PGP Encryption Explained — How to Encrypt Email Securely

An independent, step-by-step guide to understanding PGP basics, securing your email transit, and protecting your local data. Learn the differences between native S/MIME, open-source GPG tools, and robust hardware/software encryption combinations.

Quick Answer

What is PGP Encryption? Pretty Good Privacy (PGP) is an encryption protocol primarily used to secure emails and files in transit via public-key cryptography. To encrypt an email securely, you need your recipient's public key to lock the message, which they later unlock using their private key. While highly secure for transit, PGP does not protect files resting on your hard drive unless separately encrypted.

Editorial Team Last Updated: August 2026 14 min read
End-to-end protectionPublic-key cryptographyDigital signaturesAES-256 protectionCloud-linked lockersCross-device accessGranular Windows access controlEncrypted storageEnd-to-end protectionPublic-key cryptographyDigital signaturesAES-256 protectionCloud-linked lockersCross-device accessGranular Windows access controlEncrypted storage
What people search for

What is PGP Encryption and How Does It Secure Data Over the Internet?

Most email services already use transport encryption between servers, but that is not the same as end-to-end protection. A provider, a compromised mailbox, or an unlocked endpoint may still expose the message after delivery.

PGP uses two layers of cryptography. A temporary symmetric key handles the message or file efficiently, while the recipient’s public key protects that temporary key. A public key can be distributed to senders; the matching private key must remain under the recipient’s control. Digital signatures can also show whether the content changed and which key signed it.

Public and private key encryption concept protecting online data
Security Needs Assessment

What type of encryption do you actually need?

Choose the risk you are trying to reduce. Email encryption, encrypted storage and Windows access controls solve different problems.

Step by step

Email Encryption How-To: 3 Different Approaches

If you've searched for "how to encrypt a file for email on mac" or "PGP encryption email outlook", you have several paths. Here are the primary methods available today.

Encryption software workflow for securing files and email attachments

Method 1: Native OS / Built-in OS Method (S/MIME)

Before installing third-party tools, check if your corporate environment already supports S/MIME. Applications like Microsoft Outlook and Apple Mail support this natively.

  • How it works: You obtain a digital certificate from a Certificate Authority (CA). Outlook uses this to encrypt messages.
  • Setup: Go to Outlook Trust Center > Email Security > Settings > Certificates and Algorithms. Select your installed S/MIME certificate.
  • Limitations: Both sender and recipient must have S/MIME configured. It relies on a centralized CA hierarchy rather than a decentralized web of trust.

Method 2: Free Open-Source Tools (GnuPG / Kleopatra)

If you want pure PGP encryption without centralized authorities, GnuPG (GPG) is the open-source standard.

  • How it works: You generate a local keypair. Windows users typically install Gpg4win, which includes Kleopatra (a visual certificate manager).
  • How to gpg encrypt a file: You can right-click a file, select "Sign and encrypt", and choose the recipient's public key.
# GPG encrypt file with public key command line gpg --encrypt --recipient "recipient@example.com" my_document.pdf

Method 3: Dedicated Encryption Software for Files

PGP protects a transfer only while the content remains encrypted. After decryption, an ordinary saved copy is exposed to anyone who can access the endpoint. File-level encryption is therefore a separate control for laptops, shared workstations, removable media and synchronized folders.

Folder Lock uses encrypted lockers for this at-rest layer. Folder Protect and Folder Lock Lite should not be described as equivalent encryption options, because their role is locking, hiding or restricting access rather than encrypting the underlying file contents.

At a glance

Choose Protection by Threat, Not by Product Name

Digital and physical security layers protecting sensitive information

S/MIME

ProtectsEmail in transit
Identity modelCertificate authority
Main constraintCertificates on both sides

A strong fit for managed Outlook or Apple Mail environments where administrators can issue and maintain certificates.

OpenPGP / GnuPG

ProtectsMessages and files
Identity modelUser-managed keys
Main constraintKey handling

Useful when end-to-end confidentiality and signatures matter, but every participant must manage keys and verify identities correctly.

