Mastodon DMs are not end-to-end encrypted. In theory admins could manually see DMs in their server's database. (The same is true on Twitter/X etc.)
If you want encrypted communications, I'd recommend XMPP (aka Jabber). It is federated into servers like Mastodon, but designed for encrypted messaging & calling.
There's a non-technical site to help people sign up on existing servers:
@FediTips if you're totally mad you could use gpg to encrypt the messages before sending. Assuming the person you're trying to talk to has a public key
There's an encrypted messenger called @delta which pretty much does that for email, it sends encrypted contents via unencrypted email. It means existing email accounts can be turned into encrypted chat accounts, as long as the other person is using Delta too. (And you can chat with non-Delta email users as long as you're okay with non-encrypted messages.)
@FediTips@LonM@delta I wrote several French-speaking PDFs (which haven't been peer-reviewed, and such a topic is unlikely to be of any interest to the academic community anyway) calling for dropping this outdated norm. I've been mostly inspired by Latacora and one of their titles could be translated to “Keyoxide is to cryptography what mercurial Lego would be to aerospace” – it's mostly a dangerous teenager practice