Skip to content
Independent & Expert-Reviewed AboutContactDisclosure
EmailSignatureHelp EmailSignatureHelpOffice 365 Signature Experts
Outlook Help · Updated July 2026

How to Encrypt Email in Outlook (Every Method, Step by Step)

Outlook has three separate ways to encrypt an email — and which one you can use depends almost entirely on your licence, not your skill. Here’s every method for new Outlook, classic Outlook, the web app and mobile, plus the exact reason the Encrypt button is greyed out for so many people.

11 min read By Edvard Smith New Outlook · classic · web · mobile
How to encrypt email in Outlook — the Encrypt button on the Options ribbon showing Encrypt-Only and Do Not Forward
The Encrypt button lives on the Options ribbon. If it’s greyed out, the cause is almost always your licence — not a setting you’ve missed.
The direct answer

Compose a new message, open the Options tab, and click Encrypt. Choose Encrypt-Only to protect the message, or Do Not Forward to also block forwarding, copying and printing. That’s the whole process — if your licence includes Microsoft Purview Message Encryption. It’s built into Microsoft 365 Business Premium, E3 and E5, and into Microsoft 365 Personal and Family for Outlook.com. It is not included in Business Basic, Business Standard, Office 365 E1, or a free Outlook.com account, which is why the button is missing or greyed out for so many people.

Email encryption in Outlook has a reputation for being complicated, but the actual clicking part takes about four seconds. What makes it feel hard is everything around it: three different encryption technologies sharing one button, a licence matrix that changed names twice, and an interface that moved when Microsoft shipped the new Outlook.

So this guide separates the two things that usually get tangled together. First, which encryption you’re entitled to — a two-minute check that saves an hour of clicking around settings that were never going to work. Then the exact steps for each method, in each version of Outlook, including what your recipient actually sees at the other end.

The 3 Ways to Encrypt Email in Outlook

Outlook stacks three different encryption technologies behind what looks like a single feature. They solve different problems, and only one of them is realistic for most people.

1
Purview Message Encryption. Microsoft’s built-in option, formerly called Office 365 Message Encryption or OME. No certificates, no setup — if your licence covers it, the Encrypt button just works. Sends to any address, including Gmail. This is the one you want.
2
S/MIME. Certificate-based encryption. Both sender and recipient need a digital certificate installed, and you need the recipient’s public certificate before you can encrypt to them. Powerful, standards-based, and genuinely fiddly to roll out.
3
Personal & Family encryption. The consumer version for Outlook.com, included with a Microsoft 365 Personal or Family subscription. Same underlying technology as Purview, fewer options, and no admin controls.
💡
A fourth thing that isn’t encryption: Outlook already uses TLS to protect messages while they travel between mail servers, automatically, on every email you send. That’s genuinely useful, but it protects the route, not the message — the email sits unencrypted at both ends and TLS can silently downgrade if the receiving server doesn’t support it. When people say “encrypt an email,” they mean one of the three methods above, which protect the message itself.

Before You Start: Check Whether You Actually Have Encryption

This is the step nearly every guide skips, and it’s the reason most people end up frustrated. Purview Message Encryption is a licensed feature. If your plan doesn’t include it, no amount of clicking through settings will make the Encrypt button appear — and the plan names give you almost no clue which is which.

Here’s the actual breakdown, straight from Microsoft’s licensing documentation:

Your planEncryption included?What to do
Microsoft 365 Business PremiumYesNothing — the Encrypt button should appear
Microsoft 365 / Office 365 E3YesNothing — included as standard
Microsoft 365 / Office 365 E5Yes, plus revoke & expiryEnable Advanced Message Encryption for the extras
Office 365 A1, A3, A5 (education)YesNothing — included as standard
Office 365 Government G3, G5YesNothing — included as standard
Microsoft 365 Business StandardNoAdd Azure Information Protection Plan 1, or upgrade to Business Premium
Microsoft 365 Business BasicNoAdd Azure Information Protection Plan 1, or upgrade
Office 365 Enterprise E1 / F3NoAdd Azure Information Protection Plan 1
Exchange Online Plan 1 or 2NoAdd Azure Information Protection Plan 1
Microsoft 365 Personal or FamilyYes (consumer version)Use Outlook.com — see Method 3 below
Free Outlook.com accountNoSubscribe to Personal/Family, or use a third-party tool
⚠️
The Business Standard trap. This catches out more small businesses than anything else in Microsoft 365. Business Standard sounds like a mid-tier plan that would obviously include email encryption — it doesn’t. A small medical practice, law firm or accountancy on Business Standard will find the Encrypt button greyed out no matter what they try. The fix is an Azure Information Protection Plan 1 add-on licence for each user who needs it, or a move up to Business Premium.
30-second check
Open Outlook on the web, start a new message, and look for the Encrypt button (on the toolbar, or under the three-dot menu). If it’s there and clickable, you have encryption and can skip straight to Method 1. If it’s missing or greyed out, your licence is the first thing to check — not your settings.

