Does Gmail encrypt emails? Yes, in three different ways
Gmail encrypts your email more than once on its way to the recipient, and it still isn't private from Google. Both halves of that sentence are true, and the confusion comes from treating "encrypted" as one thing. It is at least three.
Does Gmail encrypt emails?
Yes. Gmail encrypts every email in transit with TLS whenever the other mail provider supports it, and it encrypts messages and attachments at rest on Google's servers. Google manages the keys for both, so Google can still process your mail. End-to-end encryption exists only on certain paid Workspace editions.
So the useful question is not whether Gmail encrypts, but which encryption applied to this message and who holds the key. The table below is the whole answer in one place.
Every layer of Gmail encryption, and who holds the key
| Where your email is | What protects it | Who gets it | Who holds the key |
|---|---|---|---|
| Between your device and Gmail | HTTPS | Every account | |
| Between Gmail and another provider | TLS, if the other provider supports it | Every account | Google and the other provider |
| Stored on Google's servers | AES encryption at rest | Every account | |
| Sent with hosted S/MIME | Message-level encryption | Work or school accounts | Google hosts the keys |
| Sent with client-side encryption | End-to-end encryption | Selected Workspace editions | Your organization |
The first three rows happen on their own in every account, personal Gmail included. The last two are add-ons that an administrator has to switch on. Each row is explained below with Google's own wording.
Does Gmail encrypt emails by default?
Yes, in transit. Google's Gmail encryption page says: "All Gmail messages use TLS automatically." TLS (Transport Layer Security) encrypts the connection between mail servers, so someone tapping the network between Gmail and the recipient's provider sees scrambled data.
The connection between you and Gmail is covered separately. Google's email encryption FAQ notes that "since 2010, HTTPS has been the default when you're signed into Gmail."
There is a condition attached to TLS, and it is the part most summaries drop.
When does Gmail send an email without encryption?
When the other side can't accept it. Google's security check page puts it plainly: "For TLS to work, the email providers for both the sender and recipient must use TLS."
Gmail does not refuse to deliver in that case. It sends the message anyway, unencrypted, and marks it with a red open lock. The same FAQ explains why this still happens: "Gmail is capable of encrypting the email it sends and receives, but only when the other email provider supports TLS encryption."
Email between two Google accounts is always encrypted in transit. The gap is mail to and from smaller providers, old company mail servers, and some bulk senders. If the recipient is a clinic, a local law office, or a school district running its own mail server, do not assume the lock is there.
TLS also stops at each server. It protects the trip, not the message. As Google's FAQ says, "What TLS doesn't do is encrypt data at rest." That is a separate layer.
Does Gmail encrypt email at rest?
Yes. Google's Workspace encryption whitepaper, which states that it "applies to both consumer and enterprise data," describes how. Stored data is broken into chunks, and each chunk is encrypted with its own key "using the Advanced Encryption Standard (AES) cipher with a 128-bit or stronger key." Many articles round that up to "AES-256" for everything. Google's document does not.
At-rest encryption protects you if a disk is stolen or a data center is breached. It does not protect your mail from Google, and the whitepaper is direct about that. The access rules ensure that "data in each chunk can only be decrypted by authorized Google services and employees." In its default mode, the paper adds, "Google manages cryptographic keys on behalf of its customers."
This is the difference between encryption at rest and encryption you control. What Google does with that access, and how to limit it, is the subject of our piece on whether Gmail is private.
Does Gmail encrypt email attachments?
Yes, the same way as the message. Attachments travel inside the email, so TLS covers them in transit whenever it covers the message. At rest, the whitepaper's table of encrypted data lists Gmail as "Messages and attachments."
The same limits apply. An attachment sent to a provider without TLS travels unencrypted. An attachment stored in Gmail is encrypted with keys Google manages. If the file is the sensitive part, such as a tax form or a passport scan, the attachment gets no extra protection that the message lacks.
Is Gmail end-to-end encrypted?
Not for personal accounts. End-to-end encryption means only the sender and recipient hold the keys. Gmail has two message-level options, both for organizations:
Hosted S/MIME. Available on work or school accounts. Google says it "securely manages a copy of your key," and its security page adds that "these keys are hosted by Google, and they encrypt and decrypt the message." Messages show a green lock. This protects mail from outsiders along the whole route, but Google holds a key.
