Your E-mail Is a Postcard

Your E-mail is a Postcard. Stop sending sensitive data on postcards.

September 15, 20267 min read

Your Email Is a Postcard: How to Send Encrypted Email in Microsoft 365

Picture this. You mail a postcard to your accountant with your bank routing number written on the back in Sharpie. Every postal worker, every sorting machine operator, and anyone who picks it up off the counter can read it. You'd never do that.

And yet a standard email works a lot like that postcard. It hops between servers on its way to the recipient, and at several points along the way it can be read, copied, or forwarded by someone who was never supposed to see it.

The good news: if your business runs on Microsoft 365, the fix is probably already sitting in your Outlook toolbar. You just have to know it's there.

First, what "encrypted email" actually means

There are two layers here, and it's worth knowing the difference because one of them gives people a false sense of security.

Transport encryption (TLS) protects the message while it's traveling between mail servers. Microsoft 365 does this automatically. It's genuinely useful, but it only works if the receiving mail server also supports it, and it does nothing once the message lands in someone's inbox. Think of it as an armored truck that drops your postcard on the front porch.

Message-level encryption locks the message itself. The content and its attachments stay protected in the recipient's mailbox, and you can add rules like "nobody can forward this." That's the layer most people mean when they say "send it encrypted," and that's the layer we're talking about for the rest of this post.

What actually needs to be encrypted?

Not every email. If you encrypted your "who's bringing donuts Friday" thread, your team may push back, and honestly they'd be right.

The rule of thumb: if the information in the email could be used to steal money, steal an identity, or embarrass someone, encrypt it.

In practice, that usually means:

  • Personal identifying information — Social Security numbers, dates of birth, driver's license or passport numbers, home addresses paired with account details.

  • Payment and banking information — routing and account numbers, wire and ACH instructions, credit card details, invoices with payment links.

  • Health information — anything touching a diagnosis, treatment, insurance claim, or medical record. If HIPAA applies to you, this isn't optional.

  • HR and payroll records — offer letters with compensation, W-2s and 1099s, I-9 documentation, benefits enrollment forms, performance or disciplinary documentation.

  • Legal and contractual material — signed agreements, settlement discussions, anything your attorney would rather not see forwarded.

  • Credentials and system details — passwords, VPN configs, license keys. (Better still: use a password manager and don't email these at all.)

Nonprofits, a few extras for you: donor records and giving history, grant applications containing beneficiary data, client or case files, and board materials discussing personnel or finances. Donor trust is your most valuable asset, and it takes exactly one leaked spreadsheet to spend it.

Why this matters more than it used to

A few reasons this has moved from "nice to have" to "must have":

Wire fraud is thriving. Business email compromise — where an attacker reads your mail, waits for an invoice, and swaps in their own bank details — costs American businesses billions a year. Encrypting emails that contain payment instructions, with forwarding disabled, closes off one of the easier ways for that scheme to work.

Regulators are paying attention. HIPAA, GLBA, PCI DSS, the FTC Safeguards Rule, and a growing pile of state privacy laws all expect reasonable protection for sensitive data in transit. "We emailed it in plain text" is not a great line in an audit.

Your cyber insurance is asking. Renewal questionnaires increasingly ask about email encryption and data loss prevention. Answering "yes" honestly is cheaper than answering "no."

Your clients notice. When a prospective client sends you their financial documents and gets back a secure, encrypted reply, that says something about how you run your business. It's a small moment that builds a lot of confidence.

The part where you find out you may already have this feature

Here's our favorite thing to tell clients: if you're on Microsoft 365 Business Premium, message encryption is already included. No extra purchase, no new vendor, no separate portal for your team to learn.

Business Premium is the license we recommend to nearly every small business and nonprofit we work with, and encryption is a big part of why. Along with the Encrypt button in Outlook, it brings sensitivity labels, data loss prevention, advanced threat protection, and device management into one bundle. For most organizations under 300 users, it's the single best security value Microsoft sells.

Using it is refreshingly boring. Compose your message, click Encrypt in the Outlook toolbar, and choose your protection level. Encrypt-Only protects the message and its attachments. Do Not Forward does that and blocks forwarding, printing, and copying. Then hit send, the same as always.

On Business Standard or Business Basic? You have options.

Business Standard and Business Basic don't include message-level encryption out of the box. You still get transport encryption, but not the Encrypt button.

You have two straightforward paths:

  1. Add the information protection add-on. Microsoft sells a per-user add-on license that enables message encryption on top of Standard or Basic. It's a few dollars per user per month, which for most small teams is a rounding error compared to a single wire fraud incident.

  2. Step up to Business Premium. Once you add up the add-on cost plus what you're likely paying separately for antivirus, device management, and threat protection, Business Premium often comes out cheaper and simpler. We run this math with clients all the time, and it surprises people more often than not.

Either way, you're not stuck. And you don't need to bolt on a third-party encryption service with its own login, its own bill, and its own support line.

What it looks like on the other end

A fair question: does the recipient need to be a Microsoft customer? No.

  • If they're also on Microsoft 365, the message just opens in their Outlook. They may not even notice anything unusual.

  • If they're on Gmail, Yahoo, or anything else, they get a notification with a link to a secure web portal. They verify themselves with a one-time passcode sent to their email (or by signing in with their Google account), then read and reply securely.

It's one extra step for them. Most people handle it without blinking, especially when they understand why you're sending their tax documents that way.

Make it automatic so nobody has to remember

The weakest link in any security policy is a human being on a deadline. So don't rely on your team clicking the right button every time.

Microsoft 365 lets you build mail flow rules that encrypt messages automatically. A few patterns we set up regularly:

  • Encrypt any outbound message where the body or an attachment contains something that looks like a Social Security number or credit card number.

  • Encrypt anything sent to a specific domain, like your law firm or your payroll provider.

  • Encrypt anything where a user types a keyword such as "secure" in the subject line — a nice, memorable escape hatch for your team.

Set it once, and the right thing happens whether anyone remembers or not.

A quick dose of honesty

Encryption is not a force field. It won't help if you send the message to the wrong Dave in your address book. It doesn't stop a recipient from screenshotting your message. And it's no substitute for multi-factor authentication, phishing training, and reliable backups.

What it does do is make sure that if a message is intercepted, sitting in a compromised mailbox, or landing somewhere it shouldn't, the contents aren't readable. That's a meaningful layer, and it's one of the easiest ones to turn on.

Let's find out what you're already paying for

Most of the businesses we talk to are surprised to learn they've been paying for security features they've never turned on. Encryption is very often one of them.

If you're not sure what your licenses include, whether your current setup meets your compliance obligations, or how to roll this out without confusing your team, that's exactly the kind of thing we do at Phoenix Technology Partners. We'll audit your Microsoft 365 tenant, tell you plainly what you have and what you're missing, and set it up so it works quietly in the background.

Reach out for a no-pressure conversation about your Microsoft 365 environment. Worst case, you'll learn your email is in better shape than you thought.

blog author avatar

Jacob Howe

Jacob Howe is a Co-founder at Phoenix Technology Partners.

Back to Blog