Method 1: Encrypt with Microsoft Purview Message Encryption

This is the method that covers the vast majority of real situations. It needs no certificates and no preparation, it works with any recipient address on any provider, and the encryption is applied by Microsoft 365 rather than by your computer — so it behaves the same on desktop, web and phone.

New Outlook & Outlook on the web
  • Select New mail.
  • Open the Options tab on the ribbon.
  • Select Encrypt, then choose an option from the dropdown.
  • Write your message and Send.
  • In some web layouts the button sits under the three-dot menu at the bottom of the compose window instead.
Classic Outlook for Windows
  • Select New Email.
  • Open the Options tab.
  • Select Encrypt (older builds: Permission).
  • Pick Encrypt-Only or Do Not Forward.
  • Write your message and Send.
⚠️
Use the Options ribbon, not File → Encrypt. Microsoft confirmed a known issue in February 2026 affecting classic Outlook: encrypting through File → Encrypt can produce messages recipients cannot open, with a “you don’t have sufficient permissions” error — even though the send appeared to work. Several organisations also found that path silently applying Do Not Forward when Encrypt-Only was selected. The Options ribbon path above is unaffected. If you’ve been encrypting through the File menu and hearing that recipients can’t open your messages, that’s your cause.
Outlook on Android & iPhone
  • Tap compose to start a new message.
  • Tap the three-dot menu in the compose view.
  • Tap Set permissions.
  • Choose your encryption option, then send as normal.
Good to know
  • Attachments inherit the protection automatically.
  • The setting applies per message, not per account.
  • Your admin’s custom sensitivity labels appear in the same dropdown.
  • Recipients inside your tenant open it with no extra steps.

Encrypt-Only vs Do Not Forward: Which Should You Pick?

The dropdown gives you at least two built-in options, plus any sensitivity labels your organisation has published. The difference between the two defaults matters more than it first appears — particularly for attachments.

 Encrypt-OnlyDo Not Forward
Message body encryptedYesYes
Recipient can forwardYesNo
Recipient can copy or printYesNo
Office attachments after downloadDecrypted for Microsoft 365 recipientsStay encrypted
PDF and image attachmentsCan be downloaded unencryptedCan be downloaded unencrypted
Best forSensitive information the recipient may legitimately need to pass onInformation that must stay with one named person

The nuance worth remembering: Do Not Forward keeps Word, Excel and PowerPoint attachments protected even after they’re downloaded, because those file formats understand Microsoft’s rights management. PDFs and images do not — under either option, they can be saved out in the clear. If a PDF genuinely must stay locked, protect the file itself with a password before attaching it rather than relying on the email setting.

Method 2: S/MIME Encryption (Certificate-Based)

S/MIME is the older, standards-based approach, and it works differently in an important way: the encryption happens on your device using certificates, not on Microsoft’s servers. That makes it genuinely end-to-end, which is why regulated industries and government still specify it. The price is real setup friction — both sides need a certificate, and you need the recipient’s public certificate before you can encrypt anything to them.

Set up S/MIME in new Outlook
  • Go to Settings → Mail → S/MIME.
  • Select Import and choose your .pfx certificate file.
  • Enter the password you set when you downloaded it.
  • Choose whether to sign and encrypt by default.
Set up S/MIME in classic Outlook
  • Import the .pfx file into Windows first.
  • Go to File → Options → Trust Center.
  • Select Trust Center Settings → Email Security.
  • Under Certificates and Algorithms, Choose your certificate.

Once it’s installed, encrypting is the same gesture as before — the Options tab gains Encrypt and Sign toggles for the message you’re writing. The catch is that Outlook needs the recipient’s public certificate in order to encrypt to them; without it, the send fails.

💡
New in mid-2026: the new Outlook for Windows had no S/MIME support at all for a long stretch, and a great deal of advice online still says so. That changed in May and June 2026, when Microsoft rolled out two features that closed the gap: storing S/MIME certificates directly in Contacts (certificates saved in classic Outlook carry over automatically), and LDAP directory lookup for finding external recipients’ public certificates, configurable under Settings → Mail → S/MIME. If you postponed moving to the new Outlook because of S/MIME, it’s worth re-testing.
Which one should you actually use?
For almost everyone, Purview Message Encryption. It reaches any recipient on any provider with zero preparation, and the recipient experience is far gentler. Choose S/MIME only when a regulator, a contract, or a security team specifically requires end-to-end encryption with certificates — and when you have the administrative capacity to issue and renew certificates for everyone involved.

