How do you securely send documents via email?
Quick answer
Don't rely on email itself to be secure, because it isn't encrypted end to end and your document is readable by the mail providers at both ends. Encrypt the file before you send it, using a document open password at 256-bit AES, then give the recipient that password by text or phone call rather than in the same email. For anything genuinely sensitive, send a link to a controlled location you can expire or switch off instead of attaching the file at all.
Key facts
- Mail between the major providers is normally encrypted in transit with TLS, but it is not end-to-end encrypted. Providers may encrypt stored mail at rest, but they hold the keys, so the message and its attachments are readable to the provider and to anyone with access to either mailbox.
- Adobe Acrobat offers three encryption strengths when you set an open password. Choosing compatibility with Acrobat X and later gives you 256-bit AES, Acrobat 7 and later gives 128-bit AES, and Acrobat 6 and later gives the much weaker 128-bit RC4.
- A document open password stops the file being opened. A permissions password only stops the security settings being changed, so on its own it does not keep anyone out.
- Gmail confidential mode does not encrypt anything end to end. Google keeps the message body and attachments on its own servers and sends the recipient a link, which is also why it can expire and revoke access.
- Google's own help page states that recipients of a confidential-mode email can still take screenshots or photos, and that recipients running malicious software may still be able to copy or download the message.
- Microsoft Purview Message Encryption sends external recipients a wrapper email pointing at a portal, where they authenticate with a Microsoft, Google or Yahoo account to read the message.
- Emailing the password in the same thread as the encrypted file cancels out the encryption. Anyone who can read one message can read both.
Email is encrypted on the way and readable once it lands
Most people assume encryption in transit means the document is private, and it doesn't. Mail between Gmail, Outlook and the other big providers almost always travels over TLS, so nobody is reading it off the wire, but it is not end-to-end encrypted. Providers generally encrypt stored mail at rest, but they hold the keys, so the message is readable to their systems and to anyone who gets into either mailbox: a postcard in a locked van, where the journey is fine and whoever holds the keys can still read it.
Password the file, then send the password somewhere else
The version that actually holds up takes about ninety seconds: in Acrobat, open the document, go to the protect tools and encrypt with a password, set a document open password rather than a permissions password, and set compatibility to Acrobat X and later so you get 256-bit AES instead of the old RC4. Then text the password or ring them, because a password pasted into the same thread protects nothing, and I have watched perfectly sensible people do exactly that under deadline pressure.
A link you can switch off beats an attachment you can't
Once a file is in someone's inbox it is theirs forever, which is the real argument for sending a link instead. Gmail's confidential mode is a version of this: Google holds the content on its own servers and sends a link, which is how the expiry and revocation work, although Google's documentation admits it cannot stop a recipient photographing the screen. It is also roughly the shape of what I build, so worth being plain about the limits. LiveDocument puts a PDF and a recorded video walkthrough behind one link with expiry and revocation, which helps when you need to explain a document as well as protect it, but it is not encryption, has no watermarking or NDA gating, and is not a data room, so for a genuinely confidential contract the password belongs on the file itself or the document belongs in something like DocSend. Years of sending proposals taught me that most "secure email" failures are not cryptographic anyway: they are the wrong attachment, the stale version, or the password sitting in the same thread.
The Bottom Line
Email is fine as a delivery route and poor as a container, so protect the document rather than the message: encrypt the file and pass the password through a different channel, or send a link you can expire when the deal is done.
Written by Cameron James