How to Remove Encryption From Outlook Email in 2026

📅 July 27, 2026 ✍️ By Chris Almond ⏱️ 9 min read
how to remove encryption from outlook email guide featured image

🔑 Key Takeaways

  • Outlook encrypts at three layers: Purview tenant policy, S/MIME per message, and IRM labels.
  • Received encrypted mail cannot be un-encrypted; reply, forward, or copy into a fresh message.
  • Admins disable encryption via Exchange mail flow rules; test one mailbox for 30 minutes first.
  • Toggle S/MIME off in the Options ribbon on desktop or the three-dot menu on Outlook web.
  • Keep encryption on for PHI mail; use Mailhippo per-message rather than stripping tenant policy.

Removing encryption from an Outlook email sounds like a one-click task. In practice the steps depend on which layer of the Microsoft encryption stack applied the encryption in the first place.

Outlook uses three separate encryption layers. Microsoft Purview Message Encryption at the tenant policy layer, S/MIME at the per-message certificate layer, and Information Rights Management at the sensitivity label layer. Each layer has its own removal path. Users trying to manage encrypted email across a mixed environment need to know all three.

This guide walks through removing encryption from an outbound message before you send it, from a received message so you can reuse the content, and from tenant policy when an admin needs to shut off automatic encryption on a specific rule.

Identifying which Outlook encryption layer applied to a message

Open the message. Click the ellipsis or three-dot menu. Choose Message Options or Properties, depending on the Outlook version.

The Properties dialog shows the message class. rpmsg indicates Purview Message Encryption. IPM.Note.SMIME indicates S/MIME. The Sensitivity field shows any active IRM label. This one dialog answers most encryption-source questions in under a minute.

Once you know the layer, you know the removal path. Purview Message Encryption removes at the Encrypt button on the Options ribbon or through a tenant mail flow rule change. S/MIME removes through the Encryption toggle in the Options ribbon. IRM labels remove through the Sensitivity dropdown near the message subject line.

Users who skip the identification step end up clicking every toggle they can find. The wrong toggle often does nothing because it addresses a different layer than the one applying encryption.

Removing encryption from an outbound Outlook message on desktop

Compose the message as usual. Go to the Options ribbon at the top of the composer window. The Encrypt button lives in the Permission group near the middle of the ribbon.

Click the Encrypt button. If encryption was on, the button toggles off and the shield icon disappears from the composer. If the button opens a dropdown, choose No Encryption at the top of the list.

Send the message. The recipient receives the message without any portal link or password step. Verify by checking the sent copy in the Sent Items folder and reviewing the message class in Properties.

If the Encrypt button is grayed out, a tenant mail flow rule is enforcing encryption based on recipient domain, subject line keyword, or content pattern. The user cannot override the rule. Contact the tenant admin or route the message through how to encrypt email from outlook alternative flows if a genuine business need exists.

how to remove encryption from outlook email in article illustration one

Removing encryption from an outbound Outlook message on web

Outlook web uses a slightly different navigation. Compose the message. Click the three-dot menu at the top of the composer, next to the Send button.

Choose Encrypt from the dropdown. A submenu opens with encryption options. Select No Encryption or click the current option again to toggle it off.

Outlook web shows a lock icon at the top of the composer when encryption is active. The icon disappears after you toggle encryption off. Send the message when the icon is gone.

Outlook web hides some encryption options behind the plan tier. Business Basic users see fewer options than Business Premium users. Enterprise E5 users see the most options because Purview features are all included. Reference the current option matrix at Microsoft Learn Purview Message Encryption.

Removing encryption from an outbound Outlook message on mobile

The Outlook mobile app on iOS and Android places the encryption toggle inside the ellipsis menu of the composer. Tap the ellipsis to open the extended menu.

Tap Encrypt Message. A screen appears with the current encryption setting. Choose No Encryption and tap the back arrow to return to the composer.

The lock icon in the composer header disappears when encryption is off. Send the message from the mobile composer. The recipient receives an unencrypted message that opens in any mail client.

Users on personal iPhones sending occasional PHI often struggle with the mobile encryption workflow. A dedicated app like how to encrypt email from iphone guide setups or a service like Mailhippo simplifies the mobile case without requiring native Outlook encryption at all.

Example

A cardiology clinic in Denver needed to move 40 archived referral letters from Outlook into a new EHR that could not decrypt Purview-protected messages. The office manager opened each message, confirmed the message class showed rpmsg in Properties, then copied the decrypted body text into fresh unencrypted messages sent to a dedicated import mailbox. Attachments required a second pass because Outlook kept them encrypted even when the body decrypted. The full migration took six hours across two days, with every step logged in the tenant change ticket.

