Use case
Is email private? Here's what actually happens to it
Email is usually encrypted while it moves and almost never encrypted at rest. Two companies you don't control end up holding a readable, searchable copy of every message — and that copy outlives the reason you sent it.
Say it in a chat with no inbox — free, no sign-upWhat actually happens after you press send
Your mail client hands the message to your provider's outbound server. That server looks up where the recipient's domain receives mail and opens a connection to it. If both machines support TLS, the hop is encrypted — and then the receiving server decrypts it, runs it through spam and malware filters, writes it to disk, and builds a full-text search index over it so the recipient can find it later by typing three words. At the end of a journey that takes under a second, two companies neither of you jointly chose are each holding a plain, readable copy, plus an index that makes it instantly retrievable.
That gap is the whole answer to "is email encrypted?" Encryption in transit protects the wire between two machines. End-to-end encryption means only the sender and the recipient hold the keys, and every machine in between carries a box it cannot open. Email, by default, does the first and not the second. It is an armored truck with a stop at every depot, and at every depot the box comes off and gets logged.
The reason is architectural, not negligent. SMTP, the protocol carrying your mail, was published in 1982 and had no encryption in it at all. STARTTLS — the mechanism that upgrades a connection to TLS — was standardised twenty years later, in 2002, and it is opportunistic by design: if the other server doesn't offer encryption, the message goes anyway, in the clear. That worked. Google publishes the encrypted share of Gmail's traffic in its transparency report and it has sat above 90% for years. Transport is largely a solved problem. Storage never was.
And email does something almost no other channel does: it manufactures copies. Every recipient, every Cc, every forward, every phone and laptop syncing the same mailbox creates an independent copy on infrastructure you have no relationship with. There is no button anywhere that reaches them. When people ask "can someone read my email", the honest answer isn't about interception — nobody needs to intercept anything. The copies are already sitting still, in a searchable box, waiting.

Who ends up with a readable copy
| Who | What they can read | How long it typically lasts |
|---|---|---|
| Your own provider | Body, attachments, subject, every address — plus the search index it built over all of it | Until you delete it, and past that: trash holds mail for around 30 days, backups longer |
| The recipient's provider | The same message, on infrastructure you never picked and can't audit | Whatever their retention policy says, which is not your decision |
| The recipient, and every device syncing that mailbox | Everything, including the ability to forward it anywhere | Indefinitely — your delete button does not reach their inbox |
| An employer, if either address ends in a company domain | Full mailbox contents through the admin and eDiscovery tools built into Google Workspace and Microsoft 365 | Often years, under a retention policy almost nobody reads |
| Apps you once granted mailbox access | Whatever the OAuth scope allowed, which is frequently "read all your mail" | Until you revoke it, and most people never revisit that screen |
| Anyone holding valid legal process against a provider | Stored mail, requested from the company rather than from you | Thresholds differ by country; the US baseline still rests on a 1986 statute |
Defaults vary by provider, plan and jurisdiction. Reflects common configurations as of July 2026.
Five things "my email is encrypted" still leaves in the open
- The subject line
PGP and S/MIME encrypt the body of a message. The subject is a header, and headers stay in cleartext, which means the most summarising line in the whole message is the one part that travels and gets stored readable. "Divorce consultation — Thursday 4pm" gives away everything the encrypted paragraph underneath was protecting.
- The envelope
Who wrote to whom, at what time, from which IP address, through which servers. Every message carries a stack of Received headers that reads like a routing log, and it is never end-to-end encrypted, because the servers doing the routing have to read it. Metadata alone reconstructs a relationship: frequency, timing, and who was copied in.
- Storage at both ends
TLS protects the hop, not the hard drive. A mainstream provider holds your mail in a form it can read, because that is what makes search, filtering, spam detection and previews work. Google stopped scanning consumer Gmail content for ad personalisation in 2017, and that was a policy change, not an architectural one — the technical access it gave up voluntarily is still there.
- Whether and when you opened it
A single 1×1 transparent image embedded in an HTML email tells the sender the moment you opened it, roughly where you were, and which mail client you used. Marketing platforms ship this by default and so do several "read receipt" browser extensions used by ordinary colleagues. Blocking remote images switches it off; Apple's Mail Privacy Protection instead loads every image for everyone, which breaks the signal rather than the practice.
- Gmail's confidential mode
It looks like a disappearing email and is not one. The content still sits with Google, the expiry is enforced by the interface rather than by cryptography, and the recipient can photograph the screen exactly as before. It raises the effort required to keep a copy. It does not make the message unreadable to anyone who had it.

