Google is rolling out a new client-side encryption system for Gmail enterprise users, marking a significant step forward in email security and interoperability. This update introduces end-to-end encryption (E2EE) that works across different email platforms, including non-Gmail services, with user-controlled keys.
A simplified encryption method for greater compatibility
Unlike S/MIME, which demands that users exchange and manage certificates, Google’s new method removes that barrier by relying on client-side encryption. This means that emails are encrypted on the sender’s device before being sent, and only the recipient can decrypt them, using their own access key.
Enterprise admins can now manage their own encryption keys, keeping data control firmly in the hands of the organization. This is a crucial shift for companies concerned about sensitive information being accessed by third-party providers.
Encryption even beyond the Gmail ecosystem
This updated system allows secure communication with recipients outside the Gmail network. Gmail users will receive encrypted emails directly in their inbox, while non-Gmail recipients are redirected to a secure, read-only version of Gmail where they can view the message.
For companies still using S/MIME, Gmail will adapt by sending encrypted emails via that standard, ensuring backward compatibility.
IT tools for greater protection
Google has introduced extra controls for IT teams, including the ability to enforce restricted Gmail viewing for external recipients—even if they’re Gmail users. This helps ensure that emails aren’t stored on unmanaged devices or third-party servers.
Additionally, new features like client-side encryption defaults, data loss prevention tools, classification labels, and AI-powered spam and phishing protection are being integrated to strengthen security further.