Is iMessage encrypted? Yes, but check your iCloud backup
The lock is real. What decides whether your iMessages stay private is not the message itself but the copy of it that ends up in iCloud, and one setting that most people have never opened.
Is iMessage encrypted?
Yes. iMessage is end-to-end encrypted by default, so Apple cannot read a message while it travels between devices. The exception is storage: if iCloud Backup is on and Advanced Data Protection is off, the backup holds a copy of the key to your messages, and Apple can decrypt that backup. Green-bubble SMS is not encrypted.
Everything below comes from Apple's own documents, checked on October 11, 2026.
What iMessage encrypts and what it does not
Apple's Platform Security guide says of iMessage that "Apple doesn't store message content or attachments, which are all secured with end-to-end encryption so that no one but the sender and receiver can access them" (iMessage security overview). Each device generates its own key pairs and sends only the public keys to Apple's directory service. Apple's servers pass along ciphertext.
Since iOS 17.4 the protocol behind this is PQ3. According to Apple Security Research, each device registers a post-quantum Kyber-1024 key next to a classical P-256 elliptic curve key, and the conversation is rekeyed with fresh post-quantum keys roughly every 50 messages and at least once every 7 days. Kyber is the algorithm NIST later standardized as ML-KEM. Message signatures still use classical ECDSA.
Three things are outside that envelope:
- Metadata. The same guide states that "metadata, such as the timestamp and APNs routing information, isn't encrypted."
- Messages waiting for delivery. If a device is offline, the encrypted message sits on Apple's servers "for up to 30 days." It is still ciphertext.
- The stored copy in iCloud. This is the one that changes the answer.
Can Apple read your iMessages?
In transit, no. From iCloud, it depends on two switches: iCloud Backup and Advanced Data Protection.
Apple's iCloud data security overview lists Messages in iCloud as end-to-end encrypted, then qualifies it in a note: under standard data protection, "Messages in iCloud is end-to-end encrypted when iCloud Backup is disabled." With both on, "your backup includes a copy of the Messages in iCloud encryption key to help you recover your data." The same page's table shows who holds the key to that backup under standard protection: Apple.
That gives four setups.
| Your iCloud setup | Where your messages are stored | Can Apple decrypt the stored copy? |
|---|---|---|
| Standard protection, iCloud Backup on, Messages in iCloud on | Messages in iCloud, with the key copied into the backup | Yes, through the key in the backup |
| Standard protection, iCloud Backup on, Messages in iCloud off | Inside the device backup itself | Yes, Apple holds the backup key |
| Standard protection, iCloud Backup off, Messages in iCloud on | Messages in iCloud only | No, the key stays on your trusted devices |
| Advanced Data Protection on | Either or both | No, the backup and the key inside it are end-to-end encrypted |
Advanced Data Protection is off until you turn it on. Anyone who uses iCloud Backup and has never opened that setting is in one of the first two rows.
Two details matter if you change anything. First, Apple says that when you turn off iCloud Backup, "a new key is generated on your device to protect future Messages in iCloud." Second, a conversation has two ends. Your messages also live on the other person's devices, and if their backup is in one of the first two rows, that copy is in the same position no matter what you set on your own phone.
What Apple can hand to police
Apple publishes what it can produce in its Legal Process Guidelines for US law enforcement (the current version is dated October 2025). Four points cover iMessage:
- Live interception: not possible. "Apple cannot intercept customers' iMessage or FaceTime communications as these communications are end-to-end encrypted."
- Lookup logs: yes. Apple keeps "iMessage capability query logs," a record that a device asked whether a phone number or email address can receive iMessage. The guidelines say these logs "do not indicate that any communication between customers actually took place," are "retained up to 25 days," and can be obtained with a court order or search warrant. Apple's consumer page, Messages and Privacy, puts the storage of those looked-up numbers and addresses at "up to 30 days."
- iCloud content under standard protection: yes, with a search warrant. The guidelines list Messages and device backups, and note that backups "may include photos and videos in the Camera Roll, device settings, app data, iMessage, Business Chat, SMS, and MMS messages and voicemail." For data it can decrypt, "Apple retains the encryption keys in its U.S. data centers."
- iCloud content under Advanced Data Protection: mostly no. "Apple cannot decrypt certain iCloud content, including Photos, iCloud Drive, Backup, Notes, and Safari Bookmarks." Email, contacts and calendars remain available.
So the route from an encrypted iMessage to a readable transcript runs through the backup. The legal process is the same either way. The setting decides whether there is anything readable to produce.
How to check your own iPhone
This takes about two minutes. Paths are from Apple's current support pages.
- Check Advanced Data Protection. Open Settings, tap your name, tap iCloud, and scroll to Advanced Data Protection. It shows On or Off. To turn it on you need iOS 16.2 or later on your devices, two-factor authentication, and a recovery contact or a recovery key, because Apple will no longer be able to help you recover that data.
- Check iCloud Backup. Settings, your name, iCloud, iCloud Backup. If this is on and step 1 says Off, you are in one of the first two rows of the table.
- Check Messages in iCloud. Settings, your name, iCloud, See All, Messages in iCloud. This tells you whether messages sync on their own or ride along inside the device backup.
- Check Contact Key Verification. Settings, your name, then scroll down to Contact Key Verification. With "Verification in iMessage" on, you get an alert if the keys for a contact who also uses it fail verification, and you can compare verification codes with a contact yourself. Apple's Contact Key Verification page lists iOS 17.2 or later, iCloud Keychain, a passcode and two-factor authentication as requirements.
