Is Gmail Confidential Mode Actually Secure?
It sets an expiry and hides the forward button — but it is not end-to-end encrypted, Google can still read it, and a screenshot defeats it entirely.
Gmail’s confidential mode looks like the answer to sending something sensitive by email. You set an expiry date, you can require an SMS passcode, and the recipient gets no forward, copy, print or download buttons.
It is genuinely useful. It is also widely misunderstood, and the misunderstanding matters — people use it for things it was never going to protect.
Described as of September 2026; check Google’s and Microsoft’s current documentation for the exact options.
What it actually does
When you turn on confidential mode (the padlock-and-clock icon in the compose window):
- You set an expiry — anywhere from a day to several years. After that the recipient sees a message saying it has expired.
- You can require an SMS passcode to open it.
- The Gmail interface hides forward, copy, print and download.
- You can revoke access early from your Sent folder.
- Recipients outside Gmail don’t get the message itself — they get a link to a Google-hosted page.
For the common case — a document that shouldn’t sit in someone’s inbox for five years — that’s a real improvement over a normal email.
What it does not do
It is not end-to-end encrypted. This is the big one. The message is encrypted in transit and at rest the way all Gmail is, but Google holds the keys and can read the content. If your threat model includes Google, a subpoena served on Google, or a compromise of Google, confidential mode changes nothing. It is not comparable to Signal or to a tool where the server only ever holds ciphertext.
A screenshot defeats it completely. Removing the forward and download buttons is a user-interface restriction, not a cryptographic one. The recipient can screenshot it, photograph the screen with their phone, or retype it. Google says this plainly in its own help pages. Anyone who wants to keep the content, keeps it.
“Expiry” only covers Google’s copy. The message body lives on Google’s servers and the expiry withdraws access to it. It does not reach a screenshot, a copy pasted into a document, or anything the recipient saved while they had access.
The passcode is SMS. Better than nothing, and it does stop someone with only mailbox access. But SMS is interceptable and vulnerable to SIM swapping, and it means handing Google the recipient’s mobile number.
Attachments get the same treatment — same protections, same limits.
So when should you use it?
Use it when the risk is an old message sitting around, which is the usual risk:
- a document that’s only relevant for a week;
- something sent to a large personal mailbox that will never be cleaned out;
- anything where you’d like the option to revoke access after the fact.
Don’t use it when:
- the recipient might be hostile — the restrictions are advisory;
- the content is a live credential — use something built for that, and change it after first use;
- you need Google not to have it — that requires end-to-end encryption, which this isn’t;
- you need proof of who opened it, beyond the passcode.
The Outlook equivalent
Microsoft 365 Message Encryption appears as Encrypt and Do Not Forward in the compose window, and behaves much the same: Microsoft can access the content, restrictions are enforced by the client, and screenshots still work. The honest summary for both is identical — good against sprawl, weak against a determined recipient, no protection from the provider.
If you need the stronger version
The pattern behind all of this is: the message should be readable by the right person, for a limited time, and I’d like to take it back. Email platforms give you a partial version because the content lives on their servers, in a form they can read.
For a one-off secret, a one-time link gets you closer — with the caveat that link previews and mail scanners can spend the single view (One-Time Secret Alternatives compares them).
For an organisation, WaxSeal takes the other approach. The secret is encrypted on the sender’s device for the chosen recipients’ devices, whose keys live in the Secure Enclave; the vault holds ciphertext it cannot read; and what you send is an ordinary photo carrying only an invisible reference, which survives the compression of WhatsApp, WeChat or email. There’s no link to preview or scan, and a forwarded photo opens for nobody else. The sender sets burn-after-reading, an expiry, or a PIN given by phone, and can revoke it — after which the photo is just a photo.
The same honest limits apply as to everything above: revoking ends further authorised opening, it cannot un-show what somebody already read, so you still rotate a credential you no longer trust. Both sides need the app, sending to others happens inside a team workspace (recipients are free), and it carries text, not documents.
The one-line version
Gmail confidential mode is a good expiry and clean-up feature and a poor secrecy feature. Use it to stop sensitive email piling up in other people’s mailboxes — and never assume it hides anything from Google, or from a recipient with a phone camera.
Frequently asked questions
Is Gmail confidential mode end-to-end encrypted?
Can someone screenshot a Gmail confidential mode email?
Does the SMS passcode option make it secure?
What is the Outlook equivalent of Gmail confidential mode?
StegoSafe hides AES-256-encrypted secrets inside ordinary photos — in a deniable format with no header or marker — and can split them across several photos with Shamir Secret Sharing. Runs fully offline on iPhone, iPad and Mac; one universal purchase. For organisations that must send a secret and control it afterwards, see WaxSeal
Get StegoSafe →