are text messages private are text messages encrypted is SMS encrypted

Are text messages private? SMS, RCS and iMessage compared

Adrian Maverick · · 12 min read

"Text message" used to mean one thing. Today the same app on your phone sends SMS, MMS, RCS or iMessage depending on who is on the other end, and their privacy is very different. Some can be read by your carrier. Some cannot. The app does not make the difference obvious, so most people never know which kind they just sent.

Are text messages private?

It depends on the type. Standard SMS and MMS texts are not private: they are not end-to-end encrypted, so your carrier can read and hand over their contents. iMessage and RCS chats that show a lock are end-to-end encrypted, so only the people in the conversation can read them. Your carrier still logs who you texted and when.

The rest of this post is the evidence for that answer, a way to check any conversation yourself, and what carriers and police can actually get.

Text message privacy by type (as of October 2026)

Message type End-to-end encrypted? Who can read the content How to tell
SMS / MMS (any phone) No You, the recipient, the carriers that carry it, anyone who gets into those networks Green bubble on iPhone with no lock; no lock in Google Messages
RCS, Android to Android in Google Messages Yes, automatically, when both people use Google Messages with RCS chats on You and the recipient Lock on the send button and next to the timestamp
RCS between iPhone and Android Yes, in beta, when both carriers support it, the iPhone runs iOS 26.5 or later and the Android phone has the latest Google Messages You and the recipient when the lock shows; otherwise treat it like SMS "Encrypted" with a lock at the top of the chat on iPhone
iMessage (Apple to Apple) Yes You and the recipient Blue bubble, lock at the top of the chat

Each row comes from the companies' own documentation. Apple's page on the difference between iMessage, RCS and SMS/MMS says SMS and MMS "aren't end-to-end encrypted, which means they're not protected from a third-party reading them while they're sent between devices." Google's help page on end-to-end encryption in Google Messages says the same thing from the Android side: "End-to-end encryption isn't available for SMS/MMS messages."

If the term is new to you, end-to-end encryption means the message is locked on your device and unlocked only on the recipient's. The companies in the middle carry it but hold no key to open it.

Are text messages encrypted between iPhone and Android?

Some are, and this is the fact most articles have out of date.

For years the answer was no. A text between an iPhone and an Android phone was SMS, and when Apple added RCS in iOS 18 it arrived without end-to-end encryption. In March 2025 the GSMA, the mobile industry's standards body, published RCS Universal Profile 3.0, which defines end-to-end encryption for RCS using the Messaging Layer Security (MLS) protocol.

On May 11, 2026, Apple and Google began rolling it out. As of October 2026, here is exactly what Apple's support page says:

  • It is labeled "end-to-end encrypted RCS messaging (Beta)" and "will roll out over time."
  • You need iOS 26.5 and a carrier that supports end-to-end encryption. On Apple's carrier list, AT&T, T-Mobile and Verizon all show the feature in the US.
  • It depends on the other person too: "the encryption of each RCS conversation depends on whether your contact's carrier also supports it." In a group, all participants need carriers that support it.
  • When it is active, the conversation shows "Encrypted" with a lock icon at the top. If you do not see it, in Apple's words, "your RCS messages aren't protected from a third-party reading them while they're sent between devices."

On the Android side, Google says it requires the latest version of Google Messages. Google's help page also notes that RCS in a messaging app that does not support end-to-end encryption is not encrypted, and that "currently only Google Messages supports end-to-end encrypted RCS."

So a green bubble no longer tells you much on its own. Green can be plain SMS, unencrypted RCS, or encrypted RCS. The lock is the thing to look for.

Check any conversation in 10 seconds

You can test this on your own phone right now.

On iPhone

  1. Open the conversation in Messages.
  2. Look at the top of the chat. A lock means the chat is end-to-end encrypted. Blue bubbles with a lock are iMessage. Green bubbles with "Encrypted" and a lock are encrypted RCS.
  3. Green bubbles with no lock are SMS, MMS or unencrypted RCS. Treat them as readable by the carrier.

On Android (Google Messages)

  1. Open the conversation and start typing.
  2. Look at the send button. A small lock on it, and next to each message's timestamp, means end-to-end encryption is on.
  3. No lock means the message is going out as SMS/MMS or as unencrypted RCS.

Check again now and then. Google's page notes that an encrypted chat falls back when either person loses RCS, turns it off or switches phones, and encrypted messages need mobile data or Wi-Fi to send.

Can your carrier read your text messages?

For SMS and MMS, yes. The message passes through the carrier's systems in a form the carrier can read. CISA, the US cybersecurity agency, puts it bluntly in its mobile communications guidance: "SMS messages are not encrypted. A threat actor with access to a telecommunication provider's network who intercepts these messages can read them."

For end-to-end encrypted iMessage and RCS chats, the carrier cannot read the content. It still handles the delivery, so it knows a message moved. Apple's page says that for RCS, identifiers including your phone number and, depending on the carrier, your IP address are exchanged with "your carrier and their partners." That is metadata, and metadata reveals more than most people expect.

How long do carriers keep text messages?

