Is Gmail Confidential Mode Actually Secure?

The short answer
Gmail Confidential Mode is not end-to-end encrypted. It prevents forwarding, copying, and printing, and lets you set an expiration date — but Google's servers still process the message content. A recipient can photograph or screenshot the email at any time. Use it to limit casual sharing, not to protect genuinely sensitive data.
Gmail Confidential Mode is not end-to-end encrypted. It restricts forwarding and adds expiry, but Google can read the message and recipients can screenshot it.
On this page
- 01The short answer
- 02What confidential mode actually protects — and what it does not
- 03How the restrictions work in practice
- 04How to send a confidential mode email in Gmail
- 05How confidential mode behaves differently by platform
- 06What to do when confidential mode does not behave as expected
- 07A faster way: consistent control before the message leaves your outbox
"Is Gmail Confidential Mode actually secure?" is a reasonable question, and the feature name makes it harder to answer than it should be. The word "confidential" implies something close to end-to-end encryption — a message that only the intended recipient can read. That is not what Confidential Mode delivers.
Gmail introduced Confidential Mode to give senders a set of recipient-side controls: an expiration date, a block on forwarding and printing, and an optional SMS passcode for non-Gmail recipients. Those controls are real and in some situations genuinely useful. What they do not add is any cryptographic protection on the message itself. This post explains exactly what the controls cover, where they stop, and when Confidential Mode is still the right tool to reach for — and when it is not.
The short answer#
Gmail Confidential Mode is not end-to-end encrypted. Google's servers receive and process your message in the same way as any standard Gmail message. The feature adds recipient-side restrictions: it removes the forward, print, and download options from the recipient's Gmail interface, and it lets you set a date after which the message link stops working. It does not prevent Google from accessing the message content, and it does not prevent a recipient from capturing what they can see on their screen.
Three things Confidential Mode cannot do, regardless of how it is configured:
- Stop Google from processing the message. The message passes through and is stored on Google's infrastructure as normal. Both the sender's and recipient's copies are subject to Google's standard data handling.
- Prevent a recipient from capturing the content. A recipient can take a screenshot using their device's built-in tools, photograph the screen, or copy text using applications that operate outside the Gmail interface. No browser-based control can block this.
- Fully restrict non-Gmail recipients. Recipients on Outlook, Apple Mail, or any other client receive a link to a Gmail-hosted web view rather than the message body. If the SMS passcode option is not enabled, there is no additional verification step before the message loads.
What confidential mode actually protects — and what it does not#
The clearest way to evaluate Confidential Mode is to map it against specific threats. The table below shows where it helps, where the protection is only partial, and where it offers no protection at all.
| Threat | Does Confidential Mode help? | What actually covers it |
|---|---|---|
| Recipient forwarding the email via Gmail | Yes — forwarding is disabled in the Gmail interface | Confidential Mode is sufficient for this |
| Recipient printing from Gmail | Yes — the print option is removed from the Gmail interface | Confidential Mode is sufficient for this |
| Recipient copying and pasting the message text inside Gmail | Partial — copy is blocked inside the Gmail UI; system clipboard tools outside the interface are not restricted | Nothing prevents a copy made outside Gmail's own interface |
| Message access expiring after a set date | Yes — the Gmail-hosted link becomes inaccessible after the expiry date you set | Confidential Mode is sufficient for time-limiting access |
| Recipient taking a screenshot or photograph of the screen | No — this is outside Gmail's control entirely | No Gmail feature prevents this; it requires a separate trust arrangement with the recipient |
| Google reading the message content | No — the message is processed by Google's servers as a normal Gmail message | End-to-end encryption (S/MIME or a third-party encrypted mail service) |
| Message intercepted in transit | No — TLS protects the transport channel; Confidential Mode adds no end-to-end encryption | S/MIME, PGP, or a message-level encryption layer |
| Non-Gmail recipient reading via their own mail client | Partial — the message body is not embedded in the notification email; the recipient must follow a link to a web view | SMS passcode adds a verification step before the web view opens |
How the restrictions work in practice#
Think of Confidential Mode as a set of interface controls applied to the recipient's Gmail session, not as a lock on the message content itself. When a recipient opens a Confidential Mode email in Gmail, the forward, print, and download buttons are absent. The message text is still rendered in the browser — which means it is still visible, still capturable at the screen level, and still fully processed by Google on both ends.
For non-Gmail recipients the mechanism works differently. Gmail does not embed the message body in the notification email it sends. Instead, the notification contains a short prompt and a link to a Gmail-hosted web page where the recipient can read the message. If you enabled the SMS passcode option, the recipient must enter a code sent to their phone before the page loads — and a new code is sent each time they open the link.

