GUIDE · UPDATED APRIL 2026 · 3 MIN READ

Email confidentiality disclaimers: what they are worth and how to write one

Does the "This message and its attachments are confidential" block carry any real weight? What it brings, what it does not, and how to write one if it is needed.

IN BRIEF
  • A disclaimer creates no contractual obligation for a recipient who never agreed to it.
  • Its value is mainly evidential: it shows an intention of confidentiality.
  • It is justified mostly in sectors where misdirected email is frequent and costly.
  • Three lines are enough: beyond that it goes unread and weighs down every message.

“This message and its attachments are confidential and intended solely for the addressee. If you have received this message in error, please delete it.” That block sits at the bottom of millions of business emails. Its real weight is more limited than its solemn tone suggests.

This article presents general reasoning. Whether a disclaimer is relevant in your situation is a matter for your counsel.

What a disclaimer does not do

This has to be said plainly, because the opposite illusion is widespread.

It creates no contractual obligation. A contract requires agreement. A recipient who discovers the clause after opening the message never agreed to it. It is hard to see how they could be held to an obligation they never signed up to and discover at the end of their reading.

It prevents nothing. If the message goes to the wrong recipient, the clause does not make it unreadable. It politely asks them to destroy a message they have already read.

It does not protect against a leak. A malicious recipient is not stopped by a paragraph.

What it genuinely brings

Its value is evidential rather than binding, and that value is not nil.

It shows that the sender considered the information confidential. In a dispute over whether information was confidential — a trade secret, data covered by a non-disclosure agreement — that consistent expression of intent can be a contextual element.

It also plays an internal role, often underestimated: its presence reminds employees they are handling sensitive information. It is as much a signal of company culture as a legal device.

Finally, in some sectors it is part of professional expectation: its absence, at a law firm or a consultancy, would be noticed.

When it is genuinely justified

The useful criterion is simple: is misdirected email frequent and costly in your business?

It is for a law firm, an accountancy practice, an HR department handling individual files, a mergers and acquisitions team, a medical service. The disclaimer makes sense there.

It is much less so for a sales team discussing public offers, or a support team answering technical questions. A systematic disclaimer on innocuous messages dilutes the signal: when everything is marked confidential, nothing is.

How to write one if it is needed

Three lines, not ten. A long block goes unread, and it stacks up on every reply in a conversation.

One language, unless there is a real need. Doubling the disclaimer in another language doubles its length for generally no benefit — see bilingual email signatures.

A sober register. Threatening formulations in capitals produce the opposite of the intended effect.

A compact wording:

This message and its attachments are confidential. If you are not the intended recipient,
please let us know and delete it.

Two lines, and the essentials are there.

A frequent confusion worth clearing up: the confidentiality disclaimer and the legal identification notices are two distinct things.

Identification notices — company name, legal form, registration, registered office — can be mandatory depending on your legal form and your activity. They are covered in mandatory legal notices.

The disclaimer is an optional clause, added at the sender’s initiative.

Both sit in the same place — at the foot of the signature, in small type — but they have neither the same nature nor the same necessity.

Worth knowing: if you keep a disclaimer, lock it in the template. An employee rewriting their signature generally deletes it without thinking, and you lose the consistency that was its only evidential value.

The question to ask internally

Rather than carrying forward a block inherited from a template found ten years ago, put the question to your counsel: in our business, does this disclaimer bring anything?

The answer is sometimes yes, often no. In the second case, removing it lightens every message your organisation sends — several hundred thousand a year — with nothing lost.

That decision is one of those a signature policy is meant to settle once and for all, rather than leaving it to each person’s judgement.

Frequently asked questions

Is a confidentiality disclaimer mandatory?
No, it is not a mandatory legal notice under company law. It is a clause the sender adds on their own initiative, to be distinguished from identification notices, which can be mandatory.
Does a disclaimer legally bind the recipient?
Hardly. A clause discovered after receipt, which the recipient never agreed to, creates no contractual obligation for them. Its weight is mainly evidential: it shows the sender's intention of confidentiality.
How long should a disclaimer be?
Three lines at most. Ten-line blocks go unread, weigh down every message and stack up in threads, which makes them counterproductive.
Should it be added to every message?
That depends on your business. In sectors that routinely handle sensitive information, yes. Elsewhere, a systematic disclaimer on innocuous exchanges dilutes the signal until it stops working.

Roll out your signature with Signally

Build your template for free, then deploy it across the organisation from your admin console.

Create my signature