By Glenn Fleishman
Is your secure iMessage conversation actually secure?

Apple introduced iMessage within Messages in 2011 as its house-brand, end-to-end encrypted messaging product. The promise of iMessage is that posts are always encrypted, using servers and technology developed by Apple and controlled by it. The encryption keys reside on your device, stored so Apple can’t access them, and no third party should ever have the leverage to retrieve them. (There’s a big proviso there, which I’ll explain at the end of this article.)
Despite exploits uncovered over the many years since iMessage first appeared, the core protocol has never been breached, only device exploits or iCloud-backup extractions that allowed access to stored messages. That’s a strong track record. Apple has continued to tinker with improving iMessage encryption, while also adding an optional method of ensuring conversation integrity, Contact Key Verification.1
But in researching the update for Take Control of FaceTime and Messages, a lengthy ebook that covers those two apps plus the Phone app 2, I discovered you could be lulled into a false sense of security based on what you assumed iMessage was and was not.
The odds of this change in standards causing a security breach and your messages being exposed seem unlikely, at least right now. But after scrolling through conversations and seeing what’s going on, I feel Apple has omitted important signals for users when iMessage suddenly stops being used during a conversation.
When is an iMessage not an iMessage?
Messages supports four kinds of communications, each with its own encryption standards and limitations, except for iMessage:
- iMessage: iMessage is always encrypted, but you may not always be using iMessage in an iMessage conversation, which is a confusing thing to say—bear with me.
- RCS: The Android-standard RCS is encrypted only if every non-Apple device in the conversation has a recent-enough version of RCS that supports encryption and its carrier also allows it.3
- SMS/MMS: SMS and MMS are never encrypted. (SMS allows text only; MMS supports rich media and group messaging. RCS is intended as the ultimate replacement for MMS.)
Apple sensibly organizes messages into conversations: a series of messages with another person or in the same group of people. However, that presentation method intentionally hides most of the details about how different communications protocols may be used within a single conversation. Apple likes to keep things simple.
As you start a conversation, Messages offers all sorts of visual signals that let you know when you’re using iMessage, as reassurance and branding:
- The person’s email address or phone number appears in blue.
- At the very start of the conversation, iMessage appears on a line by itself and a lock icon plus Encrypted appears on the next line. (You can always scroll way back to the start of a conversation and find this.)
- In the conversation, your messages are shown in blue.
- Click or tap the conversation profile image or images, and in the Info pane, at the very bottom, a message in gray in small type notes “All iMessage conversations are securely encrypted end-to-end, so they can’t be read while they’re sent between devices.”
That feels like a lot of reinforcement of the point! And, when you’re using iMessage, you probably expect you’re always using it throughout a conversation. But within an iMessage conversation, things can go wrong, and the system downgrades to the next commonly available option.
The hierarchy of Messages standards ranks, from most to least desirable:
- iMessage
- RCS with encryption
- RCS
- MMS
- SMS
The impact of that hit me while revising my book: when iMessage isn’t available, Apple tells you only inline. Despite all the information Messages displays about iMessage being encrypted, the inverse state is faint. This kind of negative knowledge, or information about something not happening, can often be as important as something that does happen. A warning about a fuel tank approaching empty is the kind of information every driver (or pilot) needs, for instance. If you think end-to-end encryption—or Apple-based encryption—is critical for you, then a pop-up message or other warning is what you would expect.

Look through the images in this story to see real-world examples I encountered this summer. In one, my wife and I are texting in a conversation that goes back almost two decades. For unknown reasons, Messages couldn’t perform a secure interchange—no security warning appeared, but something prevented iMessage from doing its usual handshake dance. So it defaulted without an alert to RCS, and noted that inline (see the figure’s top).
Because Messages supports RCS encryption, it can use it with other iCloud users, too, allowing encryption to continue even though it’s not iMessage encryption. Then, equally oddly, it went right back to iMessage (see near bottom).
If a conversation switches to an unencrypted communications method, there’s no warning; only, as you can see in another example, the gray inline message in a group chat of iMessage users (encrypted) shifted to unencrypted RCS when I added someone whose device didn’t support iMessage or encrypted RCS.

