Skip to main content
A man smiles while using a laptop in his kitchen, beside a padlock and password icon representing email attachment encryption
11 min

How to Encrypt Email Attachments (Outlook, Gmail, & iOS)

You can encrypt email attachments by protecting the email that carries them. Here are the current steps for Outlook, Gmail, and Apple Mail on iPhone.

Most email services protect an attachment as part of the message, rather than asking you to encrypt each file separately.

The right method depends on your account, subscription, administrator settings, recipient, and the control you need after sending.

This guide explains how to use the built-in options in Outlook, Gmail, and iOS, including TLS, Microsoft Purview Message Encryption, Confidential Mode, and S/MIME.

It also covers when a purpose-built secure email workflow can help you add recipient checks, secure replies, access visibility, and future-access control.

 

Contents

 

What Is Email Encryption?

Email encryption protects message content by converting it into a form that unauthorised people should not be able to read.

Different methods protect different parts of the journey. TLS protects the connection between participating mail systems, while message-level services and S/MIME can keep the message protected beyond that connection.

How a recipient opens the message also varies. They may use a compatible email app, sign in through a secure browser experience, enter a passcode, or use a certificate and private key.

For sensitive attachments, choose the method that fits the recipient experience and the controls you need, not encryption terminology alone.

Use the steps below for your email setup.

How to Encrypt Email Attachments in Outlook

Outlook logo

Outlook can protect messages and attachments using Microsoft Purview Message Encryption or S/MIME, depending on the account, licence, client, and organisation settings.

  • Microsoft Purview Message Encryption lets eligible Microsoft 365 users apply options such as Encrypt and Do Not Forward.
  • S/MIME uses digital certificates and requires certificate setup for the sender and recipient.

Choose the route your organisation supports and that gives recipients a practical way to open the attachment.

Encrypting Email Attachments in New Outlook for Windows

New Outlook for Windows supports Microsoft Purview Message Encryption if you have a qualifying Microsoft 365 subscription and your administrator has enabled it.

To encrypt an email in New Outlook for Windows, follow these steps:

  1. Open Outlook and click on ‘New Email’ to compose a new message.
  2. In the email composition window, click on the ‘Options’ tab.
  3. Select ‘Encrypt’.
  4. Choose the option that fits the restrictions you need, such as ‘Encrypt’ or ‘Do Not Forward’. The options you see depend on your Microsoft 365 setup.
    How to encrypt email attachments in New Outlook
  5. Write your message and attach any documents.
  6. Click ‘Send’.
Note: Encrypt protects the message while allowing normal recipient actions such as forwarding. Do Not Forward adds usage restrictions to the message. Attachment behaviour can also vary by file type, recipient client, and your organisation’s configuration.

Encrypting Email Attachments in Classic Outlook for Windows (With a Qualifying Microsoft 365 Subscription)

To use Microsoft Purview Message Encryption, you must have a qualifying Microsoft 365 subscription.

Microsoft Purview Message Encryption also needs to be configured by your email administrator before you can use it.

To encrypt an email with Microsoft Purview Message Encryption, follow these steps:

  1. Open Outlook and click on ‘New Email’.
  2. Click on the ‘Options’ tab.
  3. Select ‘Encrypt’.
  4. Choose the option that has the restrictions you need, such as ‘Encrypt’ (sometimes described as Encrypt-Only) or ‘Do Not Forward’.
    Encrypt email attachments using Outlook encryption options
  5. Write your message and attach any documents.
  6. Click ‘Send’.
Note: In the Outlook apps, people typically apply encryption on a per-message basis. Some organisations also set up mail flow rules to encrypt certain emails automatically.
 

Encrypting Email Attachments in Classic Outlook for Windows (Using S/MIME)

If your organisation uses S/MIME, Classic Outlook can encrypt the message and its attachments with digital certificates.

Both sender and recipient need compatible email software and valid certificate setup. The sender also needs the recipient’s public certificate before sending an encrypted message.

