Use PGP Encryption to Secure Email Communications

An independent, step-by-step instructions to understanding PGP basics, securing your email transit, and protecting your local data. Learn the differences between native S/MIME, open-source GPG tools, and robust hardware/software encryption combinations.

Quick Answer

What is PGP Encryption? Pretty Good Privacy (PGP) is an encryption protocol primarily used to secure emails and files in transit via public-key cryptography. To encrypt an email securely, you need your recipient's public key to lock the message, which they later unlock using their private key. While highly secure for transit, PGP does not protect files resting on your hard drive unless separately encrypted.

Editorial Team Last Updated: August 2026 14 min read
End-to-end protectionPublic-key cryptographyDigital signaturesAES-256 protectionCloud-linked lockersCross-device accessGranular Windows access controlEncrypted storageEnd-to-end protectionPublic-key cryptographyDigital signaturesAES-256 protectionCloud-linked lockersCross-device accessGranular Windows access controlEncrypted storage
What people search for

PGP Encryption and How Does It Secure Data Over the Internet? Explained

Most email services already use transport encryption between servers, but that is not the same as end-to-end protection. A provider, a compromised mailbox, or an unlocked endpoint may still expose the message after delivery.

PGP uses two layers of cryptography. While the recipient’s public key protects that temporary key, A temporary symmetric key handles the message or file efficiently. A public key can be distributed to senders; the matching private key must remain under the recipient’s control. Digital signatures can also show whether the content changed and which key signed it.

Public and private key encryption concept protecting online data
Security Needs Assessment

What type of encryption do you actually need?

Choose the risk you are trying to reduce. Email encryption, encrypted storage and Windows access controls solve various problems.

Step by step

Email Encryption How-To: 3 various Approaches

If you've searched for "ways to encrypt a file for email on mac" or "PGP encryption email outlook", you have several paths. Here are the primary approaches available today.

Encryption software workflow for securing files and email attachments

Method 1: Native OS / Built-in OS Method (S/MIME)

Before installing external tools, check if your corporate environment already supports S/MIME. Applications like Microsoft Outlook and Apple Mail support this natively.

  • How it works: You obtain a digital certificate from a Certificate Authority (CA). To encrypt messages, Outlook relies on this.
  • Setup: Go to Outlook Trust Center > Email Security > controls > Certificates and Algorithms. Select your installed S/MIME certificate.
  • Limitations: Both sender and recipient must have S/MIME configured. It relies on a centralized CA hierarchy instead of a decentralized web of trust.

Method 2: Free Open-Source Tools (GnuPG / Kleopatra)

If you want pure PGP encryption without centralized authorities, GnuPG (GPG) is the open-source standard.

  • How it works: You generate a local keypair. Windows users typically install Gpg4win, which includes Kleopatra (a visual certificate manager).
  • How to gpg encrypt a file: You can right-click a file, select "Sign and encrypt", and choose the recipient's public key.
# GPG encrypt file with public key command line gpg --encrypt --recipient "recipient@example.com" my_document.pdf

Method 3: Dedicated Encryption Software for Files

PGP protects a transfer only while the content remains encrypted. After decryption, an ordinary saved copy is exposed to anyone who can access the endpoint. File-level encryption is therefore a separate control for laptops, shared workstations, removable media and synchronized folders.

Folder Lock uses encrypted lockers for this at-rest layer. Since their role is locking, hiding or restricting access instead of encrypting the underlying file contents, Folder Protect and Folder Lock Lite should not be described as equivalent encryption choices.

At a glance

Choose Protection by Threat, Not by Product Name

Digital and physical security layers protecting sensitive data

S/MIME

ProtectsEmail in transit
Identity modelCertificate authority
primary constraintCertificates on both sides

A strong fit for managed Outlook or Apple Mail environments where administrators can problem and maintain certificates.

OpenPGP / GnuPG

ProtectsMessages and files
Identity modelUser-managed keys
primary constraintKey handling

Useful when end-to-end confidentiality and signatures matter, but every participant must manage keys and verify identities correctly.