- Look at the conversation itself. Blue bubbles are iMessage. Green bubbles are SMS, MMS or RCS. Apple's support page says iMessage conversations show a lock icon at the top, and an encrypted RCS conversation shows "Encrypted" with a lock.
If you want Apple out of the stored copy, you have two options: turn on Advanced Data Protection, or turn off iCloud Backup and back up to a computer with an encrypted local backup instead.
Advanced Data Protection in the UK
In the United Kingdom the first option is not available to everyone. Apple stopped offering Advanced Data Protection to new UK users in February 2025 after a government order under the Investigatory Powers Act. Apple's UK support page says users "who have not already enabled Advanced Data Protection will no longer have the option to do so," that people who already had it on will get further guidance, and that "iMessage and FaceTime, remain end-to-end encrypted globally, including in the UK."
As of October 2026 that has not changed. TechCrunch reported on August 3, 2026, citing the Financial Times, that Apple filed a new complaint at the Investigatory Powers Tribunal against a later notice. For a UK user who never enabled Advanced Data Protection, the practical choice for messages is the third row of the table: iCloud Backup off. Our post on whether iCloud is encrypted and the UK order follows that case.
Are green bubbles encrypted?
SMS and MMS are not. Apple's page on iMessage, RCS and SMS/MMS says they "aren't end-to-end encrypted, which means they're not protected from a third-party reading them while they're sent between devices."
RCS is in between. The GSMA published an end-to-end encryption specification for RCS in March 2025, as part of Universal Profile 3.0. Apple began rolling it out in beta on May 11, 2026, for iPhones on iOS 26.5 with supported carriers and Android phones on the latest Google Messages. Apple's support page still labels it beta and adds that "the encryption of each RCS conversation depends on whether your contact's carrier also supports it." A green bubble is encrypted only when the conversation shows "Encrypted" with the lock.
The same question for your email
Advanced Data Protection changes the answer for messages, photos and backups. It does not change it for mail. Apple's table lists iCloud Mail as "in transit & on server" with the key held by Apple under both settings, "because of the need to interoperate with the global email system." So the question to ask of an inbox is the one this post asks of iMessage: who holds the key to the stored copy?
Secria Mail uses zero-access encryption for every message in your mailbox, with hybrid ML-KEM-1024 and X25519 on every plan. Your keys are created on your device and only reach our servers encrypted. If you use iCloud Mail today, the iCloud Mail comparison shows the differences side by side.
Frequently asked questions
Is iMessage end-to-end encrypted by default?
Yes. There is nothing to turn on for messages between Apple devices. What is not end-to-end encrypted by default is the iCloud backup that can hold those messages or the key to them. That requires Advanced Data Protection.
Can police read my iMessages?
They cannot intercept them, and Apple says it has no way to decrypt them in transit. With a search warrant, Apple can provide iCloud content it is able to decrypt, which under standard protection includes device backups containing iMessage, SMS and MMS messages. With Advanced Data Protection on, Apple cannot decrypt the backup.
Is iMessage encrypted over Wi-Fi?
Yes. The encryption happens on your device before the message is sent, so it is the same over Wi-Fi and cellular data. The owner of the network can see that your phone connects to Apple, not what the message says.
Is iMessage end-to-end encrypted in the UK?
Yes. Apple states that iMessage remains end-to-end encrypted in the UK. What UK users who had not already enabled it cannot do, as of October 2026, is turn on Advanced Data Protection, so iCloud Backup there stays under standard protection.
Does Apple keep a record of who I message?
Not of the messages. Apple's Legal Process Guidelines say it "does not have iMessage communication logs." It does keep capability query logs, which show that a device looked up whether a number or address can receive iMessage, for up to 25 days.
Check the four settings once, and again when you set up a new iPhone. For the inbox, Secria Mail is free to start.
Sources
- Apple Support, "iCloud data security overview" (published January 5, 2026): https://support.apple.com/en-us/102651
- Apple Platform Security, "iMessage security overview": https://support.apple.com/guide/security/imessage-security-overview-secd9764312f/web
- Apple Platform Security, "How iMessage sends and receives messages securely": https://support.apple.com/guide/security/how-imessage-sends-and-receives-messages-sec70e68c949/web
- Apple Security Research, "iMessage with PQ3" (February 21, 2024): https://security.apple.com/blog/imessage-pq3/
- Apple, "Legal Process Guidelines: Government & Law Enforcement within the United States" (published October 2025): https://www.apple.com/legal/privacy/law-enforcement-guidelines-us.pdf
- Apple Legal, "Messages & Privacy": https://www.apple.com/legal/privacy/data/en/messages/
- Apple Support, "How to turn on Advanced Data Protection for iCloud" (April 17, 2026): https://support.apple.com/en-us/108756
- Apple Support, "About iMessage Contact Key Verification" (May 7, 2026): https://support.apple.com/en-us/118246
- Apple Support UK, "Apple can no longer offer Advanced Data Protection in the United Kingdom to new users": https://support.apple.com/en-gb/122234
- TechCrunch, "Apple challenges UK government's latest demand for iCloud backdoor: report" (August 3, 2026): https://techcrunch.com/2026/08/03/apple-challenges-uk-governments-latest-demand-for-icloud-backdoor-report/
- Apple Support, "What is the difference between iMessage, RCS, and SMS/MMS?" (May 11, 2026): https://support.apple.com/en-us/104972
- Apple Newsroom, "End-to-end encrypted RCS messaging begins rolling out today in beta" (May 11, 2026): https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/
- GSMA, "RCS Encryption: A Leap Towards Secure and Interoperable Messaging" (March 14, 2025): https://www.gsma.com/newsroom/article/rcs-encryption-a-leap-towards-secure-and-interoperable-messaging/
Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.