The honest split: two different problems wearing the same coat
If the thing genuinely belongs in email — a thread with a lawyer, invoices you'll need in eighteen months, correspondence that has to survive both of you closing your laptops — then the fix is email, done properly. Proton Mail and Tuta are built so the provider cannot read what it stores: your mailbox is encrypted at rest with keys derived from your password, and messages between two accounts on the same service are end-to-end encrypted, subject line included in Tuta's case.
Be clear-eyed about the ceiling, though. The moment you write to an ordinary address at an ordinary provider, you are back on plain SMTP, and the encrypted provider protects only the half of the conversation living on its own servers. The workarounds are real but effortful: a password-protected message the recipient opens through a browser link, or PGP configured on both ends, which in practice means convincing the other person to configure PGP. Switching providers upgrades your side of every conversation. It does not upgrade theirs.
The second problem is different, and it is the one people actually search about. A password. A door code. A backup code. Your new address, sent to one person. A sentence you want a specific human to read and no system to keep. None of that needed an inbox — it needed to reach one person once. Email is not badly built for that; it is built for the opposite of that. It keeps, it indexes, it copies, it syncs. Asking it to be ephemeral is asking a filing cabinet to be a conversation.
That second job is what FadeChats does. You open the page and a private room for two exists immediately — no account, no email address, nothing to install. You send one invite link that works exactly once. Whatever you type travels directly from your browser to theirs over an encrypted peer-to-peer connection, so the server relaying the introduction never sees a message and has nothing to store, index or hand over. When you close the tab the room expires and there is no copy anywhere to delete, because none was ever written.
The trade is honest and it is a real one. FadeChats cannot do email's job: there is no offline delivery, so the other person has to actually be there at the same time; there is no thread to reread next month; there are no stored attachments; it is two people, not a group; and like every tool on earth, it cannot stop the other person from taking a screenshot. It is a channel for the thing that shouldn't have been filed, not a replacement for the filing.
Sending something that never touches an inbox
- Open FadeChats and get a room
The room is created the moment the page loads. There is no sign-up form, because there is no account — nothing about you is collected, so nothing about you can later be attached to the conversation.
- Send the one-time invite link
Any channel works, including the email you were about to use — the link admits one person once, and expires on its own in about 10 minutes if nobody opens it. What ends up in an inbox is a dead link, not the secret.
- Say the thing, then close the tab
Text and images move browser to browser over the encrypted data channel. You can answer "wait, which account is that for?" in the same room, which a one-way self-destructing note can't do. Then the room expires and there is nothing to delete.
The honest recommendation
Keep email for what email is good at, and move it to a provider that can't read what it stores — Proton Mail or Tuta — if that matters to you. Then stop pushing one-off secrets through it. A password, a code or an address does not need a permanent, indexed, searchable home in two companies' storage: it needs to arrive once, to one person, and be gone.
The other half: the address itself
Everything above is about who can read what you send. There's a companion question with a less comfortable answer: who already has your email address, and what is it filed next to? Data brokers assemble profiles from public records, purchases and app data, then publish them on people-search sites — commonly your name beside a home address, phone number, age, relatives, and the email addresses you've used. That listing is why the phishing that reaches you knows your street, and choosing a better mail provider does nothing about it, because the leak happened somewhere you were never a customer.
Disclosure: the link below is an affiliate link. If you subscribe through it, FadeChats earns a commission at no extra cost to you. FadeChats itself stays free, ad-free and account-free — this is what pays for the writing.


Optery scans hundreds of data-broker and people-search sites for listings of you, files the opt-out requests, and re-runs the scan every month, because brokers quietly re-list profiles they can still sell — removal is upkeep, not a one-off. The free tier produces an exposure report with screenshots of where you appear, which is worth running on its own before you decide anything. Two limits to know going in: it changes what brokers publish about you, not anything inside your mailbox, and its coverage is built for the markets it operates in — the US, Canada, Australia, New Zealand and South Africa.
See which sites publish your address
Frequently asked questions
Is email encrypted?
In transit, usually — the connection between mail servers is protected by TLS well over 90% of the time on major providers. End to end, almost never. That means the message is decrypted, stored and indexed on your provider's servers and again on the recipient's, in a form both companies can read. "Encrypted email" in the ordinary sense describes the wire, not the storage.
Can someone read my email without me knowing?
Several people can, without anything unusual happening. An administrator on a company domain can search any mailbox through built-in eDiscovery tools. Any app you once granted mailbox access keeps it until you revoke it. A provider can be served legal process directed at the company rather than at you. And whoever picks up an unlocked, signed-in phone gets everything, instantly, by search.
Can Google read my Gmail?
Technically yes — Gmail stores your mail in a form Google can process, which is what makes search, filtering and spam detection work. Google stopped scanning consumer Gmail content to personalise ads in 2017, and that was a policy decision rather than a change in architecture. Providers like Proton Mail and Tuta differ structurally: the mailbox is encrypted at rest with keys they don't hold, so the access simply isn't there.
Does deleting an email delete it everywhere?
No. Deleting removes it from your view; the recipient's copy, their provider's copy, every device syncing that mailbox and any backup taken in the meantime are all untouched. Outlook's recall only works when both parties are inside the same Exchange organisation, and it frequently fails there too. Once a message is delivered, you have no reach into it.
Can my employer read my work email?
Yes, and usually without asking. Google Workspace and Microsoft 365 give administrators search and export tools over every mailbox in the organisation, typically under a retention policy that keeps mail for years. That applies to personal messages sent from a work address, and in many workplaces to personal mail read in a browser on a managed device.
What should I use instead of email for a password or a code?
Something with no inbox at the other end. A password manager's sharing feature is the right tool inside a team you already work with. For a one-off exchange with someone outside it, a disappearing chat like FadeChats moves the detail directly between two browsers, lets the other person ask a follow-up question, and leaves no stored copy on either side once the room expires.