How to Encrypt Email in Outlook (Every Method, Step by Step)
Outlook has three separate ways to encrypt an email — and which one you can use depends almost entirely on your licence, not your skill. Here’s every method for new Outlook, classic Outlook, the web app and mobile, plus the exact reason the Encrypt button is greyed out for so many people.
Compose a new message, open the Options tab, and click Encrypt. Choose Encrypt-Only to protect the message, or Do Not Forward to also block forwarding, copying and printing. That’s the whole process — if your licence includes Microsoft Purview Message Encryption. It’s built into Microsoft 365 Business Premium, E3 and E5, and into Microsoft 365 Personal and Family for Outlook.com. It is not included in Business Basic, Business Standard, Office 365 E1, or a free Outlook.com account, which is why the button is missing or greyed out for so many people.
Email encryption in Outlook has a reputation for being complicated, but the actual clicking part takes about four seconds. What makes it feel hard is everything around it: three different encryption technologies sharing one button, a licence matrix that changed names twice, and an interface that moved when Microsoft shipped the new Outlook.
So this guide separates the two things that usually get tangled together. First, which encryption you’re entitled to — a two-minute check that saves an hour of clicking around settings that were never going to work. Then the exact steps for each method, in each version of Outlook, including what your recipient actually sees at the other end.
The 3 Ways to Encrypt Email in Outlook
Outlook stacks three different encryption technologies behind what looks like a single feature. They solve different problems, and only one of them is realistic for most people.
Before You Start: Check Whether You Actually Have Encryption
This is the step nearly every guide skips, and it’s the reason most people end up frustrated. Purview Message Encryption is a licensed feature. If your plan doesn’t include it, no amount of clicking through settings will make the Encrypt button appear — and the plan names give you almost no clue which is which.
Here’s the actual breakdown, straight from Microsoft’s licensing documentation:
| Your plan | Encryption included? | What to do |
|---|---|---|
| Microsoft 365 Business Premium | Yes | Nothing — the Encrypt button should appear |
| Microsoft 365 / Office 365 E3 | Yes | Nothing — included as standard |
| Microsoft 365 / Office 365 E5 | Yes, plus revoke & expiry | Enable Advanced Message Encryption for the extras |
| Office 365 A1, A3, A5 (education) | Yes | Nothing — included as standard |
| Office 365 Government G3, G5 | Yes | Nothing — included as standard |
| Microsoft 365 Business Standard | No | Add Azure Information Protection Plan 1, or upgrade to Business Premium |
| Microsoft 365 Business Basic | No | Add Azure Information Protection Plan 1, or upgrade |
| Office 365 Enterprise E1 / F3 | No | Add Azure Information Protection Plan 1 |
| Exchange Online Plan 1 or 2 | No | Add Azure Information Protection Plan 1 |
| Microsoft 365 Personal or Family | Yes (consumer version) | Use Outlook.com — see Method 3 below |
| Free Outlook.com account | No | Subscribe to Personal/Family, or use a third-party tool |
Method 1: Encrypt with Microsoft Purview Message Encryption
This is the method that covers the vast majority of real situations. It needs no certificates and no preparation, it works with any recipient address on any provider, and the encryption is applied by Microsoft 365 rather than by your computer — so it behaves the same on desktop, web and phone.
- Select New mail.
- Open the Options tab on the ribbon.
- Select Encrypt, then choose an option from the dropdown.
- Write your message and Send.
- In some web layouts the button sits under the three-dot menu at the bottom of the compose window instead.
- Select New Email.
- Open the Options tab.
- Select Encrypt (older builds: Permission).
- Pick Encrypt-Only or Do Not Forward.
- Write your message and Send.
- Tap compose to start a new message.
- Tap the three-dot menu in the compose view.
- Tap Set permissions.
- Choose your encryption option, then send as normal.
- Attachments inherit the protection automatically.
- The setting applies per message, not per account.
- Your admin’s custom sensitivity labels appear in the same dropdown.
- Recipients inside your tenant open it with no extra steps.
Encrypt-Only vs Do Not Forward: Which Should You Pick?