Carriers do not publish a retention schedule, and I could not find a current official one. The best public document is a US Department of Justice chart from August 2010, released by the ACLU. It is old, and the carrier lineup has changed since, but it shows the pattern that matters:

Carrier (2010) Text message content Text message detail (who, when)
Verizon 3 to 5 days 1 rolling year
T-Mobile Not retained 2 years prepaid, 5 years postpaid
AT&T Not retained 5 to 7 years postpaid
Sprint Not retained 18 months

The words of a text were kept briefly or not at all. The record of who texted whom, and when, was kept for years. Treat the specific numbers as historical, since policies may have changed, and the shape as the lesson: the log outlives the message.

Can police read your text messages?

In the US, there are three routes, and each has a different legal bar.

  • From the carrier. Under the Stored Communications Act, message content held by a provider for 180 days or less requires a warrant, and Verizon's transparency report says it requires a warrant before disclosing stored content such as text messages. Records about your texts (numbers, dates, times) have a lower bar and can be obtained with a subpoena or court order. Given how briefly carriers keep content, the records are what is usually there to get.
  • From the phone. Every message you can read on your screen can be read by someone with your unlocked phone, encrypted or not. In Riley v. California (2014) the Supreme Court held that police generally need a warrant to search a phone seized during an arrest.
  • From a backup. End-to-end encryption protects messages in transit. Copies in a cloud backup follow the backup's rules, not the chat's. Google states that encrypted messages received on your phone are "included in Android backup and accessible to apps you've granted SMS or notifications permissions to."

When a chat is end-to-end encrypted, the carrier has no readable content to hand over. That does not make the conversation unreachable. It moves the question to the two phones and their backups.

Deleting a text removes it from your phone. It does not remove the recipient's copy or the carrier's record that the message was sent.

What the 2024 telecom breach showed

In November 2024, the FBI and CISA confirmed that hackers affiliated with the Chinese government had compromised multiple US telecommunications companies. The statement lists what was taken: customer call records, the private communications of "a limited number of individuals who are primarily involved in government or political activity," and information that was subject to US law enforcement requests under court orders. The campaign is widely known as Salt Typhoon.

CISA's guidance followed on December 18, 2024, and was updated in November 2025. It is written for "highly targeted individuals" in senior government, military and political roles, though CISA calls it "applicable to all audiences." Its first recommendation is to "only use end-to-end encrypted communications," naming "Signal or similar apps" as an example of a free app that works on both iPhone and Android. It also says to stop using SMS for login codes.

The breach was not the first sign of trouble in the phone network. The systems that route texts between carriers, SS7 and Diameter, have had known weaknesses for years, and in March 2024 the FCC asked carriers what they are doing to stop those weaknesses from being used to track people's locations.

How to make your texts more private

  1. Update your phone and messaging app. Encrypted RCS between iPhone and Android needs iOS 26.5 or later and the latest Google Messages. On Android, make sure RCS chats are turned on.
  2. Look for the lock before you send anything sensitive. No lock means the carrier can read it.
  3. Decide where your backups go. A private chat with a readable backup is only as private as the backup. Check your iCloud or Android backup settings.
  4. Move login codes off SMS. CISA recommends phishing-resistant sign-in such as security keys or passkeys, and an authenticator app instead of SMS for less valuable accounts.
  5. Lock the phone itself. A strong passcode protects every message on the device, whatever protocol delivered it.
  6. Use an end-to-end encrypted app for conversations that need it. That is CISA's first recommendation. If you are weighing a messaging app against email for a given conversation, our comparison of Signal and email covers when each fits.

The other inbox to check

Email is the other place your private conversations live: receipts, medical results, contracts, password resets. It deserves the same question you just asked about your texts. Secria Mail encrypts every message in your mailbox with zero-access encryption. Your keys are created on your device and only reach our servers encrypted.

Frequently asked questions

Are text messages encrypted on iPhone?

iMessage conversations (blue bubbles) are end-to-end encrypted. SMS and MMS (green bubbles) are not. RCS chats with Android phones are end-to-end encrypted when the conversation shows "Encrypted" with a lock, which as of October 2026 requires iOS 26.5 or later and supporting carriers on both sides.

Are text messages encrypted on Android?

In Google Messages, RCS chats with other Google Messages users are end-to-end encrypted automatically, and you will see a lock on the send button. SMS and MMS are not encrypted, and Google says RCS in other messaging apps is not end-to-end encrypted.

Can someone read my text messages without my phone?

For SMS, your carrier can, and so can anyone who gains access to the carrier's network or obtains the content through legal process. For end-to-end encrypted chats, the content is readable on the devices in the conversation and in any backup that is not itself end-to-end encrypted.

Can police get deleted text messages?

Deleting a text removes your copy. The recipient still has theirs, a backup may hold one, and the carrier's record that the message was sent can be kept for years. In the 2010 DOJ chart, most carriers did not keep the content itself at all.

Is RCS safer than SMS?

Encrypted RCS is: only the people in the chat can read it. RCS without the lock is not end-to-end encrypted, and Apple says such messages "aren't protected from a third-party reading them." Check for the lock instead of assuming.

Texts are private when the lock is there and not when it is missing. Check your most important conversations today, then ask the same question of your email.

Sources

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.