Are VoIP calls encrypted?
A VoIP call can travel encrypted: TLS encrypts the call signaling (who is calling whom), and SRTP encrypts the voice itself. This way even someone listening on the network cannot hear the call or tell who was dialed.
What encryption is, and why it matters for the phone
Encryption turns information into a sequence that looks meaningless, so that only someone holding the "key" can turn it back into its original form. You use it every day: the small padlock in the browser when you log in to your bank online is a sign of encryption.
In a VoIP call, the voice becomes packets of data that travel over the network — on the office network, at the internet provider, and on the way to the server. Without encryption, anyone who manages to listen to the traffic at one of those points can, with the right tools, put the packets back together into voice. With encryption, they see only noise.
There are two things you can protect in a call, and each has its own method: the signaling — who is calling, whom, when, and which keys were pressed — and the media, meaning the voice itself.
TLS and SRTP — two layers
TLS (Transport Layer Security) is the same technology that protects websites. In telephony it wraps the SIP messages — the messages that manage the call: registering the extension, "I'm dialing this number," "the call was answered." When SIP is used over TLS, it is sometimes called SIPS.
SRTP (Secure Real-time Transport Protocol) is the secure version of RTP, the protocol that carries the voice. It encrypts each voice packet separately, without adding noticeable delay.
| Layer | What it protects | Without it, someone can see |
|---|---|---|
| TLS | Call management and registration | Who called whom, when, and sometimes account details |
| SRTP | The voice itself | What was said in the call |
The important thing to understand: one without the other is partial protection. TLS without SRTP hides whom you called but not what you said. SRTP without TLS hides the voice, but the voice encryption keys are exchanged through the signaling — so you usually turn on both together.
How far the encryption reaches
This is the point most people miss. The encryption applies to the segment between your device — an IP phone or an app — and the PBX. When a call stays inside the PBX, from extension to extension, and both are encrypted, the whole path is protected.
But a call that goes out to a regular phone line or a mobile phone passes from the PBX to the public telephone network. From there it travels like any phone call, under the rules of the telephone network, and not with your encryption. In other words: VoIP encryption protects your network and the internet, not the other side of the call.
One more point: call recording is done on the PBX itself, so an encrypted call can still be recorded if you set up recording. Encryption protects against someone listening along the way, not against the PBX that handles the call.
What is needed for it to work
- Support on both sides — in the phone or app, and in the PBX. Most professional phones support TLS and SRTP, but you need to turn it on in the settings.
- Security certificates — as with websites, the server presents a certificate that proves it really is the right server. An expired certificate can cause phones to stop registering.
- Ports in the firewall — an encrypted connection usually uses a different port from the regular connection, and you need to make sure it is open for outgoing traffic.
- The right clock on the device — certificate checking depends on the date. A device with a wrong clock may reject a valid certificate.
Who it matters to most
Every organization has an interest in privacy, but some care more: law and accounting offices, clinics and therapists, institutions that handle sensitive information about students and families, and employees who connect from public networks — a café, a hotel, a station.
On a public Wi-Fi network in particular, a phone app without encryption exposes the call to anyone connected to the same network. Here the difference between encrypted and unencrypted is real.
Common mistakes
- Thinking that encryption prevents a break-in. It prevents eavesdropping. Misuse of an extension is guarded against with passwords and restrictions — see Phone Fraud.
- Encrypting only some of the devices and assuming everything is protected.
- Forgetting the outside party — a call to a mobile phone is not encrypted end to end.
- Turning encryption off "because something wasn't working" and not turning it back on after the real problem was found.
A full example: a law office that also works from home
An office with six lawyers. Three sit in the office with IP phones on a network cable, two work half the week from home with software on a computer, and one is often in courts with an app on a mobile phone. The calls include details about cases, which is exactly the kind of organization that encryption matters to.
Inside the office the network is private, and the risk of eavesdropping is low. The problem is in the other two places: the home network of a lawyer working from the living room, and the Wi-Fi network of the café near the courthouse. There, without encryption, anyone connected to the same network can in principle listen to the traffic.
The practical solution: turn on TLS and SRTP in the app and in the software of the employees outside the office, and make sure the PBX accepts encrypted connections. The phones in the office can stay as they are, or join later. The encryption protects the segment between the device and the PBX; a call that goes out to a client on a regular line continues from there over the telephone network like any call.
What is encrypted and what isn't — a table
| Segment | Without encryption | With TLS + SRTP |
|---|---|---|
| From the office phone to the PBX | Visible on the office network and along the way | Encrypted |
| From a mobile app to the PBX | Visible on public Wi-Fi | Encrypted |
| Between two encrypted extensions | Visible | Encrypted end to end through the PBX |
| From the PBX to a regular phone line | According to the telephone network | According to the telephone network — the encryption doesn't continue there |
| Recording of the call on the server | Stored with the provider | Stored with the provider — a separate matter from encryption along the way |
The last row is important: encryption along the way and protecting the recordings are two different subjects. Recordings are protected with permissions — who is allowed to listen — and a limited retention period.
