| Email encryption makes the contents of a message unreadable without the right decryption access. Microsoft 365 already encrypts stored mailbox data and protects most connections with TLS, so the decision facing a business is usually about message-level protection. |
A client sends through a security questionnaire with one line on it: do you encrypt email containing our information? Or a lawyer asks on the phone, mid-job.
The answer depends on what the question means by email encryption. Protection while email travels between servers is a different thing from protection applied to an individual message, and your provider encrypts stored mailbox data as well.
This guide covers what each one protects, what Microsoft 365 supplies, and which one you are being asked for.
What Is Email Encryption?
Email encryption is the use of cryptography to make the contents of a message unreadable without the appropriate decryption access. Three separate layers get that name, and they coexist rather than compete.
| Protection | What it covers | What it does not establish |
|---|---|---|
| TLS | The connection carrying the message | Any continuing restriction after delivery |
| Provider storage encryption | Mailbox data held by the provider | That a signed-in account cannot read or forward the mail |
| Message-level protection | Content access under the selected policy | That every exported copy or attachment keeps the same restrictions |
This guide focuses on the two layers of email encryption you can act on: TLS in transit, and message-level encryption applied to a particular email. Storage encryption matters but is not something you configure.
Is Email Encrypted by Default?
Largely yes, and by more than most owners expect. Microsoft’s guide to the encryption options in Microsoft 365 says email data at rest is encrypted using BitLocker on the drives in its data centres, and that TLS protects mail connections.
That does not mean a given outgoing message carries message-level protection or any restriction on forwarding. What applies to a particular email depends on its route, your policies, and whether an encryption option was chosen when it was sent.
Neither layer prevents an authorised reader from passing on what they have read.
Is Email Encryption the Same as SPF, DKIM and DMARC?
No. Those three are domain authentication mechanisms, which help receiving systems spot unauthorised use of your domain. They do not encrypt message contents.
The mix-up is common because both get described as making email more secure. Our guide to email security best practices covers how the records work.

How Does TLS Encryption Protect Email in Transit?
TLS encrypts the connection between two mail servers so that anyone intercepting the traffic in between sees scrambled data rather than readable mail. Microsoft states that Exchange Online always uses opportunistic TLS by default, trying the most secure version first and working down until it finds one both servers accept.
The word doing the work in that sentence is opportunistic.
What Happens When the Receiving Server Does Not Support TLS?
It depends on whether a policy requires a secure connection. Where nothing does, Microsoft’s documentation on Exchange Online and TLS says Exchange sends the message without encryption if the recipient’s organisation does not support it.
Where a policy does require one, delivery can fail instead. Exchange Online validates outbound mail against the recipient domain’s MTA-STS policy automatically, as Microsoft’s guidance on outbound MTA-STS describes. An enforced policy that fails validation can return a non-delivery report instead.
Plain delivery is possible but not guaranteed. Confirm what the actual route does, particularly where another gateway handles your mail.
Can You Force TLS for a Particular Recipient?
Yes. Exchange Online can be configured to require TLS for mail to a named partner domain, which Microsoft calls forced TLS and recommends where compliance requirements demand it, such as medical, banking or government work.
It is an option where both organisations agree transport protection meets the requirement. It applies no restriction to the message once it arrives.
Plan for delivery failures and an alternative route first, because a certificate problem at the far end holds mail up rather than downgrading it.
What Is Message-Level Email Encryption?
Message-level email encryption protects the content of a particular message under the access rules of the system you choose, so the protection persists after delivery. This is the layer a business configures and applies.
TLS has nothing to say about a message once it has been delivered, and delivery is where most of a message’s life begins rather than ends.
How Does Microsoft Purview Message Encryption Work?
Microsoft Purview Message Encryption lets a user send a protected message to any address, including Gmail, Yahoo and Outlook.com accounts. Microsoft’s Purview Message Encryption documentation sets out more than one email encryption option: Encrypt Only encrypts the message while still allowing forwarding, and Do Not Forward adds restrictions on forwarding, copying and printing in the experiences that support them.
What the recipient sees depends on where they read it. Someone on a Microsoft 365 or Microsoft account opening it in a supported Outlook client sees it inline. Other recipients, including Gmail and Yahoo users, get a wrapper message pointing to a portal, where they sign in or use a one-time passcode sent to their address.
Choose the option that matches the information and what the recipient needs to do with it. Neither stops someone photographing a screen.
What Happens to Attachments and Shared Links?