Removing encryption from a received Outlook message

You cannot un-encrypt a message the sender encrypted. Outlook decrypts the message for display, but the encrypted copy stays in the mailbox database.

The workaround is to reply or forward without encryption when the sender policy allows. Open the message. Click Reply or Forward. Check the composer for the encryption toggle and turn it off if it appears.

Some sender policies apply Do Not Forward or block copy and paste at the label level. In that case the received message cannot be extracted at all. Reach out to the sender and ask them to resend without the restrictive label.

For content you need to move to another system, select all text in the decrypted view, copy, and paste into a fresh unencrypted message. Attachments require a separate step because Outlook often keeps attachments encrypted even when the body decrypts.

Removing encryption from Office 365 mail flow rules as an admin

Sign in to the Exchange admin center at admin.exchange.microsoft.com. Open Mail Flow, then Rules.

Review each rule in the list. Rules that apply encryption usually have Apply Office 365 Message Encryption or Apply RMS Template in the action list. Note the rule name and business owner before making any change.

To disable a rule, toggle the Enabled switch to off. To delete a rule, use the three-dot menu and choose Delete. Test the change on a pilot mailbox first. Send five test messages that would have matched the rule and confirm they arrive without encryption.

Common admin steps:

  • Document the business reason for removing the rule
  • Notify the privacy officer if the rule protected PHI
  • Set a change ticket in the tenant change log
  • Wait 30 minutes after disabling before testing
  • Keep an export of the rule XML for rollback
how to remove encryption from outlook email in article illustration two

Removing encryption from an Office 365 sensitivity label

Sensitivity labels in Microsoft Purview apply encryption at the label level. A message tagged with a Confidential label carries encryption for the life of the message.

To remove encryption from a specific label, sign in to purview.microsoft.com. Open Information Protection, then Labels. Select the label. Click Edit Label.

In the encryption settings step, choose None. Save the change. New messages tagged with the label send without encryption. Existing messages already sent with the label keep their encryption because the metadata was baked in at send time.

Removing encryption from a label affects every user who applies that label. Rename the label to avoid user confusion. A label named Confidential that no longer encrypts creates trust issues with the privacy officer and the audit team.

Removing S/MIME encryption in Outlook desktop

S/MIME encryption relies on a certificate installed on the sender machine. The certificate applies encryption per message through the Trust Center settings.

To turn off S/MIME on a single message, open the composer and go to Options, More Options, Security Settings. Uncheck Encrypt Message Contents and Attachments. Send the message without S/MIME encryption.

To turn off S/MIME across all outbound messages, go to File, Options, Trust Center, Trust Center Settings, Email Security. Uncheck Encrypt Contents and Attachments for Outgoing Messages. Click OK.

Removing the S/MIME certificate entirely happens in the Windows certificate store. Type certmgr.msc in the Run dialog. Open Personal, Certificates. Delete the S/MIME certificate. Deleting the certificate also breaks decryption of past S/MIME messages, so export a backup first.

💡Pro Tip: Identify the encryption layer before touching any toggle

Open Message Options and check the message class in Properties. The rpmsg class points to Purview, IPM.Note.SMIME points to S/MIME, and a populated Sensitivity field points to an IRM label. Knowing the layer tells you which removal path actually works. Users who skip this step click every toggle they can find and change nothing, because the toggle they picked addresses a different layer than the one applying encryption.

Removing encryption from Outlook messages in bulk

Outlook has no built-in bulk decrypt feature. Third party tools claim to bulk decrypt, but most require the sender private key and produce plaintext exports rather than in-place changes.

The supported path for bulk access uses eDiscovery in the Purview compliance portal. Create a content search that includes the target mailboxes. Export the results as a PST with the Include All Encrypted Messages option checked.

The exported PST contains decrypted copies of every message the running admin has permission to read. Import the PST into the destination mailbox using the Outlook Import feature. The imported copies are unencrypted.

Use this pattern for legal hold, migration, or forensic review only. Bulk decryption for general access defeats the point of the encryption in the first place. Reference guidance from HHS HIPAA Security Rule before running bulk decryption on any mailbox with PHI.

Common Outlook encryption removal errors and fixes

The Encrypt button stays selected even after you click it. Usually a mail flow rule is forcing encryption at the tenant. Check with the admin.

The message arrives at the recipient with the encryption warning banner even though you removed encryption. The recipient mail server flagged the message as suspicious because the sender IP does not match the tenant SPF record. Fix the SPF record.

