On Gmail’s 21st birthday, Google unveiled a groundbreaking update that enables enterprise users to send end-to-end encrypted (E2EE) emails to any recipient with just a few clicks. This feature, now available in beta, initially allows users to send encrypted emails within their organization, with plans to expand to all Gmail users in the coming weeks and eventually to any email address later this year.
What distinguishes this new encryption model from traditional Secure/Multipurpose Internet Mail Extensions (S/MIME) is its simplicity—neither senders nor recipients need specialized software or encryption certificates. As Google Workspace executives Johney Burke and Julien Duplant explained, “This capability abstracts away the traditional IT complexity and substandard user experiences of existing solutions, while preserving enhanced data sovereignty, privacy, and security controls.”
The technology leverages client-side encryption (CSE), which Google has already implemented across its Workspace suite including Calendar, Drive, Docs, and Meet. When an E2EE email reaches another Gmail user, the message automatically decrypts. For non-Gmail recipients, such as Microsoft Outlook users, the system sends an invitation to view the encrypted email through a restricted Gmail interface via a guest Google Workspace account.
Since CSE encrypts data on the client before transmission or storage in Google’s cloud, the content remains unreadable to third parties, including Google itself. Unlike traditional E2EE, however, CSE utilizes encryption keys generated and stored in a cloud-based management service, allowing organizational administrators to control keys, revoke access, and monitor encrypted files.
“This approach offers more comprehensive encryption protection,” noted Burke and Duplant. “It doesn’t matter who you send a message to or what email they’re using—your message will be encrypted and you maintain sole control with just one set of keys.”
The executives emphasized the solution’s simplicity: “It’s easy to implement and use, reducing friction for both IT teams and users. No one needs to be an encryption expert to make this work, saving teams time and money while delivering what everyone wants: email encryption that is painless and just works.”
