Good to know
1. The three kinds of email encryption
Transport encryption (TLS) — already on, automatic
End-to-end encryption (E2EE) — only you and the recipient can read it
At-rest encryption — your inbox is encrypted on the server
2. Which one do you actually need?
- Casual privacy from random snoops on Wi-Fi: TLS is enough. You already have it.
- Privacy from your email provider (no Google reading your mail to train AI or target ads): switch to a provider that uses E2EE by default — Proton Mail or Tutanota.
- Sending one specific sensitive message to one specific person: PGP between two clients, or a Proton Mail 'Password-protected message' (works to any recipient).
- Meeting a compliance requirement (HIPAA, legal, financial): your organisation usually mandates a specific tool — ask, don't improvise.
3. The easy path: switch to a privacy-first provider
Good to know
4. Setting up Proton Mail (10 minutes)
- Go to proton.me and create a free account. Pick a username and a strong password. Write the password down somewhere safe — Proton can't reset it for you, because they don't know it. That same property is what makes the encryption real.
- Verify your account via email or SMS, then download the Proton Mail app for your phone (App Store or Play Store) and the desktop bridge if you want to use Outlook or Apple Mail with it.
- Set up a recovery method (recovery email, recovery phone, or recovery file). This is the only way back into your account if you forget your password — set it up now while you remember.
- Send a test email to a friend. If they're also on Proton, you'll see a small purple padlock — that means end-to-end encrypted. If they're on Gmail, the message goes via TLS by default. To make a single email to a non-Proton user E2EE, click the lock icon at the bottom of the compose window and set a password (and a hint).
- Migrate your old email using Proton's free Easy Switch tool — it imports messages and contacts from Gmail, Outlook, or Yahoo without you setting up anything technical.
Good to know
5. The harder path: PGP with your existing inbox
Important
Practical PGP options
- Mailvelope — free browser extension that adds PGP to webmail
- GPG Suite — macOS, integrates with Apple Mail
- Thunderbird — built-in PGP since version 78
- FlowCrypt — Gmail-focused
6. What encryption can't protect
- Subject lines. PGP doesn't encrypt the subject. Proton-to-Proton mail does. If you're using PGP, keep sensitive details out of the subject line.
- Metadata. The sender, recipient, time sent, and attachment names are visible to your email provider and any provider in between. Encryption hides what you said, not who you said it to.
- The endpoints. If your phone or laptop is compromised, encryption is irrelevant — the attacker reads the message after it's decrypted on your screen.
- The recipient's choices. If you send an encrypted message and the recipient screenshots it, prints it, or forwards it in plain text, your encryption did its job — they undid it.
Quick reference: what to do this week
- Want better default privacy? Open a free Proton Mail account and use it for new sign-ups going forward. Keep your existing Gmail for noise.
- One specific sensitive message to send? Set up Proton Mail and use a password-protected message (works to any recipient).
- Regularly send sensitive material to specific people? Agree on PGP with them and set up Mailvelope or Thunderbird at both ends.
- Want full E2EE by default with no thinking required? Move to Proton Mail or Tutanota and ask the people you correspond with most to do the same.
Was this guide helpful?
Know someone who needs this? Send them the guide.
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers