Last reviewed: Next review due:
Why encrypted messaging matters for journalists
Standard SMS and unencrypted email are not confidential. Your mobile operator can read SMS messages; your email provider can read your emails; and both can be compelled to produce records by court order or by law enforcement requests under the Investigatory Powers Act 2016. For most journalism this is fine — but for any communication involving a confidential source, an unencrypted channel creates an evidence trail that can expose the source.
End-to-end encrypted (E2E) messaging solves this by encrypting messages on the sender’s device, so that only the recipient can decrypt them. The service provider never sees the message content. The practical caveat: encryption protects messages in transit. Once a message arrives on a device, it is only as secure as that device.
Tool comparison
Open-source, audited Signal Protocol. Minimal metadata collection. Disappearing messages. Phone number required (use a separate SIM for high-risk work). Best for journalist-source messaging and calls.
Swiss-based, zero-access encryption for stored emails. E2E encrypted between ProtonMail users; standard encryption to non-ProtonMail addresses. Good for initial contact from unknown sources.
German-based encrypted email with calendar. E2E between Tutanota users; password-protected for external recipients. Open-source clients. Very similar to ProtonMail in practice.
E2E encrypted messaging and calls, designed for teams. Allows username login without a phone number. Useful for newsroom-wide secure communications. Audited. Less popular than Signal for individual source contact.
E2E encrypted message content (Signal Protocol). However, Meta collects significant metadata. Backup to iCloud/Google Drive may not be E2E encrypted by default. Acceptable for low-sensitivity conversations; not for sensitive sources.
Standard SMS has no encryption. iMessage is E2E encrypted between Apple devices but backups to iCloud may expose messages. SMS records can be subpoenaed from mobile operators. Do not use for source communications.
Red flags
- Communicating with a sensitive source via standard SMS or unencrypted email.
- Using your work email account (hosted by a third party) for source communications.
- WhatsApp backups enabled on iCloud or Google Drive without additional encryption.
- Not using disappearing messages for sensitive source conversations.
- Using Telegram (not E2E by default — only "Secret Chats" are encrypted) as if it were Signal.
- Sharing source information over Slack or Microsoft Teams (not E2E encrypted, employer can read).
Encrypted messaging checklist
- I have Signal installed and have shared my Signal number with my most sensitive sources.
- I have enabled disappearing messages (set to a time appropriate to the sensitivity of the story).
- I have a ProtonMail or Tutanota address I can share publicly for initial source contact.
- I have confirmed that sources know not to contact me via standard SMS or plain email for sensitive matters.
- I have reviewed whether my WhatsApp backups are encrypted end-to-end (WhatsApp settings > Chats > Chat backup > End-to-end encrypted backup).
- I have not discussed unpublished source identities over Slack, Teams, or work email.
- For very high-risk sources: I have directed them to the newsroom's SecureDrop or OnionShare address instead.
Source protection tools
Use our source protection checklist to assess whether your communication setup is adequate.
Common mistakes
- Treating Telegram as equivalent to Signal — Telegram chats are not E2E encrypted by default.
- Ignoring metadata: even Signal reveals who you contacted and when to a network observer.
- Using the same phone number for Signal that is linked to your professional identity.
- Forgetting that cloud backups (iCloud, Google) may contain unencrypted message copies.
- Not briefing sources on how to use Signal before they need it urgently.
Related guides
Primary sources
Frequently asked questions
Is Signal really end-to-end encrypted?
Why is WhatsApp not good enough for sensitive sources?
Should I use a secure email provider or just Signal?
What is disappearing messages and should I use it?
Related guides
Primary sources
- Signal Protocol Documentation— Signal Foundation
- ProtonMail Security Model— Proton
- Communicating with Others Securely— Electronic Frontier Foundation
- Mobile Security for Journalists— Freedom of the Press Foundation
- Email Security Guidance— National Cyber Security Centre
- Investigatory Powers Act 2016— legislation.gov.uk
- Journalist Safety Resources— Reporters Without Borders