Workspace admins control SPF, DKIM, and DMARC from the Admin console, and inbound policy from the Gmail spam settings.
What email encryption is#
Email encryption protects messages in transit (TLS between servers, enforced by MTA-STS or DANE) and at rest or end to end (S/MIME, PGP, or portal-based encryption).
Why it matters#
Regulated data (health, financial, personal) requires protection in transit at minimum, and increasingly proof of it.
Setting up email encryption for Google Workspace#
- Enforce TLS 1.2+ on inbound and outbound connections.
- Publish MTA-STS to prevent downgrade attacks.
- For regulated content, use S/MIME or a secure-message portal with recipient authentication.
- Log and report TLS failures via TLS-RPT.
How Google Workspace reports results#
Open a delivered test message in Google Workspace and view the original or headers. Look for Authentication-Results and any provider-specific verdict headers. Use the provider's sender dashboard for aggregate reputation.
Common mistakes#
- Assuming 'encrypted' in Gmail means end to end; it usually means TLS in transit.
- Deploying S/MIME without a certificate lifecycle plan.
Frequently asked questions#
Is Gmail encrypted?
Gmail uses TLS in transit and encryption at rest. End-to-end encryption requires S/MIME (Workspace Enterprise) or client-side encryption.
Does Google Workspace require email encryption?
Workspace admins control SPF, DKIM, and DMARC from the Admin console, and inbound policy from the Gmail spam settings. Treat email encryption as required for any meaningful volume.