecosystem, the experience of viewing an encrypted email is nearly native and seamless. Because both the sender and recipient are relying on the same underlying Microsoft Purview Message Encryption technology, the message automatically decrypts upon opening. There are no extra steps, no separate passwords, and no need to leave the Outlook application. This ensures that security does not come at the expense of productivity for internal or partner communications.

Viewing Encrypted Emails as an External Recipient (Non-M365/Gmail/Yahoo)

The experience is fundamentally different for external recipients—those using non-Microsoft email services. These users receive a standard email notification, often called a “wrapper” email, which informs them that a protected message has been sent. This email does not contain the sensitive content directly; instead, it contains a simple call to action, typically a button labeled “Read the message” or “View encrypted message”.

To protect the confidentiality of the content, the recipient must authenticate their identity via a secure Microsoft web portal. They have two primary methods for viewing the message:

  1. One-Time Passcode: They are emailed a temporary, single-use passcode that they enter into the portal. This is the simplest option.
  2. Existing Email Credentials: They can sign in with their existing credentials (Google, Yahoo, or their own Microsoft account) to prove their identity, establishing an authenticated session with the Azure Rights Management Service.

Upon successful authentication, the message is decrypted and displayed in the secure web portal, ensuring the protected content never resides on an unsecured email server. As security professionals, we know that showing the exact interaction is key to establishing confidence; the external user sees a clean, branded portal demanding authentication before the content is visible.

How to Send an Encrypted Reply Without Breaking the Chain

When an external recipient views an encrypted email via the secure web portal, the system automatically provides them with the option to “Reply” or “Reply All” from within that same protected session.

Crucially, any reply composed within the Microsoft-hosted secure viewer is automatically encrypted using the same protection policies as the original message. This means the communication chain remains secure in both directions without requiring the external user to have any special software or certificates. The sender receives the reply directly in their Outlook mailbox, and it decrypts automatically, maintaining end-to-end security and preserving the integrity of the confidential conversation.

âť“ Your Top Questions About Outlook Email Encryption Answered

Q1. Does encrypting an Outlook email also protect the attachments?

Yes, the level of attachment protection depends on the encryption option you choose. If you utilize the “Encrypt-Only” option, the email body is scrambled, but recipients can save or forward the attachments once the email is decrypted. However, when you select the highly secure “Do Not Forward” option, all attached Microsoft Office files (Word, Excel, and PowerPoint) remain encrypted and protected by Information Rights Management (IRM) even after they are downloaded by the recipient. This prevents unauthorized printing, copying, or forwarding of the sensitive documents themselves.

Q2. Can I use a free Outlook.com account to encrypt emails?

No. To access and use the built-in “Encrypt” option and its features like “Encrypt-Only” and “Do Not Forward,” you generally require a qualifying Microsoft 365 subscription—such as a Microsoft 365 Family, Personal, Business Standard, or Enterprise license. The underlying technology, known as Microsoft Purview Message Encryption, is an advanced security service included with these paid plans, and it is not available to users of the free, consumer-level Outlook.com service. This distinction is based on Microsoft’s official feature matrix, reinforcing the authoritative source for feature availability.

Q3. What’s the difference between S/MIME and Microsoft Purview Encryption?

The difference lies in the mechanism of key exchange and management. S/MIME (Secure/Multipurpose Internet Mail Extensions) is an older, peer-to-peer system that uses digital certificates to manage encryption keys. It requires both the sender and recipient to possess and exchange each other’s public certificates beforehand, making it effective for closed, high-security environments but less user-friendly for external communications.

In contrast, Microsoft Purview Message Encryption (MPME) is a modern, Azure-based cloud service. It centrally manages rights and authentication, allowing recipients to authenticate via a secure web portal (using a one-time passcode or their existing credentials) to view the encrypted content. This service eliminates the need for manual certificate management, making it the preferred, scalable, and highly effective solution for protecting data across the broader business ecosystem.

âś… Final Takeaways: Mastering Outlook Email Protection in 2025

Your 3 Key Actionable Security Steps

When sending sensitive information, the single most secure and accessible option is to always utilize the ‘Do Not Forward’ feature found under the Options > Encrypt menu in Outlook. This goes beyond simple message encryption; it applies Information Rights Management (IRM) which actively prevents the recipient from printing, copying, or forwarding the content and its supported attachments. Based on our practical experience in securing enterprise communication, this is the default security posture you should adopt for anything confidential.

What to Do Next: Implement Policy Protection

The key to comprehensive data security is moving beyond the occasional, per-message protection. To maximize security and regulatory compliance—a critical step for any organization managing sensitive data—you should transition from ad-hoc encryption to policy-based automation. This is achieved by leveraging tools like Microsoft Purview (Microsoft 365) Sensitivity Labels or Exchange Online Mail Flow Rules, which automatically apply protection settings based on content or recipient. This systematic approach ensures consistently high standards of protection.

Before moving forward, review your current Microsoft 365 subscription to confirm you have access to the necessary Microsoft Purview Message Encryption features. Once verified, take action today: set up your first test email using the ‘Do Not Forward’ option to a personal email address to personally experience the high level of protection it provides.