is Outlook encrypted is Outlook email encrypted are Outlook emails encrypted by default

Is Outlook email encrypted? What Microsoft can still read

Adrian Maverick · · 10 min read

Outlook has an Encrypt button, a lock icon and a long list of Microsoft security pages. None of that tells you the one thing most people are asking: can anyone besides you and the person you wrote to read the message?

Is Outlook email encrypted?

Partly. Outlook encrypts the connection your email travels over, using TLS, whenever the other mail server supports it. It does not encrypt messages end to end by default. Message-level encryption needs a Microsoft 365 subscription, and even then Microsoft runs the service and manages the keys, so Microsoft can still read the mail.

"Outlook" is three different products with three different answers, which is why the question gets muddled. There is free Outlook.com (which includes every Hotmail, Live and MSN address), Outlook.com with a Microsoft 365 Personal or Family subscription, and Outlook on a work or school account. Here is each one, as of October 2026, from Microsoft's own documentation.

What each kind of Outlook account encrypts

Free Outlook.com or Hotmail Outlook.com with Microsoft 365 Personal or Family Work or school (Microsoft 365)
In transit Opportunistic TLS Opportunistic TLS Opportunistic TLS, or forced TLS if an admin sets it up
Encrypt button No Yes: Encrypt and Do Not Forward Yes, on plans that include Microsoft Purview Message Encryption
End to end by default No No No
Who manages the keys Microsoft Microsoft Microsoft by default
Can Microsoft read stored mail Yes Yes Yes by default

The rest of this post is the evidence for each row.

Are Outlook emails encrypted by default?

Only the connection is. Microsoft's help page for personal accounts describes the default, a message with no permission set, as one that "uses Outlook's opportunistic Transport Layer Security (TLS) to encrypt the connection with a recipient's email provider" (Microsoft Support).

Two words in that sentence matter.

Opportunistic means Outlook tries TLS and falls back if the other side can't do it. Microsoft's documentation for its business mail service is blunt about the fallback: "by default Exchange sends the message without encryption if the recipient's organization doesn't support TLS encryption" (Microsoft Learn). Nearly every large provider supports TLS today, so in practice most mail is covered. It is still a best effort, not a promise.

Connection means the tunnel, not the letter. The same Microsoft page says: "TLS doesn't encrypt the message, just the connection." The help page for personal accounts adds that "with TLS, the message might not stay encrypted after the message reaches the recipient's email provider." Once your email arrives, it sits on the recipient's mail server in whatever form that provider stores it, and a copy sits in your Sent folder at Microsoft.

So an ordinary Outlook email is protected from someone tapping the line between mail servers. It is not protected from the companies at either end.

Is Outlook encrypted end to end?

No, not in any default setup. End-to-end encryption means a message is locked on the sender's device and unlocked only on the recipient's, so the provider in the middle never has a readable copy. Outlook's built-in encryption does not work that way.

Microsoft's overview of email encryption describes two ways an encrypted message gets turned back into readable text: either "the recipient's machine uses a key to decrypt the message," or "a central server decrypts the message on behalf of the recipient, after validating the recipient's identity" (Microsoft Learn). The Encrypt button is the second kind. A Microsoft server does the unlocking.

The one option in Outlook that keeps the keys on people's own devices is S/MIME. Microsoft recommends it "when either your organization or the recipient's organization requires true peer-to-peer encryption," and names government agencies as the typical users. It needs a certificate for you and one for every person you write to, which is why almost nobody outside large organizations has it switched on.

What the Encrypt button does, and who gets it

The button belongs to a service called Microsoft Purview Message Encryption. It replaced Office 365 Message Encryption, which Microsoft says "was deprecated on July 1, 2023."

On personal accounts it comes with a paid subscription. Microsoft lists "encryption and prevent forwarding features" among the premium Outlook.com features for Microsoft 365 Personal and Family subscribers. A free Outlook.com or Hotmail account does not have the button at all. Subscribers get two choices:

  • Encrypt. In Microsoft's words, "your message stays encrypted and doesn't leave Microsoft 365."
  • Do Not Forward. The message "stays encrypted within Microsoft 365 and can't be copied or forwarded."

Attachments are a weak spot. Under Do Not Forward, Word, Excel and PowerPoint files stay encrypted after download, but Microsoft says "all other attachments, such as PDF files or image files, can be downloaded without encryption." A scanned passport is an image. A tax return is usually a PDF.

On work and school accounts it depends on the license. Microsoft's Message Encryption FAQ says it is "offered as part of Office 365 Enterprise E3 and E5, Microsoft 365 Enterprise E3 and E5, Microsoft 365 Business Premium, Office 365 A1, A3, and A5, and Office 365 Government G3 and G5." Organizations on Business Basic, Business Standard, Exchange Plan 1 or 2, Office 365 F3 or E1 have to buy an add-on to get it. If your company is on one of those and never bought the add-on, your Outlook has no message encryption, whatever the ribbon looks like at a bigger company.

