How to Send Secure Email in Outlook Subject Line
If you need to send sensitive information, don't rely on a word in the subject line alone. The dependable Outlook method is to write your message, open the Options ribbon, select Encrypt, and choose the protection setting Outlook gives you.
A subject-line tag such as secure, encrypt, or [secure] may work in some Microsoft 365 organisations. But that only happens when an administrator has created a mail rule for it. It isn't a universal Outlook command.
The reliable way to send a secure email in Outlook
To send an encrypted message in Outlook:
- Open Outlook and create a new email.
- Add the recipient, subject, and message.
- Open the Options tab or ribbon.
- Select Encrypt.
- Choose the protection option shown in your account.
Microsoft's Outlook instructions show Encrypt-Only as one available choice. Microsoft 365 guidance also lists Encrypt and Do Not Forward.
The names may differ slightly between Outlook versions. The key step is selecting Encrypt from Outlook's controls. This is more dependable than hoping a subject-line word triggers protection.
If you don't see the Encrypt button, don't assume that typing “secure” will fix the problem. Your account may not have the required Microsoft 365 protection features, or your organisation may use a different Outlook setup.
What to put in the subject line
There is no single subject-line word confirmed as a universal Outlook encryption command.
For a normal encrypted message, use a clear subject that tells the recipient what the email is about without putting private details in the subject. For example:
- `Updated contract`
- `Invoice for review`
- `Private document attached`
Then use Options > Encrypt before sending.
You may see instructions telling you to add a tag such as:
```text
[secure] Updated contract
```
That format can be useful if your organisation has specifically told you to use it. It should not be treated as a standard Outlook feature that works in every account.
Keep sensitive information out of the subject where possible. A subject-line word can act as a trigger in some systems, but it isn't a substitute for Outlook's encryption control.
Does typing “secure” or “[secure]” encrypt the message?
Not necessarily.
Some Office 365 environments use mail or SMTP server rules. SMTP is the system that moves email between mail servers. An administrator can configure one of these rules to look for words such as secure or encrypt in the subject line and then apply encryption.
Another setup may require the exact tag [secure] at the start of the subject. For example:
```text
[secure] Project documents
```
That can work only if the organisation's rule is built to recognise that format.
The important difference is this:
- Outlook's Encrypt button is a built-in control available in supported accounts.
- A subject-line trigger is an organisation-specific rule.
- Typing a word without a matching rule does not make the email encrypted.
So, if you're asking how to send secure email in Outlook with brackets, first check whether your employer or Microsoft 365 administrator has told you to use the bracketed format. If not, use Options > Encrypt instead.
How to use Encrypt and choose Encrypt or Do Not Forward
After you select Encrypt, Outlook may offer more than one protection choice.
Encrypt
Choose Encrypt when you want to protect the message. In some Outlook versions, this may appear as Encrypt-Only.
This is the usual choice when your goal is to send an encrypted email and let the recipient read it through the supported email experience.
Do Not Forward
Choose Do Not Forward when the message should have tighter sharing limits. This option is designed for messages that shouldn't be freely forwarded.
The exact choices depend on your account and Microsoft 365 setup. If you see only one option, use the available setting that matches your organisation's instructions.
After choosing the protection level, finish the email and send it as usual. Look at the message controls again before sending if you want to confirm that encryption is still applied.
Sending secure replies and messages with attachments
A reply needs the same care as a new message.
If the original email was protected, Outlook may carry protection into your reply. Don't assume that will always happen, though. Before you send a reply containing sensitive information, check for the Encrypt control in the reply window.
A safe process is:
- Open the message and select Reply or Reply all.
- Write only the information the recipients need.
- Open Options.
- Select Encrypt.
- Choose Encrypt or Do Not Forward, if available.
- Send the reply.
For an attachment, add the file while composing the message, then apply encryption before sending. This answers the common question of how to send a secure email in Outlook with an attachment: use the normal attachment button, but protect the whole message through Options > Encrypt.
Check the recipient list carefully. Encryption won't help if the protected email is sent to the wrong person.
If your organisation uses a subject-line rule, the same rule may apply to replies and attachments. That depends on how the mail system was configured. If the rule requires [secure], use the exact spelling and format your administrator provided.
Outlook 365, personal accounts, and organisation-specific rules
For Outlook 365, the usual route is:
New message > Options > Encrypt > choose a protection option
You may use Outlook on the web or the desktop version, but the labels and ribbon layout can vary. Look under Options for Encrypt.
Your account type matters. A work or school Microsoft 365 account may have organisation-managed encryption settings. An administrator can also create rules that react to words like secure or encrypt in the subject line.
A personal Outlook account may not have the same organisation rules. Don't assume a subject-line trigger from a workplace guide will work for a personal mailbox.
The Outlook app needs separate attention. Mobile Outlook screens and available controls can differ from the desktop and web versions. The supplied Outlook instructions support the Options > Encrypt workflow, but they don't establish that every version of the mobile app offers the same control. If you can't find Encrypt in the app, use Outlook on the web or desktop if available, or ask your administrator what method your account supports.
Before relying on a bracketed tag in Outlook 365, ask:
- Does our organisation use a subject-line encryption rule?
- Is the trigger `secure`, `encrypt`, or `[secure]`?
- Does the word need to appear at the start of the subject?
- Does the rule also cover replies and attachments?
Those details are controlled by the organisation, not by Outlook in general.
What encryption protects—and what a subject line does not do
Using Encrypt applies a protection setting to the email. Depending on the option chosen, it can also limit how the recipient handles the message, such as with Do Not Forward.
A subject-line word is different. It is simply text unless a mail rule has been created to act on it. Typing this:
```text
secure
```
doesn't automatically turn on Outlook encryption.
The subject also isn't a good place for private details. Avoid putting account numbers, passwords, medical details, or other sensitive information in it. Use a plain description and put the protected information in the message or attachment.
Encryption also doesn't correct other mistakes. It won't protect you from:
- Sending the message to the wrong address
- Attaching the wrong file
- Giving access to an unprotected copy elsewhere
- Using a subject-line trigger that your organisation doesn't support
Treat the subject line as a possible instruction for a configured mail system—not as proof that protection is active.
A quick checklist before sending
Use this checklist when sending sensitive information:
- [ ] Did you create the message in the correct Outlook account?
- [ ] Did you check every recipient?
- [ ] Did you avoid private details in the subject line?
- [ ] Did you open Options and select Encrypt?
- [ ] Did you choose Encrypt, Encrypt-Only, or Do Not Forward as needed?
- [ ] If using `[secure]`, did your Microsoft 365 administrator confirm that rule?
- [ ] Did you check that the attachment is the right file?
- [ ] If replying, did you confirm that the reply is protected too?
- [ ] If using the Outlook app, did you verify that encryption is actually available?
If you're unsure, check your Outlook encryption options before sending sensitive information. If the Encrypt control is missing—or your organisation told you to use a subject-line tag—contact your Microsoft 365 administrator and confirm the exact rule.