Email is not encrypted by default, so your documents travel through multiple servers in plain text unless you take specific steps

When you send a document through regular email, it passes through your email provider's servers, your recipient's provider's servers, and potentially several others in between. None of these servers scramble the contents by default. Anyone with access to those servers — a malicious employee, a hacker who breaches them, or someone intercepting the connection — can read what you sent. If the document contains sensitive information like tax returns, medical records, or financial statements, this is a real problem.

You have three practical routes: use your email provider's built-in encryption, password-protect the document before sending it, or use a file-sharing service that encrypts files. Each has different trade-offs in terms of setup time, recipient experience, and how much protection you actually get. The right choice depends on what you're sending and who you're sending it to.

Key Takeaways

  • Regular email sends documents unencrypted through multiple servers, so anyone with access to those servers can read them.
  • Gmail, Outlook, and Yahoo all offer built-in encryption features that work without asking your recipient to install anything new.
  • Password-protecting a PDF or Word document before sending it adds a layer of security but only works if you share the password through a separate channel.
  • File-sharing services like Tresorit or Sync.com encrypt files on their servers and let you set expiration dates or revoke access after sending.
  • The most secure approach combines two methods: encrypt the file and send the password separately, or use a service that requires a password to download.

Using your email provider's built-in encryption

Gmail, Outlook, and Yahoo all have encryption features built in. They work differently, so the method depends on which provider you use.

Gmail's Confidential Mode lets you set an expiration date on the email and prevent the recipient from downloading, printing, or copying the message. To use it, open a new email, click the lock icon at the bottom of the compose window, then set an expiration date (anywhere from one hour to five years) and choose whether to require a passcode. If you require a passcode, you send it to the recipient through a separate channel — a phone call, a text message, or a different email. The recipient sees the message in their browser but cannot save it as a file. This works well for sensitive information you want to disappear automatically, but it does not protect the document itself if the recipient takes a screenshot.

Outlook's Encrypt feature (available in Outlook.com and Microsoft 365) scrambles the entire message so that only the recipient can read it. Click the "Encrypt" button in the toolbar, and Outlook will ask whether to require a passcode. If you do, the recipient gets a separate link to enter the passcode before reading the message. This is stronger than Gmail's Confidential Mode because the message itself is encrypted, not just restricted. The downside is that the recipient cannot forward the encrypted message to someone else — they would have to copy and paste the contents into a new email.

Yahoo Mail's Secure Compose works similarly to Outlook. Click the lock icon, set an expiration date, and optionally require a passcode. The message is encrypted end-to-end, meaning Yahoo's own servers cannot read it.

Password-protecting documents before you send them

If your email provider does not offer encryption, or if you want the recipient to have a permanent copy of the document, password-protecting the file itself is a straightforward option. This works with PDFs, Word documents, Excel spreadsheets, and most other file types.

For PDF files, open the document in Adobe Acrobat (not the free Reader). Go to File > Properties > Security, then choose "Password Security". Set a password that the recipient must enter to open the file. Save the document and send it. Tell the recipient the password through a separate channel — never in the same email as the attachment.

For Word and Excel files, open the document, go to File > Info > Protect Document, and select "Encrypt with Password". Type a password and confirm it. Save the file and send it. Again, share the password separately.

The weakness of this method is that you have to send the password through a different channel, which adds friction. If you send the password in the same email as the attachment, you have gained nothing — anyone who intercepts the email gets both. But if you are already in contact with the recipient by phone or text, this is quick and effective.

Using file-sharing services with encryption

Services like Tresorit, Sync.com, and Virtru are designed specifically to send sensitive files securely. They encrypt files on their servers and let you control access after you send the link.

Tresorit encrypts files before they leave your device, so even Tresorit cannot read them. You upload the document, set an expiration date (or leave it open indefinitely), and optionally require a password. You send the recipient a link. When they click it, they can download the file, but once the expiration date passes, the link stops working. You can also revoke access at any time, even after the recipient has downloaded the file — the next time they try to open it, it will not work. This is useful if you send a document and then realize you made a mistake or want to prevent further sharing.