"Stays inside Microsoft 365" is the detail to hold on to. The message is protected from other people. It never leaves Microsoft's custody, and Microsoft holds the key.

Who holds the keys to your Outlook mail?

Microsoft does. This is stated plainly in three places.

For the Encrypt button, Microsoft's comparison of its encryption options says: "Microsoft securely manages and stores the keys, so you don't have to."

For mail stored in business mailboxes, Microsoft says email at rest is encrypted with BitLocker on the drives in its data centers, with a second layer called service encryption on top. On who controls that layer: "By default, Microsoft manages all cryptographic keys including the root keys for service encryption" (Microsoft Learn). Large organizations can supply their own root keys through a feature called Customer Key, and even then, Microsoft says it "manages all other keys."

For personal accounts, the Microsoft Privacy Statement (last updated September 2026) says the company will "retain, access, transfer, disclose, and preserve personal data, including your content (like the content of your emails in Outlook.com or files in OneDrive)" when it has a good faith belief that doing so is necessary to comply with the law or valid legal process, protect customers, keep its products secure, or protect its own rights and property. You can only disclose what you can read.

Does bringing your own key change what happens when a legal demand arrives? Microsoft answers that in its FAQ too: no. Bring-your-own-key for message encryption was, it says, "designed for compliance-focused organizations," not as a shield against subpoenas.

Test your own Outlook in two minutes

You don't have to take any of this on trust. Three checks, no tools needed.

  1. Look for the button. Start a new message, open the Options tab, and look for Encrypt. If it is missing, you are on a free account or a work plan without message encryption, and every email you send relies on TLS alone.
  2. Send an encrypted message to a Gmail or Yahoo address you own. If you have the button, choose Encrypt and send. Open the other inbox. You will not find your message there. You will find a notice that sends you to a Microsoft web page, where you sign in or ask for a one-time passcode, and Microsoft then shows you the text in your browser. That is the central server from Microsoft's own description, decrypting on your behalf. It can do that because it has the key.
  3. Think through a password reset. If you forgot your Outlook password tomorrow, Microsoft would verify you by text or backup email and hand back your whole mailbox, every old message readable. That only works when the provider can open the mailbox without anything that lives solely with you.

To see whether one specific message traveled over TLS, read its headers. Our guide to checking whether an email is encrypted shows which lines to look for. If what you need is the click-by-click steps for sending a protected message today, those are in how to send an encrypted email.

When Outlook's encryption is enough, and when it isn't

It depends on who you are keeping the message from.

If the worry is a stranger on public Wi-Fi, a misdirected forward, or a colleague passing your email along, Outlook's TLS plus the Encrypt and Do Not Forward options cover it.

If the worry is the provider itself, a breach of the provider's systems, or a legal demand served on the provider, they don't. Every Outlook option short of S/MIME leaves Microsoft able to produce readable mail.

For that second case you need a mailbox where the provider doesn't have a usable key. That is how we built Secria Mail. Your keys are created on your device and only ever reach our servers encrypted, so every message in your mailbox is sealed with your keys, and there is no subscription tier to unlock that: the free plan has the same encryption as the paid ones, including post-quantum ML-KEM-1024 with X25519. If you are moving from Outlook or Hotmail, you can bring your old mail with you as a PST file. The Outlook alternative page sets the two side by side.

Frequently asked questions

Is Hotmail encrypted? Hotmail addresses now live on Outlook.com, so the answer is the same as for free Outlook.com. Mail is encrypted in transit with opportunistic TLS, there is no Encrypt button without a Microsoft 365 subscription, and Microsoft can access stored mail.

Does Outlook encrypt attachments? In transit, attachments travel inside the same TLS connection as the message. With the paid Do Not Forward option, Office files stay encrypted after download, but Microsoft says PDFs and images "can be downloaded without encryption." With the plain Encrypt option, recipients on Outlook.com and Microsoft 365 can download attachments unencrypted.

Is Office 365 email encrypted by default? In transit and on Microsoft's disks, yes: Microsoft 365 uses TLS between servers and BitLocker plus service encryption at rest, with keys Microsoft manages. Message-level encryption is not on by default. It needs the right license, and either a user clicking Encrypt or an admin rule that applies it.

Can Microsoft read my Outlook emails? It has the technical ability. Microsoft's privacy statement says it may access and disclose content, including "the content of your emails in Outlook.com," when it believes that is necessary for the reasons listed above. The same statement says its processing "involves both automated and manual (human) methods."

Can a Gmail user open an encrypted Outlook email? Yes. Microsoft says a recipient on Google or Yahoo "can authenticate using your Google or Yahoo account or by using a temporary passcode." They read the message on a Microsoft web page, not in their own inbox.

Outlook locks the road your email travels on, and for a fee it will lock the message from other people. The one party it never locks out is Microsoft. If that is the party you had in mind, a free Secria account takes about a minute to set up.

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.