Output encoding converts special characters to safe representations before displaying user input in HTML — preventing browsers from interpreting content as executable code (XSS prevention).
HTML encode: < becomes < > becomes > preventing XSS. Context matters: HTML encoding ≠ JavaScript encoding ≠ URL encoding. Use context-aware encoding libraries (OWASP Java HTML Sanitizer, ESAPI). Never write your own encoder.