The dropdown gives you at least two built-in options, plus any sensitivity labels your organisation has published. The difference between the two defaults matters more than it first appears — particularly for attachments.
| Encrypt-Only | Do Not Forward | |
|---|---|---|
| Message body encrypted | Yes | Yes |
| Recipient can forward | Yes | No |
| Recipient can copy or print | Yes | No |
| Office attachments after download | Decrypted for Microsoft 365 recipients | Stay encrypted |
| PDF and image attachments | Can be downloaded unencrypted | Can be downloaded unencrypted |
| Best for | Sensitive information the recipient may legitimately need to pass on | Information that must stay with one named person |
The nuance worth remembering: Do Not Forward keeps Word, Excel and PowerPoint attachments protected even after they’re downloaded, because those file formats understand Microsoft’s rights management. PDFs and images do not — under either option, they can be saved out in the clear. If a PDF genuinely must stay locked, protect the file itself with a password before attaching it rather than relying on the email setting.
Method 2: S/MIME Encryption (Certificate-Based)
S/MIME is the older, standards-based approach, and it works differently in an important way: the encryption happens on your device using certificates, not on Microsoft’s servers. That makes it genuinely end-to-end, which is why regulated industries and government still specify it. The price is real setup friction — both sides need a certificate, and you need the recipient’s public certificate before you can encrypt anything to them.
- Go to Settings → Mail → S/MIME.
- Select Import and choose your .pfx certificate file.
- Enter the password you set when you downloaded it.
- Choose whether to sign and encrypt by default.
- Import the .pfx file into Windows first.
- Go to File → Options → Trust Center.
- Select Trust Center Settings → Email Security.
- Under Certificates and Algorithms, Choose your certificate.
Once it’s installed, encrypting is the same gesture as before — the Options tab gains Encrypt and Sign toggles for the message you’re writing. The catch is that Outlook needs the recipient’s public certificate in order to encrypt to them; without it, the send fails.
Method 3: Encrypting from Outlook.com (Personal & Family)
If you’re on a personal Outlook.com, Hotmail or Live address, encryption is available — but only with a Microsoft 365 Personal or Family subscription attached to the account. A free Outlook.com account has no encryption option, and neither does Microsoft 365 Basic.
- Compose a new message in Outlook.com.
- Open the Options ribbon.
- Select Encrypt.
- Choose Encrypt or Do Not Forward.
- Two options only — no custom labels.
- No admin console, reporting or audit trail.
- No revoke or expiry.
- Recipients on Gmail or Yahoo can authenticate with that account.
What the Recipient Actually Sees
This is worth understanding before you send anything important, because the experience varies a great deal — and an external recipient who wasn’t expecting a portal link may simply assume your message is phishing and delete it.
| Recipient’s setup | What happens |
|---|---|
| Same Microsoft 365 organisation | The message opens directly in Outlook, decrypted automatically. They may not even notice it was encrypted, beyond a small banner noting the restrictions. |
| Different Microsoft 365 tenant | Usually opens directly in their Outlook, with restrictions applied. Occasionally routes through the portal instead. |
| Outlook.com personal account | Opens in Outlook.com or the Outlook mobile app after signing in with their Microsoft account. |
| Gmail or Yahoo | Receives a notification email with a link. They can sign in with their existing Google or Yahoo account, or request a one-time passcode. |
| Any other provider | Receives a notification email and reads the message in the Microsoft encryption portal using a one-time passcode sent by email. |
Because the passcode arrives in the same inbox as the notification, this protects against interception in transit rather than against someone who already has access to the recipient’s mailbox. It’s the right trade-off for the vast majority of business email, but it’s worth knowing what it is.
What Outlook Encryption Does Not Protect
Encryption is genuinely strong on the things it covers. The problems come from assuming it covers more than it does.
Why the Encrypt Button Is Greyed Out or Missing
If you’ve reached this far and the button still won’t work, run through these in order. They’re arranged by how often each one turns out to be the actual cause.
Encryption is one of several settings that only behave consistently when applied centrally rather than device by device. The same is true of signatures — see our guide to Office 365 email signature management for how server-side deployment works, or browse our free email signature templates.