Do not assume an attachment keeps its protection after download. Behaviour depends on the file type, the protection option and the configuration, so test the formats you send in practice.
A SharePoint or OneDrive link is separate again: it carries its own access permissions, and encrypting the email around it does nothing to the file at the other end.
When Would a Business Use S/MIME?
S/MIME suits a business where a counterparty or a regulator requires certificate-based protection, or where signing matters as much as encryption. Signing and encryption are separate capabilities, and an encrypted message is not necessarily a signed one.
The setup is what makes it a deliberate choice. To send an encrypted message the sender needs the recipient’s public certificate and the recipient needs the matching private key, so certificates must be issued and made available beforehand.
There is a second consequence. That same Microsoft guide notes that S/MIME does not allow encrypted messages to be scanned for malware, spam or policy, so those messages reach the mailbox unexamined.

Which Type of Email Encryption Does Your Business Need?
Most New Zealand businesses need TLS working reliably, with message-level email encryption available for mail that warrants it. The decision is driven by content, recipient and obligation rather than by a rule about addresses.
Work backwards from one question: what happens if this message is read by someone it was not meant for.
SEEMail and Secure Government Email come up often in New Zealand searches on this subject. Both secure mail between public sector agencies and their partners. A private business cannot join.
When Is TLS Sufficient on Its Own?
TLS may be sufficient for lower-sensitivity correspondence where your policies and any client agreements allow it. Scheduling, general account queries, routine internal mail.
For that category the work is confirming TLS is in use, not adding anything. It is a check on your mail flow rather than a purchase.
When Do You Need Message-Level Encryption?
Consider message-level email encryption when the content is sensitive, when disclosure would carry real consequences, or when an agreement specifies it. Payroll files, clinical notes, financial statements and identity documents reach that threshold for most businesses.
Check first that the recipient is entitled to the information and that email is the right channel. A file needing ongoing access control is often better handled through an approved portal or a restricted sharing link.
Encryption does not correct a wrong address, make an unauthorised disclosure acceptable, or help when the recipient’s own account is already compromised.
Rules can apply email encryption consistently rather than leaving it to memory, using defined recipients, sensitivity labels or detectable content, which is the same machinery behind data loss prevention. They need testing in both directions, for what a rule misses and what it catches unnecessarily.
What Does Email Encryption Cost in Microsoft 365?
For most businesses it is a licensing question rather than a new product. Microsoft’s Purview licensing guidance lists Message Encryption as included in Microsoft 365 Business Premium and in the Enterprise E3 and E5 tiers.
Business Basic and Business Standard do not include it on their own. Older guidance points those plans at an Azure Information Protection Plan 1 add-on, and that route is closed: Microsoft’s Azure Information Protection service description states the AIP P1 standalone offer has not been available to new customers since January 2024.
Check your existing entitlements and the options currently on offer before assuming an upgrade is the answer. Business Premium is an established route rather than an automatic recommendation.
The rest of the cost is work rather than licence fees: agreeing which messages need protection, configuring policies, testing recipient access and helping staff pick the option. Portal-based expiry and revocation sit in Advanced Message Encryption and need qualifying entitlements.
What Are the Downsides of Encrypting Email?
The main costs of email encryption are recipient friction, reduced inspection and limited control after sending. None is a reason to avoid message-level protection, but all three are reasons to scope it rather than apply it everywhere.
Recipient friction generates the support calls. A portal and a sign-in is more work than an attachment, and some recipients will ask you to send it another way, which defeats the exercise unless you have agreed that way in advance.
Inspection depends on the method. Encryption limits scanning where a security system cannot decrypt the content, which is the position with S/MIME message bodies. Rights-protected mail may still be inspected where the service has the access and configuration to do it, including an Exchange Online transport decryption setting. Check your mail route before deciding how widely to apply encryption.
Control after sending is narrower than people assume. Revocation belongs to Advanced Message Encryption, and Microsoft’s conditions for revoking an encrypted message are specific: it works on link-based branded messages delivered through the portal, requires a custom branding template to be in place, and does not apply where the recipient opened the message inline in Outlook on a Microsoft account.
Does the New Zealand Privacy Act Require Email Encryption?
No, not as a blanket rule. The Privacy Act 2020 does not name encryption or any other technology. Information Privacy Principle 5 requires an agency holding personal information to protect it by such security safeguards as are reasonable in the circumstances to take.
Reasonable in the circumstances is the whole test: the information, the recipient and the potential harm all bear on it. Encryption may form part of that protection, alongside checking who you are sending to and limiting what you send.