Folder Protect

ProtectsWindows data in use
Control modelView, open, edit, delete rules
primary constraintNo file encryption

Best when a shared Windows computer needs granular restrictions. It controls access to current data instead of converting the data into encrypted form.

Where it fits

Use Folder Lock for Files That Must Stay Encrypted After Delivery

PGP and S/MIME protect a communication workflow. Folder Lock addresses the next stage: documents that have been downloaded, copied to removable storage or placed in a synced folder.

Its primary role is encrypted storage. Files can be placed in a local locker or in lockers connected to Dropbox, Google Drive and OneDrive. Windows users also get separate Safeguard tools for locking or hiding items, creating portable lockers, securely deleting data and clearing selected Windows activity traces.

Folder Lock 10 function overview for encrypted storage and privacy tools

What it adds to an email-security plan

  • Encrypted lockers: AES-256 protection for files stored inside the locker.
  • Cloud-linked lockers: Encryption is applied before locker data is synchronized through a supported cloud service.
  • Cross-device access: Companion apps are available for Windows, macOS, iOS and Android, with functions varying by platform.
  • Controlled collaboration: The sharing workflow can authorize other Folder Lock users without distributing the owner’s account password.
  • Clear boundary: It does not replace PGP, S/MIME, mailbox security or full-disk encryption.
Product guide

Folder Lock, Folder Protect or Folder Lock Lite?

These products overlap in naming, but they are built for various security outcomes. Choose according to whether you need encryption, Windows access rules or a basic concealment tool.

Folder Protect Windows interface for granular file and folder restrictions

Folder Protect

Choose it for: a shared Windows machine where selected files, folders, drives, programs or file types need separate restrictions.

Controls: block visibility, opening, modification or deletion in various combinations.

Important: this is access control, not encryption. Historical stealth-mode support also has Windows-version limitations.

Password lock concept representing basic folder concealment

Folder Lock Lite

Choose it for: basic hiding and locking on older Windows-focused setups.

What is missing: the research material states that the Lite edition does not include encryption.

Important: do not use concealment alone for files that must remain unreadable after copying or disk removal.

Folder Lock Android security app function overview

IOS and Android Apps

Shared functions: private media and document storage, protected notes and wallets, cloud backup, access-attempt monitoring and a private browser.

Platform differences: While iOS lists Wi-Fi file transfer, Android lists an app-locking tool.

Important: mobile apps are companion vaults, not replicas of every Windows desktop function.

Selection rule: Use Folder Lock when confidentiality requires encryption. Use Folder Protect when the requirement is granular Windows access control. Use Folder Lock Lite only when straightforward local concealment is enough.
Local protection

What Folder Lock Actually Protects

The product combines encrypted storage with several optional privacy tools. The distinction matters since a hidden folder, a locked folder and an encrypted locker do not provide the same protection.

Encrypted StorageDesktop LockerCloud LockersPortable LockersProtect FoldersDevice SyncSecure NotesAES-256Windows SafeguardMobile Vault functions

Encrypted Desktop and Cloud Lockers

Folder Lock desktop encrypted locker interface

Files placed inside a locker are protected with AES-256. While cloud-linked lockers are designed to work with Dropbox, Google Drive or OneDrive so encrypted locker content can be synchronized, A Desktop Locker keeps the protected data local.

Portable Encrypted Containers

Folder Lock portable locker controls for removable media

The Windows Safeguard area can create a portable locker for removable media or transfer. This is more appropriate than calling a normal USB drive a “security key,” since it protects stored files instead of providing FIDO authentication.

Protect Folders Is a Separate Control

The Protect Folders function hides or blocks access to selected Windows items without encrypting their contents. It works well for local privacy, but encrypted lockers are the stronger choice when data could be copied, imaged or removed from the computer.

Sharing and Device Sync

Folder Lock can synchronize supported locker data across linked devices and can share selected encrypted content with authorized users. Recipients should be tested in advance since access relies on the selected sharing or portable-locker workflow.