Method 3: Encrypting from Outlook.com (Personal & Family)

If you’re on a personal Outlook.com, Hotmail or Live address, encryption is available — but only with a Microsoft 365 Personal or Family subscription attached to the account. A free Outlook.com account has no encryption option, and neither does Microsoft 365 Basic.

How to encrypt
  • Compose a new message in Outlook.com.
  • Open the Options ribbon.
  • Select Encrypt.
  • Choose Encrypt or Do Not Forward.
What’s different
  • Two options only — no custom labels.
  • No admin console, reporting or audit trail.
  • No revoke or expiry.
  • Recipients on Gmail or Yahoo can authenticate with that account.

What the Recipient Actually Sees

This is worth understanding before you send anything important, because the experience varies a great deal — and an external recipient who wasn’t expecting a portal link may simply assume your message is phishing and delete it.

Recipient’s setupWhat happens
Same Microsoft 365 organisationThe message opens directly in Outlook, decrypted automatically. They may not even notice it was encrypted, beyond a small banner noting the restrictions.
Different Microsoft 365 tenantUsually opens directly in their Outlook, with restrictions applied. Occasionally routes through the portal instead.
Outlook.com personal accountOpens in Outlook.com or the Outlook mobile app after signing in with their Microsoft account.
Gmail or YahooReceives a notification email with a link. They can sign in with their existing Google or Yahoo account, or request a one-time passcode.
Any other providerReceives a notification email and reads the message in the Microsoft encryption portal using a one-time passcode sent by email.

Because the passcode arrives in the same inbox as the notification, this protects against interception in transit rather than against someone who already has access to the recipient’s mailbox. It’s the right trade-off for the vast majority of business email, but it’s worth knowing what it is.

💡
Tell external recipients it’s coming. If you’re sending an encrypted message to a client for the first time, a quick heads-up in a separate ordinary email prevents the single most common failure: a legitimate encrypted message being reported as phishing because it arrived as an unexpected “click here to view a secure message” link.

What Outlook Encryption Does Not Protect

Encryption is genuinely strong on the things it covers. The problems come from assuming it covers more than it does.

The subject line is not encrypted. This is the single most important limitation and it surprises almost everyone. Anyone who intercepts the message — or simply glances at the recipient’s notification pane — can read the subject in plain text. Never put a patient name, case reference, account number or diagnosis in the subject of an encrypted email.
Metadata stays visible. Sender, recipients, timestamps and message size all travel unencrypted. The fact that you emailed a particular lawyer at a particular moment is itself information, and encryption doesn’t hide it.
It can’t undo a wrong recipient. Encryption protects the message from third parties — it does nothing about sending confidential material to the wrong person, who can then simply authenticate and read it. If that happens, see our guide on whether deleting an email in Outlook unsends it, because deleting from Sent Items will not help.
Screenshots defeat Do Not Forward. Rights management blocks forwarding, copying and printing inside compliant applications. It cannot stop a recipient photographing the screen. Treat these controls as guard rails against accident, not as a defence against a determined recipient.
Non-Office attachments leak. As covered above, PDFs and images can be downloaded unencrypted even under Do Not Forward. Password-protect the file itself if it genuinely must stay locked.

Why the Encrypt Button Is Greyed Out or Missing

If you’ve reached this far and the button still won’t work, run through these in order. They’re arranged by how often each one turns out to be the actual cause.

1
Your plan doesn’t include it. By a wide margin the most common cause, and the one people check last. Compare your subscription against the licensing table above — Business Standard, Business Basic and E1 all look like plans that should include encryption, and none of them do.
2
The licence isn’t assigned to you specifically. Encryption is a per-user licence. Your organisation can own the right subscription while your individual account has never been assigned one. An admin can confirm this in the Microsoft 365 admin centre in under a minute.
3
Your client hasn’t synced the entitlement. If the licence was assigned recently, Outlook may not have caught up. Sign out completely, close Outlook, reopen and sign back in. This resolves a surprising share of cases and costs nothing to try.
4
Rights management isn’t enabled on the tenant. Purview encryption depends on Information Rights Management being switched on for your organisation. Microsoft publishes a step-by-step troubleshooting sequence for admins to verify and enable it.
5
It works on the web but not the desktop. A classic symptom of an add-on licence such as Azure Information Protection Plan 1 that hasn’t propagated to the desktop client. Test in Outlook on the web first — if it works there, the entitlement is correct and the problem is client-side.
6
Your admin has deliberately disabled it. Some organisations hide the Encrypt button by policy so that everyone uses published sensitivity labels instead. If your colleagues can’t see it either, this is likely — check whether you’re expected to use a label such as Confidential rather than the Encrypt button.
Managing Microsoft 365 email settings for a team?

