The safest way to send sensitive documents is to encrypt them before they leave your computer, then send the encrypted file through email
Email itself is not encrypted by default. When you send a document as an attachment, it travels through multiple servers in plain text — visible to your email provider, your recipient's email provider, and anyone who intercepts the message in between. If the document contains financial records, medical information, or identity details, this exposure is a real risk.
You have three practical routes: encrypt the file before sending it, use a service that encrypts on your behalf, or use end-to-end encrypted email. Each has different trade-offs in security, ease of use, and what your recipient needs to do on their end.
Key Takeaways
- Encrypting a file with a password before you send it is the most straightforward method and works with any email account.
- Your recipient needs the password to open the file, so send the password through a separate channel — never in the same email as the attachment.
- Services like Tresorit, Sync.com, and Virtru add encryption without requiring your recipient to install software or create an account.
- End-to-end encrypted email (ProtonMail, Tutanota) offers the strongest protection but requires both sender and recipient to use the same service.
- Never rely on email's "recall" or "unsend" features — once sent, assume the message is permanent.
Encrypting files with password protection before sending
The simplest method is to encrypt the file itself, then send the encrypted file as an attachment. On Windows, right-click the document, select "Compress to ZIP file", then open that ZIP file, right-click it again, and choose "Send to" → "Compressed (zipped) folder". Windows will prompt you to set a password. On Mac, right-click the file and select "Compress", then use a tool like The Unarchiver (free) to add password protection to the resulting ZIP file.
For more control, use 7-Zip (Windows, free) or Keka (Mac, free). Both let you encrypt a file with AES-256, the same encryption standard banks use. Open the tool, drag your document into it, set a strong password, and it creates an encrypted file you can email safely.
The critical step: send the password separately. Text it to your recipient, call them with it, or use a messaging app — never include the password in the same email as the attachment. If someone intercepts the email, they have the encrypted file but not the key to open it.
Using cloud services that encrypt for you
Tresorit, Sync.com, and Virtru handle encryption automatically. You upload the document to their service, generate a secure link, and email that link instead of the attachment itself. Your recipient clicks the link, and the file downloads encrypted. The service never sees the unencrypted content.
Tresorit and Sync.com are encrypted cloud storage services — you store files there and share links with password protection and expiration dates. Virtru is an email plugin that encrypts attachments inside Gmail, Outlook, or Apple Mail without leaving your email account. With Virtru, your recipient opens the attachment directly in the email, but it stays encrypted until they authenticate.
The trade-off: these services require you to trust the company running them. Tresorit and Sync.com are based in Switzerland and Hungary respectively, where privacy laws are stronger than in the US. Virtru is US-based but has published security audits. All three are paid services with free tiers that limit storage or the number of shares per month.
End-to-end encrypted email services
ProtonMail and Tutanota encrypt all messages and attachments by default, so nothing is readable by the email provider or anyone intercepting the message. Both are free with paid upgrades. The catch: your recipient must also use the same service, or you must send them a link to read the message on the web.
If you send a ProtonMail message to someone with a Gmail account, they receive a notification with a link. They click it, set a password, and read the message in their browser — but they do not need a ProtonMail account. This is more secure than standard email but less convenient than just attaching a file.
End-to-end encryption is the strongest option because even the email provider cannot read your messages. However, it requires either both of you to switch email services or your recipient to use a web interface each time. For one-off document sends, the password-protected file method is usually more practical.
What not to do: common mistakes that weaken security
Do not use email's "recall" or "unsend" feature as a security measure. These features only work if the recipient has not opened the message yet, and they do not actually delete the message from the recipient's device or the email provider's servers. Once you hit send, assume the message is permanent and could be forwarded, screenshotted, or recovered from backups.
Do not send the password in the same email as the encrypted file. If someone intercepts that email, they have everything they need. Do not use a weak password like "password123" or your recipient's name — use at least 12 random characters with uppercase, lowercase, numbers, and symbols.
Do not assume that because you deleted the email from your sent folder, it is gone. Your email provider keeps copies on their servers, and your recipient's provider keeps a copy too. Encryption is the only way to ensure the content itself is unreadable to anyone but the intended recipient.
Comparing your options at a glance
| Method | Setup time | Recipient needs | Strongest for |
|---|---|---|---|
| Password-protected ZIP file | 2 minutes | The password (sent separately) | One-time sends, no account needed |
| Tresorit or Sync.com | 5 minutes (first time) | To click a link | Sharing multiple files, setting expiration dates |
| Virtru | 10 minutes (install plugin) | To authenticate in email | Gmail or Outlook users who want encryption built in |
| ProtonMail or Tutanota | 15 minutes (create account) | A ProtonMail/Tutanota account, or to use web link | Ongoing secure communication, strongest encryption |
Choosing the right method for your situation
If you are sending a document once to someone you know, password-protected encryption is the fastest option. You spend two minutes encrypting, send the file and password separately, and you are done. Your recipient does not need to create an account or install anything.
If you send sensitive documents regularly to the same people, set up Tresorit or Sync.com. You upload once, generate a link, and can revoke access later if needed. This is useful for ongoing work with contractors, accountants, or lawyers.
If you use Gmail or Outlook daily and want encryption built into your normal workflow, Virtru is worth the setup time. It turns every email into an encrypted message without changing how you work.
If you want the strongest possible protection and are willing to ask recipients to use a web interface or switch email services, ProtonMail or Tutanota are the right choice. They protect not just attachments but the entire message, including the subject line.
Frequently Asked Questions
Can I encrypt a document if I do not have admin access to my computer?
Yes. Use an online encryption tool like Encrypt.to or OnlineConvert to upload your file, set a password, and download the encrypted version. You do not need to install software. Be cautious with online tools — use them only for documents you are comfortable uploading to a third-party server, and choose tools with clear privacy policies.
What if my recipient cannot open the encrypted file?
On Windows, they can right-click the encrypted ZIP file and select "Extract All", then enter the password. On Mac, they double-click it and enter the password. If they use a phone or tablet, they may need a file manager app like Files (iOS) or Files by Google (Android) to extract the ZIP. If they still cannot open it, send them the file through Tresorit or Sync.com instead — those services handle extraction automatically.
Is it safe to send passwords through text message?
Text message is more secure than email for passwords because text messages are not stored on email servers and are harder to intercept in bulk. However, if the recipient's phone is compromised, the password is visible. For highly sensitive documents, call them with the password instead — it leaves no written record.
Do I need to encrypt documents if they do not contain personal information?
Not strictly, but encryption protects more than just content. It also hides the fact that you are communicating with someone, the file size, and when you sent it. If the document is not sensitive, standard email is fine. If you are unsure, encrypt it — the extra step takes two minutes and costs nothing.
What happens if I send an encrypted file to the wrong person?
If you sent the password separately, they cannot open the file without it. If you sent the password in the same email, they can open it. This is another reason to always send the password through a different channel. If you realize the mistake immediately, contact your email provider — some allow you to delete messages before they are opened, though this is not may provide to work.