Yes. Microsoft Outlook can send encrypted email, but the protection available depends on the account, Microsoft 365 subscription, organisation settings and Outlook client.
For most organisations, the relevant options are TLS for the connection between email services, Microsoft Purview Message Encryption for protected messages and rights controls, and S/MIME for certificate-based encryption and digital signatures.
The right choice depends on who will receive the email, how they should access it and what the sender may need to do after sending.
Does Outlook Encrypt Email?
Outlook supports encrypted email, but "Outlook encryption" is not one single feature. Outlook is the email client. Exchange Online and Microsoft Purview provide much of the service, policy and information-protection capability behind it.
It helps to separate three layers:
- TLS protects the connection used to move email between servers.
- Microsoft Purview Message Encryption protects the message and can apply rights-management controls.
- S/MIME protects and signs message content using certificates held by the sender and recipient.
These options can be used for different jobs, and organisations may use more than one.
1. TLS in Exchange Online
Exchange Online uses Transport Layer Security (TLS) to encrypt connections between Microsoft 365 email servers and to other mail systems that support it.
This protects data while it travels through the encrypted connection. It does not create a separate protected-message experience for the recipient, and it does not give the sender a control such as closing access after delivery.
For external email, Exchange Online normally attempts to use TLS. Microsoft describes this as opportunistic TLS: if the receiving organisation does not support TLS, delivery may continue without an encrypted SMTP connection unless the sender's organisation has configured a requirement for secure mail flow.
Administrators can use connectors and other controls when email to a trusted partner must use TLS. This is an email-service decision rather than a button an individual sender selects in Outlook.
2. Microsoft Purview Message Encryption
Microsoft Purview Message Encryption combines message encryption with identity, authorisation and rights-management policies. It is built on the Azure Rights Management service and is available through eligible Microsoft 365 and Office 365 subscriptions.
Depending on the organisation's configuration, senders may be able to choose options such as Encrypt-Only or Do Not Forward. Administrators can also apply protection through mail flow rules, sensitivity labels and rights-management templates.
The recipient experience depends on their account and email client:
- Recipients using supported Outlook experiences may be able to read and reply to the protected message directly in Outlook.
- Recipients using other email services can be directed to Microsoft's encrypted-message portal.
- Portal recipients may authenticate using an eligible account or a one-time passcode, depending on the route and configuration.
Microsoft Purview Message Encryption can therefore support sensitive email both inside and outside the organisation. Licensing, tenant configuration, labels, policies and recipient route all affect what is available.
For a fuller scenario comparison, see Microsoft 365 secure email vs Mailock.
3. S/MIME Encryption and Digital Signatures
S/MIME uses digital certificates to encrypt message content and provide digital signatures. The sender needs the recipient's public certificate to encrypt the message, while the recipient uses their private key to open it.
This model can work well where both sides have established certificate management, such as communication between known organisations or professional groups.
It is less straightforward for occasional customer communication because the sender and recipient must have compatible S/MIME certificates, applications and configuration in place.
Microsoft provides S/MIME support across current Outlook experiences, subject to setup and organisational policy. Follow Microsoft's current instructions rather than assuming the same steps apply to every Outlook version.
How to Send an Encrypted Email in Outlook
The exact controls vary between new Outlook, classic Outlook and Outlook on the web. In an eligible and configured Microsoft environment, the sender generally:
- Creates a new email.
- Opens the message's Options, Permissions or Encrypt controls.
- Selects the protection made available by the organisation, such as Encrypt-Only, Do Not Forward or S/MIME.
- Checks the recipients and attachments, then sends the message.
If the encryption control is missing, the account may not have a qualifying subscription, the feature may not be enabled, or the organisation may apply protection another way. Microsoft's guide to sending S/MIME or Purview encrypted email in Outlook provides the current steps by client.

Is Outlook Encryption Enough for Sensitive Customer Email?
It may be. The answer depends on the communication rather than a simple feature score.
A configured Microsoft 365 environment may be a good fit when recipients already use supported Microsoft experiences, the available access method provides suitable assurance and administrators can operate the required licences, policies and audit processes.