How to send a confidential mode email in Gmail#
The steps below apply to Gmail on the desktop web interface. The Gmail mobile app follows nearly the same flow; differences by platform are covered in the table that follows.
- 1
Open a new message
Click Compose in Gmail. Write and address your email as you normally would. You apply Confidential Mode settings before you click Send, not before you write.
- 2
Click the lock icon in the compose toolbar
At the bottom of the compose window, click the icon labelled Turn on confidential mode — it shows a padlock overlaid with a clock face. If you do not see it immediately, look in the three-dot overflow menu at the right end of the toolbar row.
- 3
Set an expiration date
Choose when access to the message expires. The available durations are 1 day, 1 week, 1 month, 3 months, and 5 years. After the expiry date, the recipient's link to the message stops loading. Screenshots and copies already taken before that date are unaffected by expiry.
- 4
Choose a passcode setting
Select No SMS passcode if the recipient uses Gmail — they authenticate through their Google account before the message opens. Select SMS passcode if the recipient is on a non-Gmail address, then enter their phone number on the next screen. Gmail sends them a one-time code each time they open the message link.
- 5
Save the settings, then send
Click Save. The compose window shows a Confidential Mode banner confirming the settings are active. Send the message as normal. Non-Gmail recipients receive a notification email with a link rather than the message body directly in their inbox.
How confidential mode behaves differently by platform#
The sender experience is consistent across Gmail surfaces. The recipient experience depends on which client they use to open the message and how their organisation's Workspace account is configured.
| Scenario | What the recipient sees | Restrictions enforced |
|---|---|---|
| Gmail web — both parties on Gmail | Normal email view with a Confidential Mode banner and expiry date displayed | Forward, print, and download buttons removed from the Gmail interface |
| Gmail mobile app (iOS or Android) | Same as Gmail web, with the Confidential Mode banner and expiry indicator | Same interface restrictions apply; device-level screenshot tools are not affected |
| Google Workspace recipient | Same as consumer Gmail | Workspace admins can disable Confidential Mode at the organisation level — check with IT if messages are not being received as expected |
| Non-Gmail recipient (Outlook, Apple Mail, etc.) | A notification email containing a link; the message body is not in the raw email that arrives in their inbox | SMS passcode gates access to the web view; interface copy controls apply on that hosted page |
| Non-Gmail recipient, SMS passcode not enabled | Same notification email and web view link, but no passcode is required to open the page | Interface controls apply on the web view; no additional authentication step before the message is readable |
What to do when confidential mode does not behave as expected#
Several failure modes come up regularly when users rely on Confidential Mode for sensitive communications.
The recipient says they received an empty or blocked email. Non-Gmail recipients receive a notification email containing only a link, not the message body. Some corporate mail filters, security gateways, or older mail clients strip or block external links, making the notification appear blank or unclickable. Ask the recipient to open the email in a standard web browser and click the View email button from there.
The SMS passcode never arrives. Verify that the phone number includes the correct international dialling code. Carrier filtering occasionally blocks automated SMS messages, particularly from numbers associated with large cloud providers. Ask the recipient to wait a few minutes and try opening the link again, which triggers a new code. If the problem persists, you can resend the email without the SMS passcode option to confirm the link itself is working, then add it back.
The message is still accessible after the expiry date. Expiry propagation can take a few minutes across Google's infrastructure, so a small delay is expected. If the message remains accessible well past the expiry date, check the Sent folder entry — a Confidential Mode banner with the expiry date should be visible. If it is not, the settings may not have saved correctly before you sent.
Confidential Mode is greyed out or absent from the compose toolbar. Google Workspace administrators can disable the feature at the organisation level. If you cannot access it, contact your IT department or Workspace admin to confirm whether it has been turned off for your account.
Screenshots are outside Gmail's control
A faster way: consistent control before the message leaves your outbox#
Confidential Mode addresses what a recipient can do with a message after it arrives. It does not change what happens on the sender's side: the message is composed and processed on Google's infrastructure, it sits in your Sent folder with no cryptographic protection on the content, and there is no record of what happened to it after delivery.
If you send sensitive material regularly — contracts, client decisions, internal information with limited distribution — the more durable approach is a client that puts controls at the composition stage: who approves a draft before it sends, what the AI is authorised to do on your behalf, and what audit trail exists for every action. We build AI Emaily, an AI-native email client with Copilot mode where you approve every AI action before it runs, a full audit log, and a privacy model that does not train on your email content. A 7-day free trial is available at aiemaily.com — see aiemaily.com/pricing for what each tier includes.
Frequently asked
See it in AI Emaily
Keep reading

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.