Privacy & GDPR

Encrypted email: what is and isn't possible

Encrypted email is email whose content has been made unreadable to anyone who isn't allowed to see it. In practice there are two kinds that often get mixed up: transport encryption (TLS), which protects your message in transit between server and device, and end-to-end encryption, where only the sender and the recipient can read the content. They protect against different things, and it's important to know what each does and doesn't do. Below we explain it calmly, so you know what to expect from encrypted email.

By the Mailflux team Published on

What is encrypted email?

Encrypted email means that your message is converted into a code that only becomes readable again with the right key. That way, anyone who intercepts the message can do nothing with it. The difference lies in where and between whom that encryption applies.

  • Transport encryption (TLS) protects your message while it's in transit, for example between your device and the mail server, or between two mail servers. This is the standard today at serious providers. The message is protected in transit, but on the servers themselves it's readable to the systems involved.
  • End-to-end encryption (E2E) goes further: the message is encrypted on the sender's device and only decrypted again on the recipient's. In transit and on the intermediate servers it's unreadable. Only you and your recipient can access it.

Both are called "encrypted email", but they solve a different problem.

Why it matters

For anyone working with confidential information, this distinction isn't technical nitpicking. A doctor, lawyer or accountant wants to know who can, in theory, read the content of a message. Transport encryption keeps eavesdroppers on the line out; it doesn't govern who can access it on the servers or at the recipient.

There's also a reassuring side. For the vast majority of everyday correspondence, transport encryption, combined with a reliable provider that hosts in Europe, is a solid foundation. Your message is protected in transit, and the provider doesn't scan your content for advertising. For truly special, highly sensitive content, an extra layer may be needed.

So it's not a question of "encrypted or not", but of "which encryption fits what I'm sending". Answering that question honestly prevents both false certainty and needless panic.

False certainty is the biggest risk here. Anyone who thinks "encrypted" automatically means "unreadable to everyone" might send sensitive content that's still readable on the servers or at the recipient. Conversely, you see people who out of fear no longer dare email anything, while transport encryption is perfectly adequate for most things. The truth lies in the middle: know what you're sending, know what protection you have, and choose deliberately when you need an extra layer.

How it works

Picture a letter you send. Transport encryption is like an armoured courier van: no one can get to your letter along the way. But at the sorting centre and at the recipient, the envelope is opened. End-to-end encryption is like a letter in a safe to which only you and the recipient have the key: even the courier and the sorting centre can't read it.

In email terms:

  1. With transport encryption the servers negotiate a secure connection (TLS). Your message travels encrypted, but is processed on the servers in readable form, for example to filter spam or deliver it. How exactly that works, you'll read in forced TLS and encrypted connections explained.
  2. With end-to-end encryption the sender and recipient have keys. The message is encrypted before it leaves your device and only decrypted at the recipient. That usually requires both parties to use the same method and exchange keys, which makes it less straightforward in daily use.

What to watch out for

A few common misunderstandings:

  • "Encrypted means no one can ever read along." That depends on the type. Transport encryption protects in transit, but not on the servers or at the recipient. Be precise about what you need.
  • "If I encrypt it, the recipient is protected too." Only with end-to-end, and then the recipient has to cooperate. With transport encryption, protection also depends on the recipient's provider.
  • Confusing encryption with the data location. Encryption says nothing about where your data is stored or under which law it falls. Both count separately. For the privacy side, see privacy-friendly business email.
  • Forgetting extra protection for highly sensitive content. For special personal data, ordinary email, even with transport encryption, isn't always enough. In that case, weigh up whether to use an extra secure channel.

And with Mailflux

Mailflux uses encrypted connections (TLS), so your messages are protected in transit between server and device. This takes place on European, GDPR-compliant hosting, where your content isn't scanned for advertising. For the vast majority of business and personal correspondence, that's a solid foundation.

What Mailflux doesn't offer is built-in end-to-end encryption; that's more honest than suggesting otherwise. If you work with content so confidential that only you and your recipient should ever be able to read it, then extra measures may be needed. If you're not sure what fits your situation, feel free to get in touch and we'll think along with you. Every plan further includes filtering against spam, phishing and malware, automatic backups and optional two-factor authentication. Read more about the basics in European email hosting on your own domain.

Ready to start?

Professional email on your own domain, hosted in Europe and GDPR-compliant. Request your mailbox with no obligation.

Get started

FAQ

Frequently asked questions

Is my email encrypted with an ordinary provider?

At serious providers, your message usually travels via an encrypted connection (TLS), so it's protected in transit. That's transport encryption, not end-to-end. On the servers and at the recipient, the message is in principle readable to the systems involved.

What's the difference between TLS and end-to-end encryption?

TLS protects your message in transit between servers and devices; on the servers it's readable. End-to-end encrypts the message from sender to recipient, so that even the intermediate servers can't read it. End-to-end offers more, but requires both sides to cooperate.

Do I need end-to-end encryption?

For ordinary correspondence, usually not: transport encryption with a reliable, European provider is a solid foundation. For highly sensitive content, an extra layer may be wise. If you're in doubt, get in touch so you make a fitting choice.