Start by obtaining a digital ID, also known as a digital certificate, from your organisation or a trusted certificate authority and adding it to Outlook.

Adding an S/MIME Certificate to Outlook

To add a digital certificate to Outlook, follow these steps:

  1. In Outlook, select ‘File’ > ‘Options’ > ‘Trust Center’ > ‘Trust Center Settings’.
    Adding an S/MIME certificate to Outlook Step 1
  2. In the left pane, select ‘Email Security’.
  3. Under ‘Encrypted email’, choose ‘Settings’.
    Adding an S/MIME certificate to Outlook Step 3
  4. Under ‘Certificates and Algorithms’, select ‘Choose’ and then select your S/MIME certificate.
    Adding an S/MIME certificate to Outlook Step 4
  5. Select ‘OK’.

Encrypting a Single Message Using S/MIME in Outlook

To encrypt a single message using S/MIME, follow these steps:

  1. In an email message, select ‘Options’ > ‘Encrypt’.
  2. Choose ‘Encrypt with S/MIME’ (the exact wording may vary depending on your version of Outlook).
  3. Finish composing your email, then select ‘Send’.

Encrypting All Outgoing Messages Using S/MIME in Outlook

When you choose to encrypt all outgoing messages by default, you can write and send messages the same way as with any other email.

Outlook must have a valid public certificate for every recipient so that each person can decrypt the message with their corresponding private key.

To encrypt all outgoing messages with S/MIME, follow these steps:

  1. In Outlook, choose ‘File’ > ‘Options’ > ‘Trust Center’ > ‘Trust Center Settings’.
  2. On the ‘Email Security’ tab, under ‘Encrypted email’, select the ‘Encrypt contents and attachments for outgoing messages’ check box.
    Encrypting all outgoing messages using S/MIME in Outlook
  3. To change additional settings, such as choosing a specific certificate to use, select ‘Settings’.
  4. When you’re done selecting your settings, select ‘OK’ to save your changes.
Important: Microsoft Purview Message Encryption should not be applied to a message that is already signed or encrypted using S/MIME. To apply Purview encryption, you must first remove the S/MIME signature and encryption. The same applies to Purview-protected messages; do not sign or encrypt them using S/MIME.

Encrypting Email Attachments in Outlook.com

If you have a qualifying Microsoft 365 Personal or Family subscription, Outlook.com includes Encrypt and Do Not Forward options.

To encrypt emails and attachments from Outlook in your desktop browser, follow these steps:

  1. Go to Outlook.com and click ‘New Message’.
  2. Click on ‘Encrypt’ at the top of the email composition window.
  3. Choose either ‘Encrypt’ or ‘Do Not Forward’. If you choose ‘No Permission Set’, Outlook uses TLS to encrypt the connection but not the message’s contents.
  4. Write your message and attach any documents.
  5. Click ‘Send’.
Note: Microsoft documents different download behaviour by option, file type, and recipient client. With Encrypt, Outlook.com and Microsoft 365 recipients can download attachments without encryption in supported apps. With Do Not Forward, supported Microsoft Office files can remain protected after download, while files such as PDFs and images can be downloaded without encryption. Other recipients may use a temporary passcode and Microsoft’s encrypted-message portal.

How to Encrypt Email Attachments in Gmail

Gmail logo

Gmail uses TLS as standard when the receiving service supports it. It also offers Confidential Mode for Gmail accounts and S/MIME on supported Google Workspace editions.

  • Confidential Mode adds expiry, access-removal, and sharing controls for the message and attachments.
  • Hosted S/MIME adds certificate-based encryption when an eligible organisation has configured it.

The right choice depends on whether you need straightforward recipient controls or a managed certificate-based email setup.

Encrypting Email Attachments with a Free Gmail Account

For a standard Gmail account, TLS protects the message and attachment while they travel between supporting email services.

When you want an expiry date, the ability to remove access, or fewer built-in sharing options, you can use Confidential Mode.

Applying Confidential Mode in Gmail

Gmail Confidential Mode lets you set an expiry date for the message and attachments, remove access early, and optionally require a passcode.

It disables the usual forward, copy, print, and download options. Google notes that it cannot stop screenshots, photographs, or every other way information might be re-shared.

Follow these steps to apply Confidential Mode:

  1. Click the ‘Compose’ button on the left-hand side of the inbox.
    Applying Confidential Mode in Gmail Step 1
  2. Select the ‘lock icon’, found in the bottom right of the window.
    Applying Confidential Mode in Gmail Step 2
  3. Choose your desired expiry date and whether or not to set a passcode. If you choose ‘SMS passcode’, recipients will receive a passcode by text message.
  4. Press ‘Save’.
  5. Finish and send your email as normal.
Note: Confidential Mode is designed around access and sharing controls, rather than S/MIME certificate encryption. Use it when those controls meet your need, and consider a configured S/MIME or secure email workflow when you need a different recipient experience or stronger identity checks.

Encrypting Email Attachments with a Supported Google Workspace Account

Google offers hosted S/MIME on supported Workspace editions once an administrator has enabled and configured it.

Before users can send S/MIME-encrypted email, the organisation must add valid certificates and recipients must have compatible certificate setup.

Adding an S/MIME Certificate to Gmail

To add an S/MIME certificate to Gmail, follow these steps:

  1. Sign in to the ‘Google Admin console’.
  2. Click ‘Menu’ > ‘Apps’ > ‘Google Workspace’ > ‘Gmail’ > ‘User Settings’.
  3. Under ‘Organisations’ on the left-hand side, select the domain you want to configure for encryption.
  4. Check the box labelled ‘Enable S/MIME encryption for sending and receiving’ under S/MIME settings.
  5. Choose whether to let people upload their own certificates, or upload and manage root certificates yourself.
  6. Click ‘Save’.
Note: These steps can only be completed by an account administrator.

Encrypting a Message Using S/MIME in Gmail

Once your organisation has configured hosted S/MIME and the necessary recipient certificates are available, compose the message, add the attachment, and send it through Gmail.

To check the protection applied while composing, look for the message security or padlock indicator near the recipient details.

  • A ‘grey padlock’ typically means the message will be sent using TLS.
  • A ‘green padlock’ typically means it will be sent using S/MIME.
  • A ‘red padlock’ typically means the email will be sent without encryption.

Note: Icons, labels, and colours can vary depending on your account and settings.

How to Encrypt Email Attachments in iOS (Mail App)

iOS Mail logo

Apple Mail on iPhone supports S/MIME encryption for messages and their attachments.

According to Apple’s S/MIME guidance, you need a valid certificate for your email account and the recipient’s public certificate. Your organisation may provide the certificate for an Exchange account, or you can obtain one from a certificate authority.

Adding an S/MIME Certificate to iOS

After the certificate has been installed for the account, follow these steps. On current iOS versions, Mail settings begin under Settings > Apps > Mail; older versions may show Settings > Mail directly.

  1. Open ‘Settings’ on your device.
    Adding an S/MIME Certificate to iOS Step 1
  2. Open ‘Apps’ > ‘Mail’ > ‘Mail Accounts’. On older iOS versions, choose ‘Mail’ > ‘Accounts’.
    Mail account settings used to configure S/MIME on an older iOS version
  3. Select the account you want to send encrypted messages from, then open its account settings.
    Selecting an email account for S/MIME in iOS Mail
  4. Choose ‘Advanced’ > ‘Encrypt by Default’, then turn on ‘Encrypt by Default’.

Encrypting a Message Using S/MIME in iOS

Once your certificate is set up and Mail has the recipient’s public certificate, compose your message, attach the document, and send it as usual.

To toggle encryption for an email you’re composing, look for the padlock icon in the address field.

  • A ‘closed padlock’ means encryption is turned on for that email.
  • An ‘open padlock’ means encryption is turned off for that email.

