Gmail’s confidential mode looks like the answer to sending something sensitive by email. You set an expiry date, you can require an SMS passcode, and the recipient gets no forward, copy, print or download buttons.

It is genuinely useful. It is also widely misunderstood, and the misunderstanding matters — people use it for things it was never going to protect.

Described as of September 2026; check Google’s and Microsoft’s current documentation for the exact options.

What it actually does

When you turn on confidential mode (the padlock-and-clock icon in the compose window):

  • You set an expiry — anywhere from a day to several years. After that the recipient sees a message saying it has expired.
  • You can require an SMS passcode to open it.
  • The Gmail interface hides forward, copy, print and download.
  • You can revoke access early from your Sent folder.
  • Recipients outside Gmail don’t get the message itself — they get a link to a Google-hosted page.

For the common case — a document that shouldn’t sit in someone’s inbox for five years — that’s a real improvement over a normal email.

What it does not do

It is not end-to-end encrypted. This is the big one. The message is encrypted in transit and at rest the way all Gmail is, but Google holds the keys and can read the content. If your threat model includes Google, a subpoena served on Google, or a compromise of Google, confidential mode changes nothing. It is not comparable to Signal or to a tool where the server only ever holds ciphertext.

A screenshot defeats it completely. Removing the forward and download buttons is a user-interface restriction, not a cryptographic one. The recipient can screenshot it, photograph the screen with their phone, or retype it. Google says this plainly in its own help pages. Anyone who wants to keep the content, keeps it.

“Expiry” only covers Google’s copy. The message body lives on Google’s servers and the expiry withdraws access to it. It does not reach a screenshot, a copy pasted into a document, or anything the recipient saved while they had access.

The passcode is SMS. Better than nothing, and it does stop someone with only mailbox access. But SMS is interceptable and vulnerable to SIM swapping, and it means handing Google the recipient’s mobile number.

Attachments get the same treatment — same protections, same limits.

So when should you use it?

Use it when the risk is an old message sitting around, which is the usual risk:

  • a document that’s only relevant for a week;
  • something sent to a large personal mailbox that will never be cleaned out;
  • anything where you’d like the option to revoke access after the fact.

Don’t use it when:

  • the recipient might be hostile — the restrictions are advisory;
  • the content is a live credential — use something built for that, and change it after first use;
  • you need Google not to have it — that requires end-to-end encryption, which this isn’t;
  • you need proof of who opened it, beyond the passcode.

The Outlook equivalent

Microsoft 365 Message Encryption appears as Encrypt and Do Not Forward in the compose window, and behaves much the same: Microsoft can access the content, restrictions are enforced by the client, and screenshots still work. The honest summary for both is identical — good against sprawl, weak against a determined recipient, no protection from the provider.

If you need the stronger version

The pattern behind all of this is: the message should be readable by the right person, for a limited time, and I’d like to take it back. Email platforms give you a partial version because the content lives on their servers, in a form they can read.

For a one-off secret, a one-time link gets you closer — with the caveat that link previews and mail scanners can spend the single view (One-Time Secret Alternatives compares them).

For an organisation, WaxSeal takes the other approach. The secret is encrypted on the sender’s device for the chosen recipients’ devices, whose keys live in the Secure Enclave; the vault holds ciphertext it cannot read; and what you send is an ordinary photo carrying only an invisible reference, which survives the compression of WhatsApp, WeChat or email. There’s no link to preview or scan, and a forwarded photo opens for nobody else. The sender sets burn-after-reading, an expiry, or a PIN given by phone, and can revoke it — after which the photo is just a photo.

The same honest limits apply as to everything above: revoking ends further authorised opening, it cannot un-show what somebody already read, so you still rotate a credential you no longer trust. Both sides need the app, sending to others happens inside a team workspace (recipients are free), and it carries text, not documents.

The one-line version

Gmail confidential mode is a good expiry and clean-up feature and a poor secrecy feature. Use it to stop sensitive email piling up in other people’s mailboxes — and never assume it hides anything from Google, or from a recipient with a phone camera.

Frequently asked questions

Is Gmail confidential mode end-to-end encrypted?
No. Messages sent in confidential mode are encrypted in transit and at rest like any Gmail message, but Google holds the keys and can access the content. It protects the message from lingering in the recipient’s mailbox, not from Google or from a lawful request to Google.
Can someone screenshot a Gmail confidential mode email?
Yes. Confidential mode removes the forward, copy, print and download buttons in the Gmail interface, but it cannot stop a screenshot, a photo of the screen, or someone simply retyping the text. Google’s own documentation says as much. Treat it as a guard against accidental spread, not against a determined recipient.
Does the SMS passcode option make it secure?
It helps against the wrong person opening the message, because they need the recipient’s phone as well as their mailbox. It is weakened by the fact that SMS can be intercepted or redirected by SIM swapping, and you have to know the recipient’s mobile number. It’s worth turning on, but it is not strong authentication.
What is the Outlook equivalent of Gmail confidential mode?
Microsoft 365 Message Encryption, offered as ‘Encrypt’ and ‘Do Not Forward’ when composing. The trade-offs are much the same: Microsoft can access the content, the restrictions are enforced by the client rather than by cryptography, and screenshots still work.

StegoSafe hides AES-256-encrypted secrets inside ordinary photos — in a deniable format with no header or marker — and can split them across several photos with Shamir Secret Sharing. Runs fully offline on iPhone, iPad and Mac; one universal purchase. For organisations that must send a secret and control it afterwards, see WaxSeal

Get StegoSafe →