Our checklist on NZ Privacy Act compliance covers the wider obligation.
Client security questionnaires ask about email encryption directly, and a supplier agreement can turn your answer into a warranty.
How Do You Set Up Email Encryption That Keeps Working?
You set up email encryption by deciding which mail needs message-level protection, configuring the rules, and then checking the configuration still holds as the business changes. How long the first part takes depends on the number of rules and the number of recipients involved.
Start with a short list of the message types that matter, in business language not technical: payroll to the bureau, client files to the auditor, anything with identity documents.
Then decide whether staff apply protection or a rule applies it. Rules are more consistent and take longer to get right, because a rule that fires too often trains people to work around it, and staff still need to recognise what a rule misses.
Agree how recipients will recognise and open a protected message before you send anything sensitive. Test the common email clients, mobile access, shared mailboxes and your attachment types, and give recipients a known contact route so they can check an unexpected message rather than trusting a link that claims to be encrypted.
Keep it under review. Domains change, staff change, and a rule written for a payroll provider you no longer use protects nothing. Our email security services cover the management layer that keeps settings like these correct over time.
Get Email Encryption Set Up for the Mail That Matters
If a client has asked whether you encrypt email and you are not certain of the answer, resolve it before the next questionnaire arrives. Exodesk helps Christchurch, Dunedin and South Island businesses work out which messages need message-level protection, configure it in Microsoft 365, and keep it working.
Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.
Frequently Asked Questions
What is email encryption?
Email encryption makes the contents of a message unreadable without the appropriate decryption access. Three layers get called by that name: TLS protecting the connection between mail servers, provider encryption of stored mailbox data, and message-level encryption applied to a particular email. Only the last of those carries access rules that persist after delivery.
Is my business email already encrypted?
Largely yes: Microsoft 365 encrypts stored email data at rest using BitLocker and uses TLS to protect mail connections. What that does not give you is any restriction on what a signed-in recipient does with a message once they have it.
What is the difference between TLS and message-level email encryption?
TLS encrypts the connection between two mail servers and establishes nothing about the message after delivery. Message-level encryption protects the content under the access rules of the system you choose, so those rules still apply in the mailbox it reaches. Most businesses need both, used for different mail.
Does Microsoft 365 include email encryption?
The Microsoft licensing guidance lists Message Encryption as included in Microsoft 365 Business Premium and in the Enterprise E3 and E5 tiers. Business Basic and Business Standard do not include it on their own. The Azure Information Protection Plan 1 add-on that older guidance points to has been closed to new customers since January 2024. Check current entitlements before assuming an upgrade is needed.
How do I send an encrypted email in Outlook?
Compose the message, open Options, choose Encrypt, and select the protection option your organisation uses. Check the recipients and attachments before sending. Availability depends on your licence and configuration, so ask your IT provider if the option is missing.
Can the recipient read an encrypted email without a Microsoft account?
Yes. Depending on the service and the settings the sender chose, recipients can sign in with a supported account or use a one-time passcode sent to their email address. A separate Microsoft 365 subscription is not normally needed.
Is email encryption required under the New Zealand Privacy Act?
The Privacy Act does not impose a blanket email encryption rule. Principle 5 requires security safeguards that are reasonable in the circumstances, so the information, the recipient and the potential harm all bear on what is appropriate. Encryption may form part of that protection, alongside checking recipients and limiting what you send.
Can I unsend or revoke an encrypted email?
Only in specific circumstances. Advanced Message Encryption can revoke access to eligible external messages delivered through its portal, which requires a custom branding template. It does not cover messages opened inline in Outlook on a Microsoft account. It does not erase information already read or copied, and it is a different mechanism from Outlook message recall.
Is email encryption the same as SPF, DKIM and DMARC?
No. Those are domain authentication mechanisms that help receiving systems spot unauthorised use of your domain, and they do not encrypt message contents; they sit alongside email encryption rather than replacing it.
How do I get email encryption set up for my business?
Start by listing the message types that would cause a problem if read by the wrong person, then check what your current Microsoft 365 plan already includes. Exodesk configures email encryption for businesses in Christchurch, Dunedin and across the South Island, including the rules that apply it automatically.
NEXT STEP
Which of your emails would matter if somebody else read them?
Most businesses have never been asked to make that list, and the answer decides whether you need anything beyond what Microsoft 365 already gives you. An IT assessment establishes what protection is active on your mail today and where the gaps are, alongside the rest of your setup.
Or read more about our cyber security services.
