Migrate messages to Gmail as client-side encrypted email

If your organization has messages in another service or in another encryption format, then as an administrator, you can migrate those messages to Gmail as client-side encrypted messages in the S/MIME format. 

Migrated messages that include a digital signature and encryption will render safely in Gmail with inline images, hyperlinks, and attachments visible.

Some services may allow users to create S/MIME messages without a digital signature and have publicly-known vulnerabilities. When those “encrypt-only” messages are imported into Gmail, the messages are displayed in a safe format that suppresses possible exploits. This means that Gmail client-side encryption (CSE) will not display inline images, hyperlinks, or attachments in the user interface, although the underlying message continues to retain all of its content. 

Migrating S/MIME-encrypted messages

Gmail CSE natively supports the standard S/MIME message encryption format that is also used by Microsoft and other email services. If you are migrating encrypted S/MIME messages from a Microsoft service into Gmail, then you can migrate encrypted messages unchanged.

For Gmail CSE to decrypt and display S/MIME messages that were previously in a Microsoft service, the user accounts with Gmail must be configured with the same S/MIME user certificates that were used in the Microsoft environment. You must also set up the Gmail API and Gmail CSE for your users using the same certificates present in the Microsoft service. For details, see Gmail only: Configure S/MIME certificates for client-side encryption

After the Gmail accounts are configured with the S/MIME certificates, you can migrate messages from the Microsoft service into Gmail. For details, see Migrate your data to Google Workspace.

Migrating non-S/MIME formats and plain text archives

If your organization has messages that are encrypted in a non-S/MIME format, or has plain text archives that you'd like to encrypt before migrating, use the Gmail CSE Migration Utility to convert messages into the S/MIME format used by Gmail CSE.

To use the migration utility to transfer your messages:

  1. Export the encrypted messages from your service provider. 
  2. If the messages are encrypted, decrypt the mail messages to plaintext using the tooling provided by your non-S/MIME encryption vendor. 
  3. After the messages are decrypted into plaintext, use the Gmail CSE Migration Utility to encrypt your messages locally and migrate them to Gmail CSE.

 

 

Was this helpful?

How can we improve it?
13620096546203848119
true
Search Help Center
true
true
true
true
true
73010
false
false
false
false
Search
Clear search
Close search
Main menu