Client-side encryption (CSE). Here, in Google's words, "your organization holds the only copy of the key. Not even Google can open your briefcase." Messages show a blue shield. Google's admin documentation lists the supported editions as Frontline Plus, Enterprise Plus, Education Standard, and Education Plus.
Since October 2, 2025, CSE users can also send end-to-end encrypted mail to people on other providers, who open it through a guest account. Google's announcement limits that feature to Enterprise Plus with the Assured Controls add-on.
A free @gmail.com account has none of this. There is no setting to turn on and no upgrade for an individual to buy.
Is Gmail confidential mode encryption?
No. Confidential mode is access control. Google's confidential mode page lists what it does: set an expiration date, revoke access, require a passcode, and "disable options for recipients to forward, copy, print, and download your emails." The page never uses the word encryption, and it warns that recipients "can still take screenshots or photos of your emails."
A confidential message gets the same TLS and at-rest encryption as any other Gmail message, with the same keys. It limits what the recipient can do. It does nothing about who else can read the stored copy.
Check before you send: two tests that take a minute
Most advice on this topic tells you how to inspect a message after it has arrived. For anything sensitive you want to know before it leaves.
1. Read the lock in the compose window. Google's encryption page says that on a computer or Android device, "when you compose a message, select Message security." Add the recipient's address first, since the answer depends on their provider. Standard encryption, the gray lock, means TLS will be used. A red open lock means that provider does not support it and the message would travel unencrypted. Google notes you may also see a warning when "encryption hasn't worked for a specific email provider in the past."
2. Look up the recipient's mail domain. Google publishes how much of the mail it exchanges with other providers is encrypted in transit, in its Safer Email transparency report. The page has a search box. Type the part of the recipient's address after the @ sign and the report shows how much of the mail between Gmail and that domain was encrypted. It only covers domains that exchange a lot of mail with Gmail, so a small firm may not appear. If the number is well below 100 percent, treat mail to that domain as a postcard.
For a message you already received, the check is different: you read the security line and the headers. That walkthrough, for Gmail and other apps, is in how to check if your email is encrypted.
What to do when Gmail's encryption isn't enough
If the lock is red, or the content is something you would not want read from Google's servers, you have three choices.
Send it another way. A file shared through an encrypted service, or a message in an end-to-end encrypted chat app, sidesteps email altogether.
Add your own encryption on top. Google's FAQ acknowledges that when a Gmail user receives a PGP-encrypted email, "Gmail cannot see the content." The setup takes effort on both ends. Our guide on how to send an encrypted email lists the options from easiest to hardest.
Use a mailbox where the keys are yours. That is what we built Secria Mail to be. Your keys are created on your device and only ever reach our servers encrypted, so every message in your mailbox is sealed with your keys, not ours. End-to-end encryption is on by default, with post-quantum ML-KEM-1024 and X25519 on every plan, including the free one. There is no edition to buy and no administrator to ask.
Frequently asked questions
Does Gmail automatically encrypt emails? Yes. TLS in transit and encryption at rest both happen without any setting. TLS depends on the recipient's provider supporting it, and Gmail delivers the message unencrypted if it doesn't.
Does Gmail encrypt all emails? All emails are encrypted at rest on Google's servers. Not all are encrypted in transit: a message to or from a provider without TLS travels in the clear, and Gmail marks it with a red open lock.
Can Google read my encrypted Gmail? Google's systems can, yes. TLS ends at Google's servers, and the at-rest keys are managed by Google. Only client-side encryption, on eligible Workspace editions, keeps the keys out of Google's hands.
Does Gmail use TLS 1.3?
Gmail supports current TLS versions, and the version used for a given message depends on what the other server supports too. You can see the version on a delivered message in its headers, on a line that reads like version=TLS1_3.
Is Gmail encryption good enough for sensitive documents? It protects against someone intercepting the message on the network, as long as the lock is gray. It does not protect the copy stored with Google or with the recipient's provider. For documents like tax forms or ID scans, use end-to-end encryption or a different channel.
"Encrypted" in Gmail means encrypted against outsiders, with Google holding the keys. If you want a mailbox where the keys are yours, Secria's free plan takes a few minutes to set up.
Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.