Folder Protect

ProtectsWindows data in use
Control modelView, open, edit, delete rules
Main constraintNo file encryption

Best when a shared Windows computer needs granular restrictions. It controls access to existing data rather than converting the data into encrypted form.

Where it fits

Use Folder Lock for Files That Must Stay Encrypted After Delivery

PGP and S/MIME protect a communication workflow. Folder Lock addresses the next stage: documents that have been downloaded, copied to removable storage or placed in a synced folder.

Its main role is encrypted storage. Files can be placed in a local locker or in lockers connected to Dropbox, Google Drive and OneDrive. Windows users also get separate Safeguard tools for locking or hiding items, creating portable lockers, securely deleting data and clearing selected Windows activity traces.

Folder Lock 10 feature overview for encrypted storage and privacy tools

What it adds to an email-security plan

  • Encrypted lockers: AES-256 protection for files stored inside the locker.
  • Cloud-linked lockers: Encryption is applied before locker data is synchronized through a supported cloud service.
  • Cross-device access: Companion apps are available for Windows, macOS, iOS and Android, with features varying by platform.
  • Controlled collaboration: The sharing workflow can authorize other Folder Lock users without distributing the owner’s account password.
  • Clear boundary: It does not replace PGP, S/MIME, mailbox security or full-disk encryption.
Product guide

Folder Lock, Folder Protect or Folder Lock Lite?

These products overlap in naming, but they are built for different security outcomes. Choose according to whether you need encryption, Windows access rules or a basic concealment tool.

Folder Protect Windows interface for granular file and folder restrictions

Folder Protect

Choose it for: a shared Windows machine where selected files, folders, drives, programs or file types need separate restrictions.

Controls: block visibility, opening, modification or deletion in different combinations.

Important: this is access control, not encryption. Historical stealth-mode support also has Windows-version limitations.

Password lock concept representing basic folder concealment

Folder Lock Lite

Choose it for: basic hiding and locking on older Windows-focused setups.

What is missing: the research material states that the Lite edition does not include encryption.

Important: do not use concealment alone for files that must remain unreadable after copying or disk removal.

Folder Lock Android security app feature overview

iOS and Android Apps

Shared functions: private media and document storage, protected notes and wallets, cloud backup, access-attempt monitoring and a private browser.

Platform differences: Android lists an app-locking tool, while iOS lists Wi-Fi file transfer.

Important: mobile apps are companion vaults, not replicas of every Windows desktop feature.

Selection rule: Use Folder Lock when confidentiality requires encryption. Use Folder Protect when the requirement is granular Windows access control. Use Folder Lock Lite only when simple local concealment is enough.
Local protection

What Folder Lock Actually Protects

The product combines encrypted storage with several optional privacy tools. The distinction matters because a hidden folder, a locked folder and an encrypted locker do not provide the same protection.

Encrypted StorageDesktop LockerCloud LockersPortable LockersProtect FoldersDevice SyncSecure NotesAES-256Windows SafeguardMobile Vault Features

Encrypted Desktop and Cloud Lockers

Folder Lock desktop encrypted locker interface

Files placed inside a locker are protected with AES-256. A Desktop Locker keeps the protected data local, while cloud-linked lockers are designed to work with Dropbox, Google Drive or OneDrive so encrypted locker content can be synchronized.

Portable Encrypted Containers

Folder Lock portable locker controls for removable media

The Windows Safeguard area can create a portable locker for removable media or transfer. This is more appropriate than calling a normal USB drive a “security key,” because it protects stored files rather than providing FIDO authentication.

Protect Folders Is a Separate Control

The Protect Folders function hides or blocks access to selected Windows items without encrypting their contents. It is useful for local privacy, but encrypted lockers are the stronger choice when data could be copied, imaged or removed from the computer.

Sharing and Device Sync

Folder Lock can synchronize supported locker data across linked devices and can share selected encrypted content with authorized users. Recipients should be tested in advance because access depends on the selected sharing or portable-locker workflow.