Learn more about different types of email encryption.

Choosing the Right Email Attachment Protection

The built-in options in Outlook, Gmail, and iOS can be a good fit when they match your organisation’s setup and the way your recipients work.

For sensitive customer communications, the decision often goes beyond whether the attachment is encrypted. Teams may also need to check the recipient, receive information securely, see when access has happened, and respond after sending.

Mailock brings those steps together in a purpose-built secure email journey:

  • Choose a configured recipient check to add assurance before sensitive content is opened.
  • Invite secure replies so recipients can return information and documents through the protected journey.
  • Use Message Tracker to see when the protected message has been accessed and support timely follow-up.
  • Use Message Revoke to close future access when a message was misdirected, replaced, or should no longer be available.

Teams can protect individual emails through supported sending options, including Mailock for classic Outlook on Windows and the Mailock web app, while organisations can also automate higher-volume delivery through integrations.

Protect Sensitive Attachments From Outlook

See how Mailock adds recipient checks, secure replies, access visibility, and future-access control to familiar Outlook sending.

Explore Mailock for Outlook

This means Mailock can work alongside Microsoft 365 and established email workflows, adding a consistent secure customer journey where that is the operational requirement.

"Every email you send is a piece of your story. Make sure it’s one only your intended recipient should be able to read."

Paul Holland, Founder and CEO, Beyond Encryption (Mailock)

For a broader look at the available approaches, read What Is Secure Email?

 

FAQs

What Is Email Interception?

Email interception is unauthorised access to a message while it travels between systems. Encryption helps make intercepted content unreadable, although account, device, and recipient security still matter.

How Does Encryption Protect an Attachment?

In the methods covered here, the attachment is protected as part of the encrypted or access-controlled message. What happens after download depends on the service, protection option, file type, and recipient software.

Is Transport Layer Security (TLS) Enough?

TLS is valuable protection for connections between supporting mail systems. If you need the message to remain protected beyond transport, recipient authentication, usage restrictions, or post-send control, choose a message-level or secure delivery option that supports those needs.

What Is S/MIME?

S/MIME is a standard for encrypting and digitally signing email. It requires valid certificates, compatible software, and access to the recipient’s public certificate before an encrypted message can be sent.

What Is the Difference Between S/MIME and Microsoft Purview Message Encryption?

S/MIME relies on certificates and public-key exchange between users. Microsoft Purview Message Encryption is administered through Microsoft 365 and can combine encryption with identity, authorisation, and rights controls for internal and external recipients.

What Does Gmail Confidential Mode Do?

Confidential Mode can set an expiry date, remove access early, require a passcode, and disable usual sharing options for the message and attachments. It is an access-control experience rather than S/MIME certificate encryption, and it cannot prevent screenshots or every form of re-sharing.

When Should I Consider a Secure Email Service?

Consider a purpose-built service when the workflow needs more than in-transit encryption, such as configurable recipient checks, secure replies, access visibility, revocation of future access, or consistent individual and automated delivery.

 

References

Send S/MIME or Microsoft Purview Encrypted Emails in Outlook, Microsoft, 2026

Send Encrypted Messages With a Microsoft 365 Personal or Family Subscription, Microsoft, 2026

Learn How Gmail Encrypts Your Emails, Google, 2026

Send and Open Confidential Emails, Google, 2026

Turn On Hosted S/MIME for Message Encryption, Google, 2026

Use S/MIME to Send and Receive Encrypted Messages in the Mail App in iOS, Apple, 2023

Reviewed by

Sam Kendall, 16.07.26

This content is for general information only and is not legal advice.

 

Originally posted on 14 02 24
Last updated on July 28, 2026

Posted by:  Sabrina McClune

Sabrina McClune writes about cybersecurity, data protection, digital identity, and digital transformation for Beyond Encryption, helping regulated sectors understand complex technology and compliance topics with greater clarity.

Return to listing