[mh_key_takeaways]
Encrypting a single email is one button click on paper. In practice, the button lives in a different menu on every client, appears only on certain plan tiers, and behaves differently on mobile than on desktop.
This guide covers how to encrypt an email step by step in Outlook, Gmail, Apple Mail, and the major mobile apps. Where a healthcare team needs a workflow that stays consistent across every device, a dedicated secure email service with a BAA in the base plan removes the per-client variation.
Each section includes the exact menu path, the license required, and the recipient experience. Skip to the client you use.
How to Encrypt an Email in Outlook Desktop
Outlook 365 on Windows and macOS uses the Encrypt button on the Options ribbon.
Compose a new message. On the ribbon, click Options. Click Encrypt. A dropdown offers Encrypt-Only, Do Not Forward, and any custom sensitivity labels the admin has published.
Add the recipient, subject, and message body. Attachments inherit the same protection as the message body. Click Send.
The Encrypt button requires Microsoft 365 Business Premium, E3, E5, A3, A5, or G3/G5. If the button is missing or grayed out, the tenant license does not include Purview Message Encryption.
Related guide: how to encrypt email in Outlook covers every version including classic 2016 and 2019.
How to Encrypt an Email in Outlook on the Web
Outlook on the web shows the Encrypt button in the same location across every device. It uses the same Purview Message Encryption as the desktop client.
Open outlook.office.com and sign in. Click New message. Click the Encrypt button in the compose toolbar, which appears next to the attachment paperclip.
Choose Encrypt-Only or Do Not Forward from the dropdown. Add the recipient and body. Click Send.
Outlook on the web is often the fastest path for staff who rotate between office and remote work. The interface stays consistent regardless of the device or operating system.
The license requirement matches the desktop client. Business Basic and Business Standard do not include the Encrypt button.

How to Encrypt an Email in Gmail on the Web
Gmail offers two encryption paths on the web interface. The choice depends on the Google Workspace plan.
Confidential Mode is available on every Gmail account. Click Compose. Click the lock and clock icon in the bottom toolbar. Set an expiration date from one day to five years. Add an optional SMS passcode.
Confidential Mode restricts forwarding, copying, and downloading. It does not encrypt the message end to end. Google can still read the content. HIPAA compliance requires additional configuration.
Hosted S/MIME is available only on Google Workspace Enterprise Plus. When active, a padlock icon appears next to the recipient. Green means encryption is available. Click the padlock to verify the encryption level.
The Google Confidential Mode documentation covers the setup steps.
How to Encrypt an Email in Apple Mail
Apple Mail on macOS and iOS supports S/MIME natively. Setup happens once per user through Keychain Access or a configuration profile.
Install an S/MIME certificate from a public CA or internal PKI. On macOS, double-click the .p12 file to import into Keychain. Restart Mail.
Compose a new message. When the recipient public key is in your contacts, a lock icon appears next to the subject line. Click the lock to toggle encryption on.
On iOS, the lock appears in the address field when composing to a recipient with a known public key. Tap it to enable encryption for that message.
Apple Mail encryption works only when both parties have S/MIME configured. Cross-provider encryption to Gmail requires the recipient to have hosted S/MIME on Enterprise Plus.
[mh_example]
How to Encrypt an Email on Mobile Apps
Mobile encryption support is limited on both major platforms. The interface differs from desktop.
Outlook mobile on iOS and Android supports Purview Message Encryption through a Protect option. Tap compose. Tap the three-dot menu or paperclip depending on version. Tap Protect. Choose the encryption level.
Gmail mobile supports Confidential Mode. Tap compose. Tap the three-dot menu. Tap Confidential Mode. Set expiration and optional passcode.
Neither mobile app supports S/MIME with the same interface as the desktop client as of 2026. Practices sending PHI from mobile devices often need a dedicated encrypted email service with a purpose-built mobile app.
Test each workflow on the actual device. Screenshots from vendor documentation often lag the current app version.

What the Recipient Sees When You Encrypt
The sender clicks Encrypt. The recipient sees a different experience depending on the method.
- Purview Message Encryption sends the external recipient a notification email with a portal link. They sign in with Microsoft, Google, or a one-time passcode.
- Gmail Confidential Mode sends a notification with a Google-hosted link. External recipients enter an SMS passcode if the sender enabled it.
- Gmail hosted S/MIME delivers directly to the recipient inbox provided they also have S/MIME configured.
- Apple Mail S/MIME opens directly in the recipient client when both sides are configured.
- A dedicated encrypted email service like Mailhippo delivers messages that open with one click, without portals or passcodes on the recipient side.
Recipient friction shows up as support call volume. Test each method with a real recipient sample before rolling out.
Encrypting the Subject Line and Metadata
Standard email encryption protects the message body and attachments. The subject line, sender, recipient, and timestamp travel in the message envelope and remain visible.
Microsoft Purview does not encrypt subject lines by default. Doing so would break inbox threading and search. Gmail Confidential Mode also leaves subjects visible.
Some dedicated encrypted email services encrypt subject lines for HIPAA compliance where PHI might appear in the subject. Others recommend keeping PHI out of the subject entirely.
Practical rule: use a neutral subject like Update from Practice Name and put PHI only in the encrypted body. This works with every encryption method.
Sender identity and recipient address remain visible regardless of method. Encryption does not hide who is talking to whom, only what they said.
[mh_protip]
Confirming an Email Was Encrypted After Sending
Encryption confirmation appears in the mail client interface. The signal varies by platform.
Outlook Sent Items shows a padlock icon in the message header for Purview-encrypted messages. Click the message and view Properties to confirm Rights Management protection.
Gmail Sent folder shows an information banner on Confidential Mode messages with the expiration date and access restrictions.
Apple Mail Sent folder shows a lock icon in the message list when S/MIME encryption was applied. Open the message and check the signature status.
If the confirmation icon is missing, the encryption may have failed. Common causes include missing recipient certificate for S/MIME, license issue, or fallback to unencrypted delivery when the recipient method is unavailable.
Automating Encryption Instead of Clicking Per Message
Manual encryption depends on staff remembering to click. Automatic rules take that decision out of the workflow.
Exchange Online mail flow rules trigger encryption based on subject keywords, sender group, recipient domain, or DLP content type. Google Workspace compliance rules do the same on Gmail.
Configuring rules is admin work. Once set, workforce members do not need to remember to click. Every message containing PHI or sensitive keywords gets encrypted automatically before delivery.
Related guides: encrypt an email covers manual and automated methods. Can I encrypt an email in Gmail covers Gmail-specific automation. How do you encrypt an email in Outlook covers the admin rule setup.
When a Dedicated Encryption Service Simplifies the Workflow
Every mail client covered above has its own click path, license requirement, and recipient friction. Staff who rotate between clients need to remember every variation.
Mailhippo is a HIPAA-compliant email service that works with existing Gmail and Outlook accounts, includes a business associate agreement in the base plan, and delivers encrypted email without a portal step on the recipient side.
The sender clicks Send in the familiar Gmail or Outlook interface. The service handles encryption behind the scenes. The recipient opens the message directly in their inbox with one click.
Practices running healthcare marketing sites pair encrypted email with a compliant patient-facing web presence. See healthcare marketing services for the site-side counterpart.
Match the tool to the workflow. Native buttons for staff on qualifying plans with dedicated IT. S/MIME for internal certificate-managed teams. A dedicated service for practices that want one-click send and one-click open across every device and recipient.
[mh_faqs]





