Why can’t your email be as secure as your texts?

Most people take for granted that the messages they send via popular messaging apps like Meta’s WhatsApp or Apple’s iMessage are end-to-end encrypted (E2EE), meaning that no one but the sender and receiver—not even WhatsApp or Apple—can read the contents. Unfortunately, this rock-solid privacy-preserving encryption doesn’t extend to the other major type of messages we send: emails.
Not a one of the big four email providers—Google’s Gmail, Apple’s iCloud Mail, Microsoft’s Outlook, or Yahoo Mail—supports end-to-end encryption for personal accounts. Fortunately, if you do want E2EE protection for your emails similar to what you have for your texts, there are some email platforms that offer such robust privacy protections.
Why aren’t emails end-to-end encrypted?
If you have a personal email address ending in @gmail.com, @iCloud.com, @outlook.com, or @yahoo.com, the emails you send and receive are not end-to-end encrypted. However, it’s important to note that the email providers do use some encryption to protect your messages.
They do this in two ways, primarily: by encrypting your messages in transit between the sender, their servers, and the receiver, and by encrypting your emails at rest on their servers. However, this encryption isn’t end-to-end because email providers hold the encryption keys, meaning they could read your emails if they wanted or turn them over to government agencies if presented with a lawful court order. In the worst case, if an attacker stole the email platform’s encryption keys, they could possibly access all your emails and their contents.
On the other hand, with end-to-end encryption like that used by the world’s most popular messaging apps, the service provider does not have access to the encryption keys that unscramble the message to make it readable—only the sender and receiver do. This restriction is why end-to-end encryption provides superior privacy and security versus regular encryption.
The question that arises then is, why wouldn’t these email platforms just end-to-end encrypt your emails as they do with the messages in the popular messaging apps you use?
The answer is less conspiratorial than practical. Email is a decades-old technology, designed to work seamlessly across all services. If emails were encrypted end-to-end, email interoperability would break. It would be very hard, if not impossible, to send an email from, for example, a Gmail account to an iCloud account. End-to-end encrypted email would also have other drawbacks. Email services scan emails for signs of spam and phishing attempts. If those emails were end-to-end encrypted, the services wouldn’t be able to detect, quarantine, and block potential emails that are seeking to harm you.
Other useful features we’re used to, like search, would also be severely hindered. Currently, most of your emails don’t actually reside on your devices. The older ones are stored on the service’s servers. Yet you can still search for them by keyword to find that old email you need precisely because the service’s servers can read the content of your emails. E2EE emails would break this server-side ability, meaning that if you wanted to search through your thousands of old emails, you’d need to download all of them to your smartphone or laptop first.
Of course, sometimes it’s prudent to sacrifice convenience for privacy, and if you want your emails end-to-end encrypted, you do have some good options.
Trade iCloud, Gmail, Yahoo, and Outlook for these platforms
Since the early 1990s, a technology called Pretty Good Privacy (PGP) has allowed people to end-to-end encrypt their emails. However, using PGP is pretty complicated for the average email user, as it involves the manual management of encryption keys.
Thankfully, if you want end-to-end email encryption, you don’t need to manually mess with PGP—provided you are willing to switch email providers. In recent years, a number of companies have sprung up offering ready-to-use end-to-end encrypted emails. Two of the most popular are Proton Mail and Tuta Mail.
Both services are essentially the Signal of the email world. By that I mean that any emails sent from one Proton address to another Proton address, or one Tuta address to another Tuta address, are end-to-end encrypted by default, without your having to do anything.
However, there are some important limitations to these end-to-end encrypted email services. If you use either to send an email to an email address other than one ending with the E2EE address you are using (for example, sending an email from your Proton email account to someone with a Gmail email address, or even from a Proton email address to a Tuta email address), you will lose the protection of end-to-end encryption, as its transmission will default to standard email protocols. If the E2EE email service didn’t ditch the encryption in these instances, the recipient with the other email service wouldn’t be able to read the content of the message.
To get around this limitation, both Proton and Tuta allow you to send end-to-end encrypted emails to non-Proton and Tuta email addresses, respectively, via a secure online platform. Instead of seeing text in the body of the email, the Gmail or Yahoo Mail user, for example, will get a secure link. Clicking it takes them to a website where they can enter the password you provided them to decrypt your end-to-end encrypted message.
Should you switch to E2EE email?
So, should you switch to an end-to-end encrypted email platform? Most people would likely find the inconveniences too burdensome.
But if you want the most protection possible for your emails, Gmail, iCloud, Outlook, and Yahoo aren’t the services to use. In that case, E2EE email providers like Proton and Tuta are worth checking out.