Frequently Asked Questions
Compose a new message, open the Options tab on the ribbon, and select Encrypt. Choose Encrypt-Only to protect the message and its attachments, or Do Not Forward to also prevent the recipient forwarding, copying or printing it. Then write and send as normal. In the Outlook mobile apps, tap the three-dot menu in the compose view and choose Set permissions instead. The setting applies to that single message, and attachments inherit the protection automatically.
Almost always a licensing issue rather than a setting. Microsoft Purview Message Encryption is included with Microsoft 365 Business Premium, E3 and E5, and Office 365 A and G plans — but not with Business Basic, Business Standard, Office 365 E1, or Exchange Online plans on their own. Those require an Azure Information Protection Plan 1 add-on. If your plan does qualify, check that the licence is assigned to your individual account, then sign out of Outlook and back in so the client picks up the entitlement. If it works in Outlook on the web but not on the desktop, the entitlement is correct and the issue is client-side.
Not with Microsoft’s built-in encryption. A free Outlook.com account has no Encrypt option, and Microsoft 365 Basic doesn’t include one either — you need a Microsoft 365 Personal or Family subscription for personal accounts, or a qualifying business plan for work accounts. The free alternative is S/MIME, which is built into Outlook at no cost, but requires you to obtain a certificate and for your recipient to have one too, which in practice makes it impractical for casual use. Note that every email you send is already protected in transit by TLS at no cost — that just isn’t the same thing as encrypting the message itself.
No, and this catches out a great many small businesses. Despite the name suggesting a mid-tier plan, Business Standard does not include Purview Message Encryption. You have two routes: add an Azure Information Protection Plan 1 licence for each user who needs to send encrypted mail, or upgrade those users to Microsoft 365 Business Premium, which includes it as standard. For a practice or firm where only two or three people handle sensitive correspondence, the add-on is usually the cheaper option; where most of the team needs it, Business Premium often works out better and brings additional security features with it.
No. The message body and attachments are encrypted, but the subject line is not — it travels in plain text and is visible to anyone who intercepts the message, as well as in notification previews. This is the most consequential limitation of Outlook encryption and the one most people don’t know about. Never put identifying or sensitive detail in the subject of an encrypted email: no patient names, case references, account numbers, salary figures or diagnoses. Use something deliberately generic such as “Secure message regarding your account” and put every specific detail in the encrypted body.
Both encrypt the message body and attachments. Encrypt-Only stops there — the recipient can read it, then forward, copy or print it freely. Do Not Forward adds rights management that blocks those actions, and additionally keeps Word, Excel and PowerPoint attachments encrypted even after they’re downloaded. The important caveat is that PDFs and image files can be downloaded unencrypted under either option, and no setting can prevent someone photographing their screen. Use Encrypt-Only when the recipient may legitimately need to pass information on, and Do Not Forward when it must stay with one named person.
Yes, and this is a real strength of Purview Message Encryption over S/MIME. Your Gmail recipient receives a notification email containing a link to the encrypted message. They can then authenticate with their existing Google account, or request a one-time passcode sent to that same address, and read the message in Microsoft’s encryption portal in their browser. No Microsoft account and no software is needed on their side. S/MIME, by contrast, would require your Gmail recipient to hold a certificate of their own, which most people don’t.
Revoking an encrypted message is possible, but it needs Advanced Message Encryption, which is included only with Microsoft 365 E5, Office 365 E5 and Office 365 Education A5 — or as an add-on for E3. With it, you can revoke access to a message already sent and set an expiry date after which the message can no longer be opened. Because encrypted messages to external recipients are read through Microsoft’s portal rather than downloaded, revocation genuinely works on them, which ordinary message recall cannot do. On any lower plan, there is no revoke option, and standard Outlook message recall only works for unread mail inside your own organisation.
The Bottom Line
Encrypting an email in Outlook is three clicks: Options → Encrypt → pick an option. Everything that makes it feel difficult happens before that — working out whether your licence includes the feature at all, and which of three encryption technologies you’re actually using.
Check the licensing table first, because that resolves most cases in under a minute. Use Purview Message Encryption unless a regulator specifically requires certificates. Reach for Do Not Forward when information must stay with one person, and Encrypt-Only when it may need to travel. And whichever you choose, keep the subject line generic — it’s the one part of the message encryption never covers.