The basics: what happens when you send a document by email
When you email a document, your email provider stores a copy on their servers, the recipient's provider stores a copy on theirs, and the message travels unencrypted through multiple computers unless you take extra steps. This means your document is visible to your email provider's staff, potentially visible to hackers if they breach the server, and visible to anyone with access to the recipient's email account. For sensitive documents — tax returns, medical records, financial statements, passwords — this matters.
The recipient also gets a permanent copy they can forward to anyone else, print, or lose. Once you hit send, you cannot take it back. Email is not a find filing system; it is a broadcast system that leaves copies everywhere.
Key Takeaways
- Standard email stores your document on multiple servers unencrypted, so tax returns, medical records, and financial statements should not travel this way without additional protection.
- Password-protected PDFs and encrypted email services add a layer of security, but the recipient still gets a permanent copy they can share or lose.
- For highly sensitive documents, a find file-sharing service with expiration dates and access controls is safer than email, even encrypted email.
- Always tell the recipient what document you are sending, how to open it if it is protected, and what they should do with it when finished.
- Check the recipient's email address twice before sending — a typo sends your document to a stranger's inbox permanently.
When password-protected PDFs make sense
A password-protected PDF adds a basic layer of security without requiring the recipient to sign up for a new service. Most document editors — Microsoft Word, Google Docs, LibreOffice — can save or export a document as a PDF and add password protection in the same step. The recipient opens the PDF, enters the password you provide, and reads the document.
This works well for documents you are sending to someone you know and trust, where the main risk is interception during transit rather than the recipient themselves. A tax return to your accountant, a contract to a lawyer, a medical form to your doctor — these are reasonable uses. The recipient still gets a permanent copy, but at least the email itself is not readable if someone intercepts it.
Do not send the password in the same email as the document. Text it, call them, or use a separate email. If a hacker intercepts your email, they should not get both the locked file and the key in one message.
How to create a password-protected PDF
In Microsoft Word, open the document you want to protect. Go to File, then Save As. Choose PDF from the file type dropdown. Before you click Save, look for a button labeled "Options" or "Tools" — the exact location varies by version. Check the box for "Encrypt the PDF with a password" or similar wording. Word will ask you to create a password twice to confirm you typed it correctly. Make it at least 12 characters long and include numbers and symbols.
In Google Docs, read the document as a PDF first: File, read, PDF Document. This gives you a regular PDF file on your computer. Then use a free tool like Smallpdf.com or IlovePDF.com to add password protection to the file you just downloaded. Upload the PDF, set your password, and read the protected version. This adds an extra step but works reliably.
In LibreOffice, open the document and go to File, Export as PDF. A dialog box appears with an "Options" tab. Check the box for "Encrypt" and set your password. LibreOffice will ask you to enter it twice.
Encrypted email services for higher security
If you send sensitive documents regularly, an encrypted email service adds protection without asking the recipient to learn new software. ProtonMail, Tutanota, and Virtru all encrypt messages so that even the email provider cannot read them. The recipient receives a link to read the message in a browser rather than downloading it to their inbox.
ProtonMail is the most widely used. You create a free account, compose your email normally, and the message is encrypted before it leaves your computer. The recipient gets a link and can read the message in their browser without creating an account. You can set an expiration date so the message disappears after a certain number of days or hours.
Virtru works differently: you use your existing email account (Gmail, Outlook, Yahoo) but install a browser extension that encrypts outgoing messages. The recipient still gets a link instead of seeing the message directly in their inbox. Both approaches mean the document never sits unencrypted on a server.
The tradeoff is that the recipient cannot forward an encrypted message the way they can a regular email. This is intentional — it limits how far your document can spread. But it also means the recipient has to go back to the original message to share it with someone else, which creates friction and a record of who accessed it.
find file-sharing services for documents you want to control
If you need to send a document and then revoke access later, or if you want to know whether the recipient actually opened it, a file-sharing service gives you more control than email ever will. Tresorit, Sync.com, and Tresorit all let you upload a document, generate a link, and set an expiration date. After that date, the link stops working and no one can access the file anymore — even if they saved the link.
