"A client asked us to send a list of personal information as an email attachment, so I attached an Excel file and sent it as usual. Afterward, someone internally asked, 'Did you verify that the recipient is actually qualified to manage that data?' and I broke into a cold sweat. Since it was already sent, there was no way to delete it from the recipient's computer. We exchange quotes and rosters via email every day, but worrying about every single message feels endless"—we received this consultation from a staff member at a professional services firm. While email is an everyday tool, the self-evident fact that sent information can never be retrieved is surprisingly easy to overlook.
Gmail includes a feature called Confidential mode that helps alleviate these concerns. It allows you to set expiration dates, prevent forwarding and downloading, or revoke access after sending. However, it is not an all-powerful shield. In this article, we examine what this feature can and cannot accomplish from the perspective of an organization deciding how and when to deploy it.
Emails become the recipient's property the moment they are sent
Standard emails are duplicated into the recipient's mailbox the instant they are dispatched. The recipient can save them, print them, forward them to others, and take screenshots. The sender has no way to control how the message is handled thereafter. As seen in the opening consultation, realizing only after sending that the recipient might not be suited to safeguard the data means it is already too late.
Measures against misdirected emails—sending to the wrong address entirely—were discussed in our article on Gmail misdelivery and data leakage countermeasures. While that guide addressed preventing delivery to unintended recipients, this article focuses on controlling message handling after sending to the correct recipient. These are distinct issues, and both require safeguards.
What Confidential mode can do
Messages sent with Confidential mode treat the message body and attachments differently from regular email. Key capabilities include the following.
- Set expiration dates: Configure access to expire after 1 day, 1 week, 1 month, etc., preventing the recipient from opening it afterward
- Disable forwarding, copying, printing, and downloading: These action buttons are disabled within the recipient's Gmail interface
- Revoke access after sending: Senders can revoke access at any point post-delivery
- Require an SMS passcode: Recipients must enter a verification code sent to their mobile phone before opening the message
For example, in scenarios where "this estimate is valid until the end of the month, so access shouldn't be allowed afterward" or "we want only the direct contact to see this, without it being forwarded internally," Confidential mode offers tighter control than normal email. Another advantage is that recipients do not need special software; they can open the message through standard operations.
"Screenshots cannot be prevented": understanding the limitations
Because misunderstandings here can be dangerous, let us state this clearly: Confidential mode cannot prevent recipients from taking screenshots or capturing the screen with an external camera as long as the content is displayed. Disabling forwarding or download buttons cannot technically prevent capturing what appears on screen. In other words, this is not encryption meant to guard secrets against malicious actors; it is more accurately understood as a mechanism to prevent well-meaning recipients from accidentally forwarding or indefinitely archiving sensitive files.
If data sensitivity demands that "not even Google should be able to view the contents" or "decryption must be strictly restricted to specific recipients," Confidential mode is insufficient. In such cases, the mechanisms discussed in our article on Client-Side Encryption (CSE), or storing the files directly in Google Drive and managing access rights there, are far more suitable. A realistic strategy involves differentiating among standard email, Confidential mode, and encryption or Google Drive sharing depending on the sensitivity of the information.
Implementing the feature into company operations
If left to individual discretion, Confidential mode ends up as a feature used only occasionally by those who happen to know about it. To make it effective organization-wide, administrative settings and operational rules must be paired together. In the Admin console, administrators can choose whether to enable or disable Confidential mode across the entire company. Once enabled, establishing clear operational guidelines—such as requiring Confidential mode for emails containing personal information, quotes, or contracts—and sharing them with staff will minimize inconsistent decision-making.
Furthermore, combining Confidential mode with automated systems that detect, warn against, or block emails containing specific keywords or sensitive data creates a defense that does not rely solely on human vigilance. Running these automated detections as an ongoing operational process rather than a one-off setup is explored in our article on maintaining ongoing DLP operations. Confidential mode demonstrates its true value when positioned as one component within that broader operational architecture.
"We want our company to rethink the practice of exchanging confidential information over email in the first place." "We want to establish rules for choosing between confidential mode, encryption, and Google Drive sharing based on how sensitive the information is." "We want to stop relying on individual attentiveness and automatically block risky emails." If you share any of these concerns, feel free to contact GleamHub via our Google Workspace operations support. We will work alongside you to design a setup that tightens the handling of confidential information without disrupting your daily email workflows.









