Setup checklist#
- ☐ Enforce TLS 1.2+ on inbound and outbound connections.
- ☐ Publish MTA-STS to prevent downgrade attacks.
- ☐ For regulated content, use S/MIME or a secure-message portal with recipient authentication.
- ☐ Log and report TLS failures via TLS-RPT.
Audit checklist#
- ☐ Confirm you are not: assuming 'encrypted' in Gmail means end to end; it usually means TLS in transit.
- ☐ Confirm you are not: deploying S/MIME without a certificate lifecycle plan.
Ongoing monitoring#
- ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
- ☐ Monthly: re-run the setup verification after any vendor or DNS change
- ☐ Quarterly: full audit against this checklist
Frequently asked questions#
Is Gmail encrypted?
Gmail uses TLS in transit and encryption at rest. End-to-end encryption requires S/MIME (Workspace Enterprise) or client-side encryption.