Skip to content

Need urgent help? Call us at 440-991-9980

Email

Sending an encrypted email

When to encrypt a message, how to send one, and what your recipient sees when it arrives.

4 min read Updated
  • encryption
  • secure email
  • compliance
On this page

Encryption protects a message in transit and makes sure only the intended recipient can open it. Your Iconium Email Threat Protection setup includes encryption, so sending one is a matter of flagging the message — you do not need any extra software.

When you should encrypt

Encrypt anything that would cause a problem if it were read by the wrong person:

  • Social security numbers, dates of birth, driver’s licence details
  • Bank account or routing numbers, card details, payroll information
  • Medical or health information of any kind
  • Contracts, legal documents, and signed agreements
  • Employee records, disciplinary notes, offer letters
  • Client lists and pricing where your agreement requires confidentiality

If your industry is regulated — healthcare, finance, legal — your compliance obligations likely require it. When in doubt, encrypt. There is no penalty for encrypting something that did not need it.

How to send one

Compose the email as normal and put the word secure in the subject line, in square brackets:

Subject: [secure] Updated payroll details for review

Send it as you normally would. The system spots the keyword and encrypts the message on its way out.

The keyword is not case-sensitive[secure], [Secure], and [SECURE] all work equally well. What matters is the square brackets and the spelling.

Some messages encrypt themselves

Most clients also have automatic encryption switched on for sensitive categories. If a message contains content that looks like protected health information, personally identifiable information, or other regulated data, the system recognises it and encrypts the message whether or not you used the keyword.

That is a safety net, not a substitute for thinking. Automatic detection is very good but not perfect — it works on recognisable patterns, so a social security number formatted normally will be caught, while a scan of a document containing the same information may not be. If you know a message is sensitive, add the keyword. It costs you eight characters and removes all doubt.

If you are not sure whether automatic encryption is enabled for your company, or which categories it covers, ask us. It is worth knowing where your safety net actually sits.

What your recipient sees

They receive a notification saying a secure message is waiting, with a link to open it. The first time, they will be asked to verify who they are — usually by receiving a one-time code at their email address.

Once verified, they can read the message, download attachments, and reply securely. Their reply comes back encrypted too, which is the part people find most useful: the whole thread stays protected without them needing to do anything special.

Things worth telling recipients in advance:

  • The link expires after a set period. If they sit on it for a fortnight it will need resending.
  • The code goes to the same address you sent to. If they forward your notification to a colleague, the colleague cannot open it — send it to them directly instead.
  • Corporate spam filters occasionally hold the notification. If someone says they never received it, ask them to check junk before you resend.

Practical tips

Do not put sensitive detail in the subject line. The subject travels unencrypted, and it is also where the keyword lives. [secure] Account details is fine; [secure] SSN 123-45-6789 defeats the purpose entirely.

Attachments are covered. Anything attached to an encrypted message is protected along with it, so there is no need to separately password-protect a PDF. If you do add a password to a file, never send the password in the same email.

Check the recipient address before sending. Encryption protects a message from strangers. It does nothing about sending it to the wrong person on purpose. Autocomplete picking the wrong David is the most common data-loss incident we see.

Confirm bank detail changes by phone. No exceptions, no matter how encrypted or convincing the email looks. Use a number you already have on file, not one printed in the message.

If it does not work

  • Recipient says the link is broken or expired — resend the message. A fresh notification generates a fresh link.
  • Recipient never received anything — confirm the address, then ask them to check junk and their organisation’s quarantine.
  • Your message went out unencrypted — check the keyword was in the subject line rather than the body, spelled correctly, and inside square brackets. Capitalisation does not matter. Tell us what happened so we can confirm the rule is working.
  • You need to recall it — contact us immediately. Depending on whether it has been opened, there may be options.

Need a hand with a secure send? Call 440-991-9980 or email support@iconiumnetworks.com. If you are about to send something sensitive and are unsure the encryption is working, send us a test first — a thirty-second check beats a disclosure notification.

Did this fix the problem?

If you followed these steps and it's still not working, get in touch and mention this article — Sending an encrypted email — so we can skip the basics.

Still stuck? Email support at support@iconiumnetworks.com or call 440-991-9980 to open a ticket.