Warning
Care should be taken when sending sensitive information in email. Message Encryption is best suited for one time or occasional sharing. You are still responsible for ensuring information is only shared with appropriate parties. If you routinely share sensitive information with an authorized external entity, Message Encryption may not be the best solution. Contact your local support or OIT Security for further guidance or if you have any questions.
There are three levels of message protection.
-
Encrypt-Only: This option encrypts the email content, ensuring that only the intended recipients can read it. However, it does not impose any additional restrictions on what recipients can do with the email once they receive it.
-
Do Not Forward: This option not only encrypts the email but also restricts recipients from forwarding, printing, or copying the email content. This helps maintain the confidentiality of the information by preventing it from being shared beyond the intended recipients.
-
Encrypt: This option offer enhanced security over "Encrypt-Only" using S/MIME (Secure/Multipurpose Internet Mail Extensions) encryption. It converts the email content into scrambled cipher text, which can only be decrypted by recipients who have the corresponding private key.
The main advantage of using the “Encrypt” option over “Encrypt-Only” is the level of security and compatibility it provides:
-
Enhanced Security: The “Encrypt” option typically uses S/MIME (Secure/Multipurpose Internet Mail Extensions) encryption, which provides a higher level of security by converting the email content into cipher text. This ensures that only recipients with the corresponding private key can decrypt and read the email.
-
Digital Signatures: S/MIME encryption can also include digital signatures, which verify the sender’s identity and ensure that the email content has not been tampered with during transmission.
-
Compatibility: S/MIME is a widely accepted standard for email encryption and is supported by many email clients and services. This can make it easier to securely communicate with recipients using different email platforms.
In contrast, the “Encrypt-Only” option provides encryption but does not offer the additional security features and compatibility benefits of S/MIME. It is generally simpler to use but may not be as robust in terms of security.
From the new message draft window, click the "Options" tab.

Next, click on the "Encrypt" button to enable encryption.

To select another encryption option, click on the drop down arrow on the Encrypt button. This allows select betweening "Encrypt-Only" (default) and "Do Not Forward".

Outlook indicates the message will be protected. Click Send as usual when you are ready to send the message.

The process to send an encrypted message in Outlook for Web differs depending on what you see when drafting a new message.
Overflow Menu
From the new message draft window, if you do not see a button labelled "Encrypt" in the menu bar, you need to navigate into the overflow menu. Click the 3 dot icon "...", select "Encrypt" and then choose "Encrypt" or "Do Not Forward".
If you choose "Encrypt" the message is encrypted. Recipients can share the email and any attachments with any third parties without restriction.
If you choose "Do Not Forward" the message is encrypted and additional protections prevent the recipients from forwarding the email message to others. Recipients can still reply to your email. Microsoft file format attachments (such as Word documents and Excel spreadsheets) are protected and remain encrypted even if downloaded. Non-Microsoft specific file formats, including PDF documents and image files, are not protected once downloaded and can be shared by the recipient without restriction.
Exercise caution when sending sensitive file attachments with either option.

Encrypt Button
If you see an "Encrypt" button, you can click it to enable message encryption.
Step 1
Click "Encrypt".

Step 2
The message is marked for protection using Office Message Encryption. However, recipients can share the email and any attachments with any third parties without restriction.
To disallow recipient forwarding of the message in addition to encryption, click "Change permissions".

Step 3
Click the drop down in the pop-up window:

Select "Do Not Forward":

Click "OK":

Step 4
The message remains encrypted and additional protections prevent the recipients from forwarding the email message to others. Recipients can still reply to your email. Microsoft file format attachments (such as Word documents and Excel spreadsheets) are protected and remain encrypted even if downloaded. Non-Microsoft specific file formats, including PDF documents and image files, are not protected once downloaded and can be shared by the recipient without restriction.The new message draft window indicates the protection status at the top.
Click send as usual when you are ready to send the message.