So how can you be sure what’s in use without scrolling around for sure? At any given time, the Info pane always shows the current state of encryption. This figure below shows two RCS conversations: on the left, an unencrypted one; on the right, an end-to-end encrypted session.

Because it’s RCS, Apple won’t vouch for the integrity of the session on the right! The Messages label reads “Apple can’t verify the software used on receiving devices,” and provides a link with more technical information and disclaimers. This is fair: Apple is relying on an infrastructure it doesn’t control.
With the above scenarios, I don’t believe Apple is putting us in jeopardy, nor do I think you should be particularly worried about it, unless you’re someone already in a high-risk category, like a political figure, human-rights advocate, or journalist. However, I keep thinking about how what we don’t know can still hurt us.
If you’d like to prevent Messages from downgrading security, you have options, although they may not be fully desirable. All of these are managed on an iPhone at Settings: Apps: Messages. You can’t control these message settings from an iPad or Mac.
- Disable downgrading to SMS: Turn off Retry as Text Message. This may mean some messages you send won’t get through. Also, this doesn’t prevent other people in an iMessage (or encrypted RCS conversation) from sending you SMS or MMS messages if they can’t transmit via iMessage.
- Disable RCS Messaging: In RCS Messaging, disable RCS Messaging. You can’t disable only non-encrypted RCS, which is a shame, as that would be my suggestion as the next best thing. Instead, you have to disable it entirely to prevent iMessage from downgrading to either unencrypted or encrypted RCS.
- Disable MMS Messaging: Messages may try to send MMS even when it doesn’t try to use SMS, so disabling MMS Messaging will prevent that as well.
This set of options and Messages’ presentation of encryption feels overdue for an overhaul.
Protecting Messages in iCloud
I mentioned at the outset there was a proviso about accessing stored messages. The one exception to the end-to-end encryption rule is if you have iCloud for Messages enabled. In certain configurations, someone who manages to gain access to your Apple Account could retrieve an iPhone or iPad backup, retrieve that backup, and use an encryption key stored in it to decrypt messages and extract your data. That someone could be a law-enforcement agency, not just a hacker.
Because the Messages in iCloud encryption key is stored in the clear in the backup, this is the one scenario in which Apple can be compelled to provide information under the right legal framework that would allow a government-connected agent to examine your iCloud-synced messages. This is also an exploit that a criminal or other party could take advantage of.
You can avoid this end-to-end encryption loophole in one of two ways:
- Enable Advanced Data Protection for iCloud. This option adds end-to-end encryption on top of nearly all your data (excluding email, calendar entries, and contacts) stored in iCloud. This is a good move generally, though there are drawbacks: you may lose full data recovery if all your devices are stolen, lost, or destroyed. See the complete list. (ADP is not available in the United Kingdom.)
- Disable iCloud Backups. Without backups, the Messages data isn’t archived via a restorable backup to iCloud, and thus the Messages in iCloud encryption key isn’t uploaded into that backup. Backing up to your Mac (or a Windows machine) requires more effort, though most of what you want to retain is likely synced via iCloud! Read this support document for the difference between iCloud Backup and backing up to a computer.
I suggest picking one. While, again, it’s unlikely your privacy would be breached, most of modern life feels like it’s about finding out how your privacy was, in fact, breached. Why not take action before that happens, however much we trust Apple’s infrastructure and integrity?
- Contact Key Verification may be overkill for most people, but it’s still good that Apple made it universally available. I explained how it works in 2023 for TidBITS. ↩
- The update to this book is due out in the next week or so, covering the version 27 operating systems. However, you can purchase the current version now and receive a free update. ↩
- Google says the latest version of Google Messages is required, but doesn’t list a version number. On the Apple side, your device needs a version 26.5 or later release, and you have to be on a supported carrier. Most carriers support encrypted RCS, but not all! ↩
[Glenn Fleishman is a printing and comics historian, Jeopardy champion, and serial Kickstarterer. His current books in preparation, which you can pre-order, are Flong Time, No See, and That One Matt Bors Comic. Other books include Six Centuries of Type & Printing and How Comics Are Made.]
If you appreciate articles like this one, support us by becoming a Six Colors subscriber. Subscribers get access to an exclusive podcast, members-only stories, and a special community.