4 min read

Enhance your email security: how to encrypt email in Outlook

Posted by Frank Horenberg on 1st May 2025

Enhance your email security: how to encrypt email in Outlook image

Think your Outlook emails are secure? Think again. Default settings provide basic security, but don’t offer adequate protection for sensitive information.

To encrypt an email in Outlook, you have several options:

  1. For basic protection: use TLS encryption (enabled by default)
  2. For stronger security: enable S/MIME encryption via Settings > Mail > S/MIME
  3. For Microsoft 365 users: use OME by clicking Options > Encrypt when composing emails
  4. For complete protection: integrate a third-party solution like Zivver with your Outlook

Find out which type of Outlook email encryption you need and how to keep your most sensitive information safe.

How does Outlook email encryption work?

When you send an unencrypted email, it travels across multiple servers in plaintext – readable to anyone with access to those servers. When you send an encrypted email, the content is scrambled during transmission, becoming readable only when the recipient uses the correct "key" that converts it back to plain text.

Comparison Graphic Outlook

Types of email encryption in Outlook

Outlook email encryption falls into two main categories:

  1. Native options built into Microsoft's ecosystem
  2. Enhanced solutions that fill critical security gaps

While Microsoft's built-in encryption provides rudimentary protection, organizations with compliance requirements or sensitive data need robust safeguards that incorporate business email encryption capabilities.

Protect data, prove compliance, and prevent leaks with Zivver’s Outlook  security integration.

  1. Native Outlook email encryption options:
    - Transport Layer Security (TLS)
    - S/MIME (Secure/Multipurpose Internet Mail Extensions)
    - Microsoft 365 Message Encryption (OME)
  2. Enhanced Outlook email encryption solutions
    - Third-party integrations that provide superior security, such as zero-knowledge encryption

A closer look at Outlook email encryption

Transport Layer Security (TLS)

TLS is the most basic form of Outlook email encryption. It encrypts the connection between email servers, not the email itself. It's similar to how websites use HTTPS to secure your browsing.

How to use it: TLS is enabled by default in Outlook, so requires no additional action from users.

Benefits:

  • Works in the background
  • No learning curve for employees
  • No impact on the recipient's experience

Limitations:

  • Vulnerable to man-in-the-middle attacks
  • No protection once the email reaches its destination
  • No verification that emails reach the intended server

S/MIME Encryption

S/MIME provides stronger protection than TLS. It uses digital certificates to verify sender identity and encrypt message content.

How to use it:

  1. Get your digital certificate (from IT or a certificate authority)
  2. Install it on your computer
  3. Configure S/MIME in Outlook:
    - Select Settings > Mail > S/MIME
    - Select Encrypt contents and attachment for all messages I send
    - Select Add a digital signature to all messages I send
    - Select Automatically choose the best certificate for digital signing (if available)
  4. Once configured, your encryption will work behind the scenes to protect your correspondence

Note: New Outlook doesn't automatically import digital certificates. You must install the certificate manually or ask your administrator.

Benefits

  • End-to-end encryption of message content
  • Digital signature verification
  • Better protection than TLS alone

Limitations

  • Both the sender and recipient must have S/MIME certificates installed
  • Complex setup process
  • No protection for forwarded emails

Office 365 Message Encryption

OME comes with Microsoft 365 subscriptions and offers a more user-friendly approach to Outlook email encryption.

How to use it:

  1. Ensure your admin has enabled OME for your organization
  2. Create a new email
  3. In Outlook desktop:
    - Click Options > Encrypt > Encrypt-Only or Do Not Forward
  4. In Outlook Web:
    - Click Encrypt button at the top of the compose window
    - Choose Encrypt-Only or Do Not Forward

Benefits:

  • Works with recipients on any email platform
  • No certificate management necessary
  • Easy to use

Limitations:

  • Requires Microsoft 365 subscription
  • Microsoft holds encryption keys
  • Limited to 25MB attachment size

Enhanced Outlook email encryption with Zivver

Zivver provides comprehensive encryption that addresses the limitations of native Outlook options. It integrates seamlessly with Outlook to providezero-knowledge encryption, prevent human error, and support compliance.

How to use it:

  1. Install the Zivver add-on for Outlook (typically deployed by IT)
  2. When composing an email containing sensitive information:
    - The Zivver sidebar will appear in your Outlook window
    - Toggle encryption on with a single click
    - Optional: set additional security like two-factor authentication or message expiration
  3. Send your email as normal

Features:

  • Zero-knowledge encryption
  • Multi-factor authentication for recipients
  • Large file transfers (up to 5TB)
  • Message recall capabilities
  • Compliance with regulations like GDPR, HIPAA, NIS2, and DORA

Zivver vs. Outlook native encryption: key differences

Features Table

When to use enhanced Outlook email encryption

While native Outlook encryption features may be sufficient for routine communications, you should deploy enhanced email encryption software in these scenarios:

  1. When handling data subject to regulations like GDPR or HIPAA
  2. For financial or legal communications containing confidential information
  3. When sharing large sensitive files that exceed Outlook's 25MB limit
  4. For industries with specific compliance requirements, such as healthcare, finance, legal, government etc.
  5. When communicating with external parties who may not have compatible encryption systems

Do you need enhanced email encryption?

Flow Chart

FAQ: Outlook email encryption

Is Outlook email secure without encryption?
No. Standard emails can be intercepted and read by unauthorized parties.

Does Outlook encrypt emails by default?
Outlook uses TLS when available, but this only secures the connection, not the content. Full encryption requires additional steps.

Can I encrypt attachments in Outlook?
Yes, encrypting an email also encrypts its attachments. However, size limitations apply.

Can I recall an encrypted email in Outlook?
Yes, but you can only do so in Outlook on the web and Outlook for Windows.

Do recipients need special software to read my encrypted emails?
It depends. With S/MIME, recipients need compatible certificates. With OME, external recipients use a web portal.

A smarter outlook on email security

Native Outlook encryption falls short where it matters most – leaving gaps in your email security that cybercriminals are all too ready to exploit.

For full protection, choose zero-knowledge business email encryption that has data loss prevention as a standard.

New call-to-action

Frank Horenberg avatar

Frank Horenberg

Published: 1st May 2025

Subscribe to our newsletter
Share this

Enjoy this article? Share the knowledge

Stay informed with Zivver

Subscribe to get more email security tips straight to your inbox.