Encryption is one of several settings that only behave consistently when applied centrally rather than device by device. The same is true of signatures — see our guide to Office 365 email signature management for how server-side deployment works, or browse our free email signature templates.

Frequently Asked Questions

Compose a new message, open the Options tab on the ribbon, and select Encrypt. Choose Encrypt-Only to protect the message and its attachments, or Do Not Forward to also prevent the recipient forwarding, copying or printing it. Then write and send as normal. In the Outlook mobile apps, tap the three-dot menu in the compose view and choose Set permissions instead. The setting applies to that single message, and attachments inherit the protection automatically.

Almost always a licensing issue rather than a setting. Microsoft Purview Message Encryption is included with Microsoft 365 Business Premium, E3 and E5, and Office 365 A and G plans — but not with Business Basic, Business Standard, Office 365 E1, or Exchange Online plans on their own. Those require an Azure Information Protection Plan 1 add-on. If your plan does qualify, check that the licence is assigned to your individual account, then sign out of Outlook and back in so the client picks up the entitlement. If it works in Outlook on the web but not on the desktop, the entitlement is correct and the issue is client-side.

Not with Microsoft’s built-in encryption. A free Outlook.com account has no Encrypt option, and Microsoft 365 Basic doesn’t include one either — you need a Microsoft 365 Personal or Family subscription for personal accounts, or a qualifying business plan for work accounts. The free alternative is S/MIME, which is built into Outlook at no cost, but requires you to obtain a certificate and for your recipient to have one too, which in practice makes it impractical for casual use. Note that every email you send is already protected in transit by TLS at no cost — that just isn’t the same thing as encrypting the message itself.

No, and this catches out a great many small businesses. Despite the name suggesting a mid-tier plan, Business Standard does not include Purview Message Encryption. You have two routes: add an Azure Information Protection Plan 1 licence for each user who needs to send encrypted mail, or upgrade those users to Microsoft 365 Business Premium, which includes it as standard. For a practice or firm where only two or three people handle sensitive correspondence, the add-on is usually the cheaper option; where most of the team needs it, Business Premium often works out better and brings additional security features with it.

No. The message body and attachments are encrypted, but the subject line is not — it travels in plain text and is visible to anyone who intercepts the message, as well as in notification previews. This is the most consequential limitation of Outlook encryption and the one most people don’t know about. Never put identifying or sensitive detail in the subject of an encrypted email: no patient names, case references, account numbers, salary figures or diagnoses. Use something deliberately generic such as “Secure message regarding your account” and put every specific detail in the encrypted body.

Both encrypt the message body and attachments. Encrypt-Only stops there — the recipient can read it, then forward, copy or print it freely. Do Not Forward adds rights management that blocks those actions, and additionally keeps Word, Excel and PowerPoint attachments encrypted even after they’re downloaded. The important caveat is that PDFs and image files can be downloaded unencrypted under either option, and no setting can prevent someone photographing their screen. Use Encrypt-Only when the recipient may legitimately need to pass information on, and Do Not Forward when it must stay with one named person.

Yes, and this is a real strength of Purview Message Encryption over S/MIME. Your Gmail recipient receives a notification email containing a link to the encrypted message. They can then authenticate with their existing Google account, or request a one-time passcode sent to that same address, and read the message in Microsoft’s encryption portal in their browser. No Microsoft account and no software is needed on their side. S/MIME, by contrast, would require your Gmail recipient to hold a certificate of their own, which most people don’t.

Revoking an encrypted message is possible, but it needs Advanced Message Encryption, which is included only with Microsoft 365 E5, Office 365 E5 and Office 365 Education A5 — or as an add-on for E3. With it, you can revoke access to a message already sent and set an expiry date after which the message can no longer be opened. Because encrypted messages to external recipients are read through Microsoft’s portal rather than downloaded, revocation genuinely works on them, which ordinary message recall cannot do. On any lower plan, there is no revoke option, and standard Outlook message recall only works for unread mail inside your own organisation.

The Bottom Line

Encrypting an email in Outlook is three clicks: Options → Encrypt → pick an option. Everything that makes it feel difficult happens before that — working out whether your licence includes the feature at all, and which of three encryption technologies you’re actually using.

Check the licensing table first, because that resolves most cases in under a minute. Use Purview Message Encryption unless a regulator specifically requires certificates. Reach for Do Not Forward when information must stay with one person, and Encrypt-Only when it may need to travel. And whichever you choose, keep the subject line generic — it’s the one part of the message encryption never covers.