Other workflows need a more deliberate customer journey. For example, the sender may want to choose a recipient check, keep replies inside the protected exchange, see when the secure message is accessed and close future access if the document or circumstances change.
| Communication |
Route to consider |
Why |
| Internal Microsoft 365 email |
TLS, Purview policies or S/MIME |
The organisation controls the Microsoft environment and can align protection with its information policies. |
| Known external Microsoft recipient |
Purview Message Encryption |
The recipient may receive a native Outlook reading and reply experience. |
| Established certificate-based exchange |
S/MIME |
Both parties can use managed certificates for encryption and digital signatures. |
| Sensitive customer communication across varied email providers |
Evaluate the Microsoft recipient route and a specialist workflow such as Mailock |
The decision may depend on recipient checks, secure replies, sender visibility, post-send control and consistency across customer domains. |
Where Mailock Fits Alongside Outlook and Microsoft 365
Mailock gives teams a purpose-built way to protect sensitive external customer email while keeping the sender workflow familiar.
Depending on the deployment, teams can use Mailock from classic Outlook on Windows, through Microsoft 365 and Exchange Online integration, in Mailock Web or through API and automated-delivery workflows.
The connected Mailock journey helps teams:
- choose a recipient check suited to the sensitivity and customer context;
- keep customer replies protected without requiring the recipient to own a secure-email product;
- see when a protected message has been accessed through Message Tracker;
- close future access using Message Revoke when the message or circumstances change; and
- support individual and automated sending through different Mailock routes.
"The practical value for senders is being able to choose how a customer authenticates, keep the reply protected and retain direct control over the secure message after it leaves the outbox."
Adam Byford, COO, Beyond Encryption (Mailock)

Mailock gives the sender visibility and future-access controls within the protected customer-email workflow.
Mailock does not need to replace the wider Microsoft estate. Microsoft can continue to provide the mailbox, identity, transport and information-protection environment, while Mailock supports selected customer communications that benefit from its specialist workflow.
Questions to Ask Before Choosing Email Encryption
- Are recipients colleagues, known Microsoft users or external customers using many email providers?
- Does transport encryption meet the need, or should the message content carry protection and rights controls?
- What should the recipient complete before opening the protected message?
- Should recipients be able to reply securely?
- What activity does the sender need to see after sending?
- Should future access be closed if the email is misdirected or the document changes?
- Will people send messages individually, or will business systems generate them?
- Which Microsoft licences, Outlook clients and Mailock deployment options are available?
The answers help determine whether Microsoft alone fits the communication, Mailock adds useful workflow controls, or the two should play different roles.
FAQs
Does Outlook Encrypt Emails Automatically?
Exchange Online automatically uses TLS for connections within Microsoft 365 and attempts TLS for external delivery. Message-level protection through Purview or S/MIME requires the relevant licence, configuration and sender or policy action.
Can Outlook Encrypt Email to Gmail or Other Providers?
Yes. Microsoft Purview Message Encryption supports external recipients, including people using Gmail and other services. Depending on the recipient route, they may be directed to Microsoft's encrypted-message portal to authenticate, read and reply.
What Is the Difference between TLS and Purview Message Encryption?
TLS encrypts the network connection used to transport email. Purview Message Encryption protects the message and can apply identity, authorisation and rights-management policies.
Is S/MIME the Same as Microsoft Purview Message Encryption?
No. S/MIME uses certificates held by senders and recipients for message encryption and digital signatures. Purview Message Encryption is a Microsoft cloud service built on Azure Rights Management.
Does Mailock Replace Microsoft 365 Encryption?
Not necessarily. Mailock can work alongside Microsoft 365 as a specialist workflow for sensitive external customer email, while Microsoft continues to provide the broader mailbox, identity, transport and information-protection environment.
Does Mailock Work with Every Outlook Version?
The Mailock Outlook add-in is designed for supported classic Outlook for Windows environments. Mailock Web, Microsoft 365 integration, and enterprise or automated-delivery options support other parts of the secure-email workflow. Confirm current compatibility before deployment.
References
Encryption in Microsoft 365, Microsoft Learn, 2025
How Exchange Online uses TLS to secure email connections, Microsoft Learn
Microsoft Purview Message Encryption, Microsoft Learn
Message Encryption FAQ, Microsoft Learn
Advanced Message Encryption, Microsoft Learn, 2026
Send S/MIME or Microsoft Purview encrypted emails in Outlook, Microsoft Support
Open encrypted and protected messages, Microsoft Support
Reviewed by
Sam Kendall, 16.07.26
This content is for general information only and is not legal advice. Product features, licensing and service descriptions can change.