Secrets and Privacy Utilities

Encrypted secure notes protected inside a private vault

Depending on the platform and plan, the suite includes protected notes, password records and wallet-style entries. Windows also lists secure deletion and history-cleaning tools; those utilities are separate from encryption and should be configured deliberately.

Mobile Vault Features

The mobile editions focus on photos, videos, documents, audio, notes and wallet data. Android adds application locking, while iOS adds local Wi-Fi transfer. Do not assume a desktop-only feature is present on mobile.

PGP Web of Trust vs S/MIME CA Hierarchy

To fully grasp email encryption software, you must understand how identities are verified.

Chained trust relationships illustrating digital identity verification

S/MIME relies on a Certificate Authority (CA). You pay a trusted third party to vouch for your identity. It’s highly structured, making it the preferred email encryption software for corporate outlook environments.

PGP relies on a "Web of Trust." There is no central authority. Users sign each other's keys to vouch for authenticity. This is why you see warnings about an "aead integrity check in pgp key" or verifying fingerprints. It is decentralized and free, but requires active user management.

Hardware vs Software Encryption — Performance Tradeoffs

Software encryption uses the computer’s processor and storage path, so the effect depends on file size, disk speed and workload. Modern processors often handle AES efficiently, but organizations should still benchmark large transfers, virtual machines and backup jobs. Self-encrypting drives move more work into hardware, though cost and management requirements are different.

Practical workflow

How to Send an Encrypted File Without Confusing the Recipient

An encrypted attachment can be practical when the recipient cannot use PGP, but it protects the file package rather than the email itself. Confirm the recipient’s software, file-size limits and recovery expectations before sending sensitive material.

Secure file transfer workflow without sharing an account password
  1. Choose the correct method: use PGP or S/MIME when the message, sender identity and attachment all need an end-to-end email workflow. Use an encrypted container when the main requirement is protecting a file package.
  2. Create a separate transfer container: in Folder Lock for Windows, use a portable locker or an approved sharing workflow rather than sending your everyday Desktop Locker.
  3. Use a unique passphrase: do not reuse the Folder Lock account password, mailbox password or another business credential.
  4. Add and verify the files: place only the intended documents in the container, close it, then reopen it locally to confirm that the password and contents work.
  5. Send through separate channels: transmit the encrypted container by email or another approved service, and deliver the passphrase through a different channel.
  6. Test the recipient workflow: confirm that the recipient can open the selected locker format or has the required Folder Lock account/app before deleting your transfer copy.
Do not send your master credential. A transfer password should be unique to that package, and decrypted temporary copies should be removed from shared or unmanaged locations after use.
Fixes & recovery

Troubleshooting PGP and Local File Protection

Protected device lock screen used for local access security

Can a PGP message be decrypted without the private key?

No legitimate website can bypass correctly implemented PGP encryption. If the required private key or passphrase is gone, recovery may be impossible. Avoid uploading confidential material to sites that claim they can “unlock” encrypted files online.

Why does GnuPG report an integrity or AEAD error?

Common causes include a damaged transfer, a truncated attachment or incompatible software versions. Compare file hashes when available, resend the original file and update both endpoints before assuming that the passphrase is wrong.

What happens if a Folder Lock password is forgotten?

Do not promise that support can restore encrypted data. The supplied materials describe different recovery behavior across older and newer product generations, while several current locker instructions warn that a lost master password can prevent decryption. Store credentials in a separate password manager and test any account-recovery process before placing irreplaceable files in a locker.

Why is a protected folder still not “encrypted”?

Folder Lock’s Protect Folders tool and Folder Protect can restrict or conceal Windows items without changing the underlying file data. Use an encrypted locker when the threat includes disk imaging, copying to another device or removal of the storage media.

Why are features different on another device?

The Windows, macOS, Android and iOS editions are not identical. For example, Safeguard is a Windows desktop capability, Android lists app locking, and iOS lists Wi-Fi transfer. Check the feature list for the exact platform before purchasing or documenting a company process.