Attachments still open with a password prompt. Purview Message Encryption applies to attachments through the same policy. Removing encryption from the body does not automatically release the attachments. Re-attach the files after removing encryption to reset the attachment state.

The recipient sees a portal link instead of the message body. The recipient mail client stripped the message body during transport. Check the recipient inbox rules and any downstream security gateways.

When to keep Outlook encryption on and route around it instead

Removing encryption from healthcare, financial, or legal correspondence creates compliance exposure. HIPAA, GLBA, and state privacy laws require encryption of regulated content in transit.

Practices with intermittent encryption needs often benefit from a per-message alternative rather than a permanent policy change. How to send encrypted email guides and services like Mailhippo work alongside Outlook without replacing the native stack.

Mailhippo adds a per-message send option to Outlook. When the sender needs encryption for a specific message, the Mailhippo option applies encryption and a BAA-covered delivery path. When the sender does not need encryption, the message goes out through normal Outlook without any policy conflict. Practices also handling healthcare web hosting and healthcare website maintenance pair the same discipline across their web and email stacks.

For further reference, review CISA cybersecurity advisories on message encryption baselines and the HIPAA Journal on compliant email before making any tenant-level encryption change that affects regulated traffic.

Frequently Asked Questions

How do I remove encryption from an Outlook email I received? +

You cannot un-encrypt a message someone else encrypted. Outlook decrypts the message for display, but the encrypted copy stays in the mailbox. To pass the content to another system, open the message, select all, copy the text, and paste it into a fresh unencrypted message. Do not forward the encrypted message directly if the destination system cannot decrypt it. Check the sender permission label first because some labels block copy and paste as well as forwarding.

How do I remove encryption from an outbound Outlook message before sending? +

On desktop Outlook, go to the Options ribbon and click the Encrypt button to toggle the setting off. On Outlook web, open the message, click the three-dot menu at the top, choose Encrypt, then select No Encryption. On mobile, tap the ellipsis in the composer to expose the encryption toggle. If the Encrypt button is grayed out, a tenant mail flow rule is forcing encryption and only an admin can remove that rule.

Why is the Encrypt button grayed out in Outlook? +

Three common reasons. The tenant does not include Purview Message Encryption on the current 365 plan. A mail flow rule is forcing encryption based on the recipient domain or subject line keyword. An IRM permission label already applied to the message locks the encryption setting. Check the plan first in the Microsoft 365 admin center, then check active mail flow rules in the Exchange admin center. IRM label conflicts show up in the message header under Options, Properties.

How do admins remove encryption from all outbound Office 365 mail? +

In the Exchange admin center, open Mail Flow, then Rules. Find any rule that applies encryption. Disable the rule or delete it entirely. In the Purview compliance portal, review any sensitivity labels that apply encryption automatically and edit the label settings. Test the change on a pilot user before rolling to the whole tenant. Removing encryption tenant-wide creates compliance exposure for practices handling PHI, so document the business reason and get sign-off from the privacy officer first.

How do I remove encryption from Office 365 email messages in bulk? +

There is no supported one-click bulk decrypt for messages already sent. PowerShell can iterate through a mailbox and export decrypted copies to a PST using the Search-Mailbox or New-ComplianceSearch cmdlets. The PST export contains the decrypted message body for messages the running admin has permission to read. Use this pattern only for eDiscovery or migration. Bulk decryption for general access defeats the reason encryption was applied in the first place.

Does removing S/MIME encryption require certificate changes? +

No. S/MIME is a per-message setting inside Outlook. Uncheck the S/MIME encryption option in the Options ribbon before sending. The certificate stays installed on the machine and remains available for future encrypted messages. If you want to stop offering S/MIME as an option, remove the certificate from the Windows certificate store under Personal, Certificates. Removing the certificate also breaks decryption of past S/MIME messages, so export a backup first.

Is it safe to remove encryption from healthcare emails? +

No, not without a compensating control. HIPAA requires encryption of PHI in transit and at rest. Removing Outlook encryption on a message carrying PHI creates a reportable breach if the message crosses the public internet unprotected. If the goal is to remove Outlook encryption because a downstream system cannot decrypt the message, route the message through a HIPAA compliant alternative like Mailhippo instead of stripping encryption entirely. The compliance exposure of unprotected PHI outweighs the workflow inconvenience of extra tooling.

Leave a Reply

Your email address will not be published. Required fields are marked *

Send your first secure email today Start free — no credit card required. HIPAA-compliant encryption in minutes. Start Free →