Encrypted Email Services Compared: What Each One Actually Hides (2026)
Encrypted email providers hide different things. Most hide the body and leave the subject line readable. Here is what each one actually covers, and what none of them cover.
Encrypted email is usually sold as a single feature, as though a provider either has it or does not. It is better understood as a question of coverage: how much of the message does the encryption actually reach?
Almost every provider encrypts the body. Far fewer touch the subject line. None of them encrypt away the fact that you and a particular correspondent exchanged mail at a particular time, and none of them place the provider outside the reach of a lawful order. Choosing well means knowing exactly which of those gaps you care about.
This guide compares what the mainstream encrypted providers actually cover, what a court can still obtain, and where encrypted hosting is the wrong purchase entirely. If your goal is a signup you never hear from again rather than confidential correspondence, a disposable inbox is the cheaper answer, and our comparison of Proton Mail and Gmail covers the mainstream-provider question in more depth.
Key takeaways
- Encrypted email providers differ mainly in how much of the envelope they cover. Most encrypt the body and leave the subject line readable.
- Tuta encrypts subject lines, sender and recipient names, bodies, attachments, calendars, and contacts, leaving only the addresses and send date exposed — the widest coverage of the mainstream options.
- PGP cannot encrypt subject lines at all, which is a structural limit of the standard rather than a shortcoming of any particular client.
- No provider encrypts metadata away entirely, and every provider in a real jurisdiction can be compelled to hand over what it holds — Proton logged a user IP under Swiss order in 2021.
- Encrypted hosting is the wrong tool for signup forms. If you never want to hear from a site again, a disposable inbox removes the data instead of protecting it.
The three encryption models
Providers fall into three groups, and the group determines what you get far more than the brand does.
Transport encryption is the baseline every mainstream provider uses. Mail travels between servers over TLS, so an observer on the network sees ciphertext. Both endpoints — your provider and the recipient's — hold the plaintext. Gmail, Outlook, and Yahoo work this way. It defends against interception, not against the providers themselves.
Zero-access storage encryption is what Proton Mail adds. Your mailbox is encrypted at rest with keys the provider does not hold, so Proton states it cannot decrypt end-to-end encrypted content under any circumstances. Incoming mail from outside is encrypted to your key on arrival. The provider is removed from the set of parties who can read your stored mail — a real change from the transport-only model.
End-to-end encryption is the strongest, and the most conditional. It requires both sides to hold keys, which is why it applies automatically only between users of the same provider, or between people who have deliberately exchanged PGP keys. Mail from an encrypted provider to an ordinary Gmail address is not end-to-end encrypted, because the recipient has no key. This is the single most misunderstood point in the category.
What each option actually encrypts
| Body | Subject line | Attachments | Contacts / calendar | Sender & recipient addresses | |
|---|---|---|---|---|---|
| Gmail / Outlook (TLS only) | Provider-readable | Provider-readable | Provider-readable | Provider-readable | Exposed |
| Proton Mail | Encrypted at rest, zero-access | Not encrypted | Encrypted | Encrypted | Exposed |
| Tuta | Encrypted | Encrypted | Encrypted | Encrypted | Exposed |
| PGP on any provider | Encrypted | Cannot be encrypted | Encrypted | Not covered | Exposed |
The subject-line column is the one that separates these options in practice. Tuta encrypts the subject line, sender and recipient names, body, attachments, calendars, and contacts, and states that the only data not encrypted is the email addresses themselves and the date sent or received. That is the widest coverage among the mainstream choices, and Tuta built its own protocol rather than adopting PGP specifically because PGP cannot encrypt subject lines, and because of the 2018 EFAIL vulnerabilities affecting S/MIME.
The cost of that choice is interoperability. A provider using its own protocol gives full protection only inside its own network; PGP is the awkward standard that at least talks to other PGP users. Neither covers the last column, and nothing does.
The metadata problem nobody solves
Every row of that table exposes the addresses. That is not an oversight — it is how mail is delivered. A mail server has to know where to send a message, so the envelope has to be readable at every hop.