Secrets and Privacy Utilities

Encrypted secure notes protected inside a private vault

Depending on the platform and plan, the suite includes protected notes, password records and wallet-style entries. Windows also lists secure deletion and history-cleaning tools; those utilities are separate from encryption and should be configured deliberately.

Mobile Vault Features

The mobile editions focus on photos, videos, documents, audio, notes and wallet data. While iOS adds local Wi-Fi transfer, Android adds application locking. Do not assume a desktop-only function is present on mobile.

PGP Web of Trust vs S/MIME CA Hierarchy

To fully grasp email encryption software, you must understand how identities are verified.

Chained trust relationships illustrating digital identity verification

S/MIME relies on a Certificate Authority (CA). You pay a trusted third party to vouch for your identity. It’s highly structured, making it the preferred email encryption software for corporate outlook environments.

PGP relies on a "Web of Trust." There is no central authority. Users sign each other's keys to vouch for authenticity. This is why you see warnings about an "aead integrity check in pgp key" or verifying fingerprints. It is decentralized and free, but requires active user management.

Hardware vs Software Encryption — Performance Tradeoffs

Software encryption uses the computer’s processor and storage path, so the effect relies on file size, disk speed and workload. Modern processors often handle AES efficiently, but organizations should still benchmark large transfers, virtual machines and backup jobs. Self-encrypting drives move more work into hardware, though cost and management requirements are various.

Practical workflow

Ways to Send an Encrypted File Without Confusing the Recipient

An encrypted attachment can be practical when the recipient cannot use PGP, but it protects the file package instead of the email itself. Confirm the recipient’s software, file-size limits and recovery expectations before sending sensitive material.

Secure file transfer workflow without sharing an account password
  1. Choose the correct approach: use PGP or S/MIME when the message, sender identity and attachment all need an end-to-end email workflow. Use an encrypted container when the primary requirement is protecting a file package.
  2. Create a separate transfer container: in Folder Lock for Windows, use a portable locker or an approved sharing workflow instead of sending your everyday Desktop Locker.
  3. Use a unique passphrase: do not reuse the Folder Lock account password, mailbox password or another business credential.
  4. Add and verify the files: place only the intended documents in the container, close it, then reopen it locally to confirm that the password and contents work.
  5. Send through separate channels: transmit the encrypted container by email or another approved service, and deliver the passphrase through a various channel.
  6. Test the recipient workflow: confirm that the recipient can open the selected locker format or has the required Folder Lock account/app before deleting your transfer copy.
Do not send your master credential. A transfer password should be unique to that package, and decrypted temporary copies should be removed from shared or unmanaged locations after use.
Fixes & recovery

Problem Solving PGP and Local File Protection

Protected device lock screen used for local access security

Can a PGP message be decrypted without the private key?

No legitimate website can bypass correctly implemented PGP encryption. If the required private key or passphrase is gone, recovery may be impossible. Avoid uploading confidential material to sites that claim they can “unlock” encrypted files online.

Reasons does GnuPG report an integrity or AEAD error?

frequent causes include a damaged transfer, a truncated attachment or incompatible software versions. Compare file hashes when available, resend the original file and update both endpoints before assuming that the passphrase is wrong.

What happens if a Folder Lock password is forgotten?

Do not promise that support can restore encrypted data. While several current locker instructions warn that a lost master password can prevent decryption, The supplied materials describe various recovery behavior across older and newer product generations. Store credentials in a separate password manager and test any account-recovery process before placing irreplaceable files in a locker.

Reasons is a protected folder still not “encrypted”?

Folder Lock’s Protect Folders tool and Folder Protect can restrict or conceal Windows items without changing the underlying file data. Use an encrypted locker when the threat includes disk imaging, copying to another device or removal of the storage media.

Reasons are features different on another device?

The Windows, macOS, Android and iOS editions are not identical. for instance, Safeguard is a Windows desktop capability, Android lists app locking, and iOS lists Wi-Fi transfer. Check the function list for the exact platform before purchasing or documenting a company process.