Encryption versus the other layers of protection — what each one solves
| Layer | What it protects against | What it doesn't protect against |
|---|---|---|
| Call encryption (TLS + SRTP) | Listening in on a call along the way, finding out whom you called | Misuse of an extension, access to the control panel |
| Strong extension passwords | Password guessing and registration of a foreign device | Listening on a public network |
| Restricting login by address | Login to management from a foreign location | Calls by an employee outside the office |
| Recording permissions | Recordings being heard by people who shouldn't hear them | What happens to the call along the way |
| Firewall at the office | Access to the internal network | A call that has already gone out to the internet |
The bottom line: encryption is one layer among several, and not a substitute for any of the others. An organization that encrypts its calls but leaves the password 1234 on an extension has protected the wrong thing.
Three questions before you decide
- Who works outside the office, and from which network? An employee at home with their own router — low risk. A representative who answers from cafés and shopping malls — here encryption makes a difference.
- Which calls are the most sensitive? A clinic, a law office, an institution's admissions committee — sometimes you encrypt only those extensions first.
- What does the equipment support? Apps and software almost always support it. An old phone or a simple adapter — not necessarily, and that affects the order of the work.
A short history: from an open phone line to an encrypted call
The old copper lines had no encryption at all: anyone who connected a device to the pair of wires heard the call. The only protection was physical — the wires ran inside walls and locked cabinets belonging to the phone company.
When telephony moved to the internet, in the 1990s and early 2000s, the problem became more visible: voice packets travel over shared networks, and simple tools can capture them. The answer came from the internet world itself: TLS, which already protected websites and email, was adapted for call management; and SRTP was defined specifically for encrypting voice, in the early 2000s.
Today both standards are supported by most professional phones and apps. What has changed in the last decade is not the technology but the expectation: encryption went from an add-on for advanced users to something people ask for by default, just like the padlock in the browser.
How to know it's working
- On many IP phones, a small padlock icon appears on the screen during an encrypted call.
- Apps and software usually have a status line or a setting that shows "TLS" or "Secure".
- In the PBX control panel, you can usually see which protocol the extension is registered with.
- A simple test: an internal call between two encrypted extensions. If it goes through and sounds good, the setting is correct.
Mistakes and surprises along the way
- An expired certificate. As with websites, security certificates have an expiration date. When one expires, all the phones stop registering at once. A good provider renews it in advance.
- One device doesn't support it. An old phone or a simple adapter sometimes doesn't support SRTP. The solution: leave it unencrypted and know that, or replace it.
- A clock that isn't set. Certificates are checked against the time. A device with a wrong time will reject a valid certificate.
- A firewall that blocks the encrypted port. An encrypted connection uses a different port than usual, and it needs to be opened.
How it works with us at Kesher
Call encryption is a subject worth discussing before setup. If it matters to your organization, tell us in the very first conversation, and we'll check together what is right for you.
We'll go over the full picture with you: which devices you have or will have, who works outside the office and from which networks, and which calls are the most sensitive. From that we'll decide what to set up.
Even if encryption isn't at the top of your priorities, there are basic steps that protect the lines: a strong password that the system generates for each extension, and restricting access to the control panel by IP address.
FAQ
Are VoIP calls encrypted by default?
Not always. It depends on the PBX, the device and the settings. It's worth asking the provider explicitly, and not assuming.
What is the difference between TLS and SRTP?
TLS encrypts the call management — who called whom, and when. SRTP encrypts the voice itself. For full protection you need both.
Does encryption hurt call quality?
Usually not in a noticeable way. Encryption adds a little processing, and modern devices handle it easily.
If a call is encrypted, can it still be recorded?
Yes. The recording is done on the PBX, which is a party to the call. Encryption protects against someone listening along the way.
Does encryption slow the call down?
Not noticeably. The extra work the device does is very small compared with encoding the voice itself, and the added delay is measured in milliseconds.
If only some of the employees are encrypted, is it still worth it?
Yes. Encryption matters mostly in places you don't control — a home network, public Wi-Fi, a hotel. It's better to protect the people who work from there first, and expand later.
Does the customer on the other end hear anything different when the call is encrypted?
No. Encryption is completely transparent to both sides — no sound, no noticeable delay and no change in quality. The only difference is that someone listening to the network along the way hears a meaningless stream instead of voice.
Do the phones inside the office need to be encrypted too?
It's not required, but it makes things tidier: when everything is encrypted, you don't have to remember which device is protected and which isn't. On most professional phones it's a setting you turn on once.
What is the difference between encryption and a VPN?
A VPN encrypts all of a device's traffic to a single point, and from there it continues as usual. TLS and SRTP encrypt the call itself all the way to the PBX, regardless of the network. You can combine them, but for telephony, dedicated encryption is simpler and more stable.