Skip to content

Send Email Over A Secure Tls Connection

knowledge.workspace.google.com April 29, 2026

Transport Layer Security (TLS) is a protocol that encrypts email messages for security and privacy. TLS prevents unauthorized access of messages when they're sent over internet connections.

To use TLS for messages sent to and from domains and addresses that you specify, use the Secure transport (TLS) compliance setting. This setting includes options to require a CA-signed certificate, verify the hostname associated with the certificate, and test the TLS connection.

When composing a new message in Gmail, a padlock image to the recipient address means the message will be sent with TLS. The padlock shows only for accounts with a Google Workspace subscription that supports S/MIME encryption .

Before setting up TLS in your Google admin console, verify the TLS versions supported by any compliance, security, or other standards used in your organization. Not all standards support the TLS versions that Google Workspace supports.

If the standards used in your organization require TLS, enable it with the Secure transport (TLS) compliance setting.

The Secure transports (TLS) compliance setting affects delivery of messages sent over non-TLS connections, for the addresses and domains specified in the setting.

In the Google Admin console, go to Apps Google Workspace Gmail Compliance .

Requires having the Gmail Settings administrator privilege .

In the Add setting box, enter a name for the setting and take these steps:

Select Inbound , Outbound , or both. You must use an address list to enforce TLS for inbound and outbound messages. You'll set the address list in the step.

For address list matching, Gmail uses the From: sender for inbound messages and the recipients for outbound messages. For inbound messages, the From: sender must exactly match an address or domain in the setting. Authentication requirements are checked for outgoing messages.

Select Outbound - messages requiring Secure Transport via another setting for outbound messages that have other secure connection settings. For example, you can set email routing to send outbound messages through a secure connection, or you can set an alternate secure route for outbound messages.

To select an existing address list that has the domains or email addresses that require TLS connections:

To create a new address list with the domains or email addresses that require TLS connections:

Select setting options:

Require CA signed certificate (Recommended)—Requires the client SMTP server to present a certificate signed by a trusted Certificate Authority.

Validate certificate hostname (Recommended)—Verifies that the receiving hostname matches the certificate presented by the SMTP server.

At the bottom of the Add setting box, click Save . The new setting appears in the Secure Transport (TLS) compliance settings table.

You can monitor changes in the Admin console audit log .

If you get an error when setting up TLS, follow the recommendations in this section.

If you click Test TLS connection and get a certificate validation error, messages sent from your organization will bounce, even though you could save the new mail route.

To fix the error, try one or more of these solutions:

Important: We recommend keeping these options turned on whenever possible so the connection can be verified.

Send email over an alternate secure route (TLS)

Extracted Entities