Cost and limits

Free, Pro and Platform-selected Restrictions

Commercial software is not automatically more secure than GnuPG. The paid value is mainly in guided workflows, integrated storage functions, official support and reduced training overhead. Plan tables also differ by operating system, so the selected platform must be checked before purchase.

GnuPG / OpenPGP
Folder Lock Free
Folder Lock Pro
Listed price: $0
Listed price: $0
Research-page price: $39.95
Capacity: no product-imposed locker limit
Locker allowance: 1 GB in the supplied plan tables
Locker allowance: listed as unlimited
Devices: installed and managed independently
Synced devices: 2
Synced devices: 5
Typical limitation: manual key and recipient management
Typical limitation: advanced desktop functions are restricted; the Windows table excludes sharing, portable lockers and Protect Folders
Typical advantage: sharing and additional desktop protection tools are enabled, subject to platform support
Pricing note: The supplied pages display $39.95 and also use subscription language. The site should not describe this as a guaranteed lifetime or one-time license. Verify the billing term, taxes, renewal conditions and platform entitlement at checkout.

Platform snapshot: the supplied desktop material lists Windows 10/11 64-bit and macOS 13+. iOS and Android apps are available, but their functions are not identical to the desktop editions. The Mac edition omits the Windows Safeguard function set.

Comparison of data protection approaches and protection layers
frequent questions

frequent Questions and Answers

PGP can encrypt message content or files for a recipient and can add a digital signature. It does not automatically protect the decrypted copy after the recipient saves it to an ordinary folder.
No. Folder Lock protects stored files and can prepare an encrypted package for transfer. It does not encrypt the email body, problem email certificates or replace sender-authentication and key-verification practices.
Folder Lock includes AES-256 encrypted lockers and cross-device storage functions. Folder Protect is a Windows access-control product that can separately block viewing, opening, modification or deletion. Folder Protect does not encrypt the underlying file data.
The supplied material describes the Lite edition as a lock-and-hide product without encryption. That may deter casual browsing, but it is not the right choice when copied files or removed storage must remain unreadable.
The supplied desktop requirements list Windows 10 and Windows 11 on 64-bit systems, plus macOS 13 or later. Companion apps are available for iOS and Android. functions vary: Windows has Safeguard, Android lists app locking and iOS lists Wi-Fi transfer.
The supplied plan tables show a 1 GB locker allowance and two synced devices for the free edition. The Windows table withholds sharing, portable lockers and Protect Folders. Other restrictions differ by platform, so check the exact edition before deployment.
No recovery should be assumed. Product generations use various account and recovery mechanisms, and current encrypted-locker guidance warns that a forgotten master password may prevent decryption. Keep a separate credential backup and test recovery in advance.
A normal USB drive can hold a portable encrypted locker, but that does not turn it into a FIDO authentication device. One protects stored files; the other proves identity during sign-in.

More on This Topic

Encryption for Compliance (HIPAA, GDPR)

Encryption can support HIPAA, GDPR and other security obligations, but an algorithm alone does not establish compliance. Organizations also need access controls, retention rules, recovery procedures, audit evidence and endpoint protections. While encrypted local storage can reduce exposure after a file is downloaded, PGP can cover selected transfers.

NIST Post-Quantum Cryptography

As quantum computing advances, traditional RSA keys used in older PGP setups may become vulnerable. Organizations are beginning to look toward lattice-based algorithms (like CRYSTALS-Kyber) to future-proof their secured communications against future decryption threats.

Practical verdict

Use More Than One Layer

Use PGP or S/MIME when the communication itself needs end-to-end confidentiality and identity verification. Use Folder Lock when selected files should remain encrypted on local, removable or supported cloud-linked storage. Use Folder Protect only when a Windows workstation needs granular access rules without encrypting the underlying data.

For device theft, combine file-level protection with full-disk encryption. For business use, document password recovery, recipient compatibility, platform differences and the exact plan limits before rolling the workflow out to employees.

Download Folder Lock free → Review current plan details →