The practical consequence is that encryption hides what you said, not who you talk to or when. For many realistic concerns, the pattern is as revealing as the content: a sequence of messages between a person and a clinic, a lawyer, a recruiter, or a journalist tells the story without a single body being read.
Timing and volume leak the same way. So does the simple fact of an account existing at a given provider. If your concern is that a specific relationship should not be observable, encrypted email is the wrong layer to solve it at, and a different channel is the honest answer.
There is one adjacent leak worth fixing regardless of provider, because it is easy: remote images. Gmail has routed all remote images through Google's proxy since December 2013, so a tracking pixel sees Google's request rather than your IP address or browser. Encrypted providers generally leave remote-content loading to your settings, so check that it is off. Our guide to tracking pixels covers what leaks and how to stop it.
What a court can still compel
Encryption changes what a provider is able to hand over. It does not exempt the provider from being asked.
Proton is the useful case study because the facts are public. In 2021, Swiss authorities served a binding order and Proton logged the IP address of a French climate activist, who was subsequently arrested. The message contents were never decrypted, because they could not be. The user was identified anyway.
Proton's policy sets out the standing position: no permanent IP logs by default, but it can be legally compelled to begin logging under Swiss law and will disclose the limited data it holds to competent Swiss authorities. Jurisdiction affects the procedure rather than the principle — Switzerland is outside the 5/9/14 Eyes networks and outside US and EU jurisdiction, which raises the bar for foreign requests without removing it.
So the guarantee to rely on is specific and worth having: a zero-access provider genuinely cannot produce your message bodies. The guarantee not to rely on is that using one makes you unidentifiable. It does not.
When encrypted hosting is the wrong purchase
Encrypted email is built for correspondence you need to keep and want kept confidential. A large share of what arrives in a modern mailbox is neither.
Signup confirmations, one-time codes, download gates, trial activations, retailer marketing — none of that is correspondence, and encrypting it protects nothing that matters. The exposure in those flows is not that someone reads the message. It is that a permanent address is now sitting in a marketing database, ready to appear in the next breach and to be matched across services as a durable identifier.
Encryption does not touch that, because the address itself is the leak. Paying for encrypted hosting and then typing that address into every form is a common and expensive mistake.
The tool that fits is a throwaway inbox. Open a temporary address, catch the code or the confirmation link, and let it expire — there is no account to secure, nothing to recover, and nothing to appear in a breach dump later. Keep the encrypted account for the conversations that warrant it, and keep it out of signup forms entirely. Our guide to signing up without giving your email covers the practical patterns.
Encrypted email providers are not interchangeable, and the axis that separates them is coverage. Proton Mail removes the provider from the set of parties who can read your stored mail. Tuta goes further and encrypts subject lines, names, calendars, and contacts, leaving only addresses and dates. PGP encrypts bodies on any provider but structurally cannot cover subject lines.
None of them encrypt the envelope, so who you talk to and when stays visible, and none of them place a provider beyond a lawful order — Proton was compelled to log a user's IP address in 2021 and an arrest followed.
Match the tool to the exposure. Encrypted hosting for correspondence that needs confidentiality, remote images switched off everywhere, and a disposable address for the signup forms that were never correspondence in the first place.
Frequently asked questions
Sources
- Tuta, Tuta encryption explained | Tuta (opens in new tab) (2026)
- Proton, Proton Privacy Policy (opens in new tab) (2026)
- Proton VPN (official Swiss-based page), Get a VPN protected by Swiss privacy laws | Proton VPN (opens in new tab) (2026)
- TechCrunch, ProtonMail logged IP address of French activist after order by Swiss authorities | TechCrunch (opens in new tab) (2021)
- Filippo Valsorda, How the new Gmail image proxy works and what this means for you (opens in new tab) (2013)
Recommended privacy tools
Independent privacy tools that complement a disposable inbox.
ProtonMail
Swiss end-to-end encrypted email. Zero-access encryption means even Proton cannot read your messages.
Learn MoreTutanota
German encrypted email, open-source and GDPR-native, with encrypted subject lines and an encrypted calendar.
Learn MoreDeleteMe
Finds and removes your personal data from broker sites, then keeps checking so it stays gone.
Learn More