Email was not designed to be private, and most of the risk with a sensitive document is not interception — it is the copy that sits in an inbox for years, and the forward you never see.
Remove or cover anything the recipient does not need, put a password on the PDF, and send that password through a different channel — a message or a call, not the same email. It takes about a minute and closes the most common ways a document leaks.
Mail between major providers is encrypted in transit these days, so somebody reading it off the wire is not the realistic threat. What actually happens to sensitive documents is duller and more common:
Your sent folder and their inbox, both searchable, both synced to whatever devices those accounts are on, long after the reason for sending it has passed.
Onward to a colleague, an agent, a family member. Every hop is another copy you no longer control, and the original message usually travels with it.
Autocomplete picks the wrong contact with the same first name. This is the single most common way a document ends up somewhere it should not be.
A mailbox compromised next year still contains everything you sent this year. Old attachments are a standing liability.
A password on the file addresses most of this: a forwarded or misdirected PDF is not readable, and a breached mailbox yields a locked file. It does not stop a recipient who has the password from doing whatever they like with the contents — no technical measure does.
The most reliable way to protect a piece of information is to not send it. Bank statements asked for as proof of address do not need every transaction. A passport page sent to a hotel does not need the visa stamps. An ID sent for age verification does not need the full document number.
The redaction guide goes through that verification properly, including why a black rectangle drawn in a general markup tool is not the same thing.
Two things to know. The password cannot be recovered — lose it and the file is gone, which is the point. And the protection lives in the file itself, so it travels with the document wherever it is forwarded. Details in password-protect a PDF on iPhone.
A password included in the same email as the attachment protects nothing at all. Whoever ends up holding one holds both. Send it through a different channel — a text message, a messaging app, a phone call — and it stays useful.
Say what the file is when you send the password, and nothing more. "Password for the tenancy PDF I just emailed" is enough; the password itself does not need the document attached to it a second time.
For anything recurring — an accountant you send records to every quarter — agree a scheme once rather than inventing a password each time, and change it when the relationship ends.
Cloud storage changes the shape of the problem: the file lives in one place you control, and you can revoke access later — impossible with an attachment, which is copied the moment it is sent.
That only holds if the link is actually restricted. A share link set to "anyone with the link" is a public URL that happens to be hard to guess, and it stays valid after it has been forwarded. For sensitive material, share to a named account rather than a general link, set an expiry if the provider offers one, and password-protect the file anyway — belt and braces cost nothing here.
Scanning to cloud storage covers getting the document up there in the first place.
What counts as reasonable care depends on what you are sending. A rough guide:
Send only the page that was asked for. Where the recipient allows it, mark the scan with its purpose so a copy cannot easily be reused elsewhere. Password-protect it. See scanning an ID card and scanning a passport.
Cover account numbers and unrelated transactions when the request is only about your name, address, or balance.
Send the specific report requested rather than a whole file, and check whether the organisation has a secure portal — most do, and it is a better route than email.
Password protection matters less than making sure the signed version is the one that goes, and that the copy you keep matches it. See signing a PDF.
Being clear about the limits is part of doing this properly. A password stops someone opening the file; it does not stop the person you sent it to from saving it, printing it, screenshotting it, or forwarding the contents. Once a recipient can read a document, they can keep it.
Nor does any of this help if the request itself is the problem. The most expensive document leaks start with someone convincing a person to send something they should not have — a landlord who does not need a full bank statement, an "employer" asking for a passport before an interview. Before securing the file, it is worth asking whether it should be sent at all, and to that address.
Everything described here happens on your device: the scan, the redaction export, and the password are all applied locally before the file goes anywhere.
Mail between major providers is encrypted in transit, so the realistic risk is not interception. It is that the attachment sits in two mailboxes indefinitely, can be forwarded, and can go to the wrong contact. Password-protecting the file addresses all three.
Open the document, tap More then Export, keep the format as PDF, and turn on password protection. Enter a password, export, and attach that copy. The recipient's PDF reader asks for the password before it shows anything.
Send only the page that was asked for, cover details the recipient does not need, and password-protect the file. Also worth asking whether the request is legitimate — for anything official, a portal or an in-person check is safer than email.
Every mainstream PDF reader supports password-protected files, so the usual cause is a mistyped password. Passwords are case-sensitive, and a phrase of a few words is easier to relay accurately than a short string of symbols.
No. The protection has no back door, which is what makes it worth using. Keep the unprotected original in your own library and treat the protected copy as the version you send.
It can be, because you can revoke access later, which is impossible with an attachment. That advantage only holds if the link is restricted to named people — an 'anyone with the link' URL stays valid after it is forwarded.