Cost and limits

Free, Pro and Platform-Specific Restrictions

Commercial software is not automatically more secure than GnuPG. The paid value is mainly in guided workflows, integrated storage features, official support and reduced training overhead. Plan tables also differ by operating system, so the selected platform must be checked before purchase.

GnuPG / OpenPGP
Folder Lock Free
Folder Lock Pro
Listed price: $0
Listed price: $0
Research-page price: $39.95
Capacity: no product-imposed locker limit
Locker allowance: 1 GB in the supplied plan tables
Locker allowance: listed as unlimited
Devices: installed and managed independently
Synced devices: 2
Synced devices: 5
Typical limitation: manual key and recipient management
Typical limitation: advanced desktop functions are restricted; the Windows table excludes sharing, portable lockers and Protect Folders
Typical advantage: sharing and additional desktop protection tools are enabled, subject to platform support
Pricing note: The supplied pages display $39.95 and also use subscription language. The site should not describe this as a guaranteed lifetime or one-time license. Verify the billing term, taxes, renewal conditions and platform entitlement at checkout.

Platform snapshot: the supplied desktop material lists Windows 10/11 64-bit and macOS 13+. iOS and Android apps are available, but their features are not identical to the desktop editions. The Mac edition omits the Windows Safeguard feature set.

Comparison of data security methods and protection layers
Common questions

Frequently Asked Questions

PGP can encrypt message content or files for a recipient and can add a digital signature. It does not automatically protect the decrypted copy after the recipient saves it to an ordinary folder.
No. Folder Lock protects stored files and can prepare an encrypted package for transfer. It does not encrypt the email body, issue email certificates or replace sender-authentication and key-verification practices.
Folder Lock includes AES-256 encrypted lockers and cross-device storage features. Folder Protect is a Windows access-control product that can separately block viewing, opening, modification or deletion. Folder Protect does not encrypt the underlying file data.
The supplied material describes the Lite edition as a lock-and-hide product without encryption. That may deter casual browsing, but it is not the right choice when copied files or removed storage must remain unreadable.
The supplied desktop requirements list Windows 10 and Windows 11 on 64-bit systems, plus macOS 13 or later. Companion apps are available for iOS and Android. Features vary: Windows has Safeguard, Android lists app locking and iOS lists Wi-Fi transfer.
The supplied plan tables show a 1 GB locker allowance and two synced devices for the free edition. The Windows table withholds sharing, portable lockers and Protect Folders. Other restrictions differ by platform, so check the exact edition before deployment.
No recovery should be assumed. Product generations use different account and recovery mechanisms, and current encrypted-locker guidance warns that a forgotten master password may prevent decryption. Keep a separate credential backup and test recovery in advance.
A normal USB drive can hold a portable encrypted locker, but that does not turn it into a FIDO authentication device. One protects stored files; the other proves identity during sign-in.

More on This Topic

Encryption for Compliance (HIPAA, GDPR)

Encryption can support HIPAA, GDPR and other security obligations, but an algorithm alone does not establish compliance. Organizations also need access controls, retention rules, recovery procedures, audit evidence and endpoint protections. PGP can cover selected transfers, while encrypted local storage can reduce exposure after a file is downloaded.

NIST Post-Quantum Cryptography

As quantum computing advances, traditional RSA keys used in older PGP setups may become vulnerable. Organizations are beginning to look toward lattice-based algorithms (like CRYSTALS-Kyber) to future-proof their secured communications against future decryption threats.

Practical verdict

Use More Than One Layer

Use PGP or S/MIME when the communication itself needs end-to-end confidentiality and identity verification. Use Folder Lock when selected files should remain encrypted on local, removable or supported cloud-linked storage. Use Folder Protect only when a Windows workstation needs granular access rules without encrypting the underlying data.

For device theft, combine file-level protection with full-disk encryption. For business use, document password recovery, recipient compatibility, platform differences and the exact plan limits before rolling the workflow out to employees.

Download Folder Lock free → Review current plan details →