Sync.com works similarly but focuses on file storage and sharing. You upload a document, create a shareable link, and set permissions like "view only" or "download allowed". You can require a password and set an expiration date. The main difference from Tresorit is that Sync.com is more of a storage service than a one-off sending tool, so it is better if you plan to share files regularly.

Virtru integrates directly into Gmail and Outlook, so you do not have to leave your email. You compose an email normally, click the Virtru button, and set an expiration date and password. The recipient gets an email with a link to read the message securely. Virtru encrypts the message end-to-end, and you can revoke access or set the message to self-destruct.

The trade-off with these services is that the recipient has to click a link and potentially enter a password, which is slightly more friction than opening an attachment. But you get much more control — you can see when they opened the file, revoke access, and set automatic expiration.

Combining methods for maximum security

The most secure approach is to use two methods together. For example, password-protect the document and send it via email, then send the password through a separate channel. Or upload the file to Tresorit, set a password, and call the recipient to give them the password.

This is called two-factor authentication for documents. Even if someone intercepts the email with the attachment, they cannot open it without the password. And even if someone gets the password, they cannot download the file without the link. You are not relying on a single point of security.

Use this approach when the document is highly sensitive — financial records, legal documents, medical information, or anything that could cause real harm if leaked. For less sensitive documents, a single method is usually enough.

What to avoid when sending sensitive documents

Do not send sensitive documents through public Wi-Fi without using a VPN. Public Wi-Fi networks are easy to intercept, and even encrypted email can be vulnerable if your connection is not secure. If you are at a coffee shop or airport, use a VPN service like Mullvad or ProtonVPN before sending anything sensitive.

Do not use file-sharing services that do not encrypt files on their servers. Dropbox, Google Drive, and OneDrive are convenient, but they store files in plain text on their servers. They are fine for sharing non-sensitive documents, but not for tax returns or medical records. If you want to use these services, password-protect the document first.

Do not assume that because a service is "secure" it is secure for your specific use case. Read the privacy policy and see where files are stored, whether the company can read them, and what happens if the company is hacked. Tresorit and Sync.com publish detailed security documentation. Services that do not are worth avoiding.

Frequently Asked Questions

Can the recipient forward an encrypted email to someone else?

It depends on the service. Gmail's Confidential Mode prevents forwarding entirely. Outlook's Encrypt feature allows copying and pasting but not forwarding the encrypted message itself. File-sharing services like Tresorit let you control whether the recipient can download the file, but once they have it, they can share it however they want. If you need to prevent further sharing, use a service that lets you revoke access.

What if I send a document and then realize it contains a mistake?

If you used Gmail Confidential Mode or Outlook Encrypt, you cannot unsend the message, but it will expire automatically on the date you set. If you used a file-sharing service like Tresorit or Virtru, you can revoke access immediately, and the recipient will no longer be able to open the file. Regular email attachments cannot be unsent or revoked once delivered.

Is password-protecting a document enough on its own?

It is better than nothing, but only if you send the password separately. If you send the password in the same email as the attachment, an attacker who intercepts the email gets both and the password protection is useless. Always use a separate channel for the password — a phone call, text message, or different email sent hours later.

Do I need to pay for secure file-sharing services?

Most services offer free plans with limits on file size or number of shares per month. Tresorit's free plan allows one share per month. Sync.com's free plan gives you 5 GB of storage. Virtru is free for Gmail users. If you send sensitive documents regularly, a paid plan is worth the cost, but for occasional use, free plans work fine.

What is the difference between encryption and password protection?

Password protection scrambles a file so it cannot be opened without the password, but the file itself is still readable if someone guesses or cracks the password. Encryption scrambles data using a mathematical key that is nearly impossible to crack without the correct password or key. Email encryption and file-sharing services use encryption. Password-protecting a document uses password protection. For maximum security, use both.