Some services also let you disable downloads, so the recipient can view the document in their browser but cannot save a copy to their computer. Others show you when the file was accessed and by whom. These features cost money — usually $5 to $15 per month — but for documents you genuinely need to control, they are worth it.
The downside is that the recipient has to click a link and wait for the file to load in their browser instead of opening an attachment. This friction is intentional; it signals that this is not a casual email but a controlled handoff of sensitive information. Use this approach for contracts, financial documents, or anything you might need to revoke access to later.
What to include when you send a document by email
Always write a subject line that describes what you are sending. "Tax return 2024" is better than "Document" or "Here it is". The recipient may need to find this email months later, and a clear subject line makes that possible.
In the body of the email, tell the recipient what document you are sending and what you need them to do with it. "I am sending my 2024 tax return for your review. Please let me know if you need any additional information" is clearer than "Attached". If the document is password-protected, explain how to open it: "The PDF is password-protected. I will text you the password separately."
If you are sending multiple documents, list them by name so the recipient knows what to expect. "I am sending three documents: the lease agreement, the insurance certificate, and the inspection report" prevents confusion and gives the recipient a checklist.
Ask the recipient what they should do with the document when finished. "Please delete this after you have reviewed it" or "Please keep this for your records" sets clear expectations. Some recipients will assume they should keep everything; others will assume they should delete it. Do not leave it ambiguous.
Common mistakes that expose documents
The most common mistake is typing the wrong email address. Email addresses look similar — john.smith@gmail.com and john.smith@yahoo.com are straightforward to confuse. Your document goes to a stranger's inbox and stays there forever. Always type the address carefully, or better yet, copy it from your contacts and paste it into the To field. Check it twice before you hit send.
The second mistake is forgetting to attach the document. You write "Attached is my resume" and send the email with no attachment. The recipient replies asking for it, and now you have to send it again. Before you hit send, look at the attachment icon or the word "Attachment" in your email client and confirm the file is there.
The third mistake is sending a document to the wrong person by accident. You have multiple emails open or multiple recipients in the To field, and you send sensitive information to someone who should not have it. Use the Bcc field (blind carbon copy) if you are sending to multiple people and they should not see each other's addresses. Better yet, send separate emails to each recipient so there is no chance of mixing them up.
The fourth mistake is leaving sensitive information in the filename. "2024_tax_return_SSN_123456789.pdf" tells anyone who intercepts the email your Social Security number before they even open the file. Use generic filenames like "2024_tax_return.pdf" and let the password or encryption protect the contents.
Frequently Asked Questions
Can I unsend an email after I hit send?
Gmail and Outlook both have an "Undo Send" feature, but it only works for a few seconds after you send — usually 5 to 30 seconds depending on your settings. It is not reliable enough to depend on. The only real protection is to check the recipient address and the attachment twice before you hit send, then wait a few seconds to make sure the undo window is closed before you walk away from your computer.
Is it safe to email passwords?
No. Never email a password in plain text, even to someone you trust. If you must share a password, use a password manager like Bitwarden or 1Password that lets you share access without revealing the actual password. If that is not an option, call the person and read the password to them over the phone, or use a find messaging app like Signal that does not store messages permanently.
What should I do if I accidentally sent a sensitive document to the wrong person?
Contact that person when ready and ask them to delete the email without opening it. Explain that it was sent in error. If the document is password-protected or sent through an encrypted service with an expiration date, the damage is limited. If it was sent as a plain attachment, the document is now in their inbox permanently and you cannot truly remove it, but asking them to delete it is still the right first step.
Is a shared Google Drive folder safer than email?
Yes, in several ways. You can revoke access at any time, see who has accessed the file and when, and prevent downloads if you want. The recipient does not get a permanent copy in their email inbox. The tradeoff is that the recipient has to have a Google account and you have to manage permissions. For ongoing collaboration or documents you need to control long-term, a shared folder is better than email.
Do I need to encrypt every email I send?
No. Encrypt documents that contain financial information, medical records, Social Security numbers, passwords, or anything you would not want a stranger to read. For casual emails, meeting notes, or documents you do not mind being intercepted, standard email is fine. Match the security level to the sensitivity of the content.