← Back to the blog
Sunset Docs blog

How to send sensitive information by email (and when not to)

Encrypt the file and share the password another way, or use Gmail or Outlook encryption. Learn what each option protects and when to skip email.

The safest way to send sensitive information via email is often not to attach it at all: if the recipient offers a secure upload link or portal, use that instead. If email is the only option, encrypt the file with a strong password and share that password through a different channel, such as a phone call, or use your mail provider's encrypted or confidential mode while understanding its limits.

This guide explains each option, what it actually protects, and the situations where email is the wrong tool. It is practical guidance, not legal advice for a specific organisation.

Why a plain attachment is risky

An ordinary attachment is a copy that you cannot take back. Once sent, it can sit in your Sent folder, the recipient's inbox, forwarded threads, downloads folders and backups, each with its own retention rules.

The transport between mail servers is usually encrypted, but not always. The UK National Cyber Security Centre explains that the STARTTLS mechanism used between mail servers "is not a flawless technique" and that a mail service still needs to accept mail without TLS to reach everyone. Even when the connection is encrypted, the message is readable in each mailbox it reaches.

The most common failure is simpler: the wrong recipient. The Information Commissioner's Office describes a case where a staff member emailed a file containing special category data of 241 people to the wrong address. Because the file was neither encrypted nor password protected, everyone who received the email could access the data.

Option 1: encrypt the file and send the password separately

This works with any email provider and any recipient.

  1. Save the document as a PDF or Office file, or place it in an archive.
  2. Protect it with a password using the encryption option in your PDF editor, office suite or archive tool. If the tool offers a choice of method, pick AES-256.
  3. Use a long passphrase that nobody could guess from the context. Avoid the recipient's date of birth, phone number or ID number.
  4. Email the encrypted file with a neutral subject line, such as "Documents you requested".
  5. Share the password through a different channel: a phone call, a text message or in person.

The ICO is direct about the last step: you should communicate the key over a separate channel and "do not include the password within the same email as the encrypted file attachment". A password sent in a second email to the same address protects little, because anyone who can read one message can usually read the other.

Limits: once the recipient decrypts the file, they hold an ordinary copy. Encryption protects the file in transit and at rest in mailboxes. It does not control what happens after it is opened.

Option 2: Gmail confidential mode

Gmail's confidential mode lets you set an expiry date, remove access early, and require an SMS passcode. Recipients cannot forward, copy, print or download the message or its attachments from Gmail's interface, according to Google's help page.

Google's own documentation also states the limits:

  • Recipients "can still take screenshots or photos" of the message, and recipients with malicious programs may still copy or download it.
  • Gmail replaces the message content and attachments with a link. Recipients on other email services see a link and receive a passcode by email unless you choose the SMS option.
  • It is not end-to-end encryption. Google offers end-to-end protection as a separate feature, client-side encryption, which an administrator must set up and which is only available in certain Google Workspace editions.

Confidential mode is useful for limiting casual forwarding and for cutting off access after a deadline. It is not a reason to send something you would not trust the recipient's provider and devices to hold.

Option 3: Outlook and Microsoft Purview Message Encryption

Microsoft 365 business accounts can use Microsoft Purview Message Encryption, and Outlook.com mailboxes linked to a Microsoft 365 Personal or Family subscription have a similar option. There are two main choices:

Option What recipients can do Main limit
Encrypt Read, reply, copy, print and forward Protects the message from outsiders, not from the recipient
Do Not Forward Read and reply, but not forward, print or copy in supported clients PDFs and images can be downloaded without encryption

The attachment detail matters. Microsoft states that with Do Not Forward, Word, Excel and PowerPoint attachments stay encrypted after download, but "all other attachments, such as PDF files or image files, can be downloaded without encryption". For business tenants, Microsoft advises that if an attachment is not an Office document that supports inherited protection, you encrypt the file before you attach it.

Recipients outside Microsoft 365 open the message in a web portal, either by signing in with a Google, Yahoo or Microsoft account or with a single-use code. Microsoft notes that each passcode expires after 15 minutes.

What about PGP and S/MIME?

Both encrypt the message itself, end to end, and both work well between people who have already set them up. The catch is setup: the NCSC notes that this approach requires both sides to have the necessary trust infrastructure in place, which is unlikely with most customers or one-off contacts.

Decision table: which option fits your situation

Situation Safer option
The recipient has an upload portal or secure link Use it. Do not email a copy as well
One file to a known contact who uses any email service Encrypted file, password by phone or text
Both sides use Microsoft 365 Encrypt or Do Not Forward, and encrypt PDFs or images separately
You use Gmail and want an expiry date Confidential mode with SMS passcode, knowing it is not end-to-end
Regular exchanges with the same partner PGP or S/MIME set up once, or a shared portal
Several recipients Separate messages, or Bcc so addresses are not exposed
A request you did not expect asks for documents Call the organisation on a number you already know before sending anything
Passwords, full card numbers, private keys Do not email. Use the organisation's dedicated channel
You must keep the document for years Not email. Store it in your organisation's records system

Use the table as a starting point. Your organisation's own policy and any sector rules come first.

When not to use email at all

Some information should not travel by email even when encrypted. Login credentials and private keys give access to everything else, so a leak is hard to contain. Full payment card details can be used for fraud as soon as they are exposed. Health, criminal record or children's data calls for a channel your organisation has approved for that category.

Email is also a poor fit when you need to know who opened a document, when it was deleted, or that nobody kept a copy. Mail systems are built to deliver and keep messages, not to expire them.

If you are the business receiving the documents

If customers regularly email you IDs, payslips or bank statements, the safer fix is on your side. Give them a secure upload link for document collection instead of an email address. The customer opens the link, uploads the files and needs no account or password exchange.

Sunset Docs works this way: your team views watermarked page images rather than the original file, every document has a deletion date, and opens, prints, downloads and deletions are logged. It does not stop someone photographing a screen, and it does not remove copies a customer already sent elsewhere, so ask them not to email the same files as well.

The comparison of upload portals and email attachments goes deeper into that choice.

Questions

Is email encrypted by default?

Usually only in transit between servers, and only when both servers support it. The message is stored readable in each mailbox, so anyone with access to the account can open it.

Is a password-protected PDF enough?

It is reasonable for a one-off exchange if the password is long, not guessable from the context, and shared through another channel. A short password or one sent in the same thread gives little protection.

Does Gmail confidential mode work if the recipient uses Outlook?

Yes. The recipient receives a link instead of the content and opens it with a passcode sent by email, or by SMS if you chose that option. The same limits apply: they can still photograph or screenshot what they see.

I sent sensitive information to the wrong address. What now?

Ask the recipient to delete it and confirm in writing. If you used confidential mode, remove access from your Sent folder. A business that leaked personal data must assess the risk, and in the UK report it to the ICO where feasible within 72 hours if a risk to people is likely.

Should I delete the email after sending it?

Deleting your Sent copy reduces your own exposure, but it does not recall the recipient's copy or remove backups. Agree with the recipient how long they will keep the file.

A company asked me to email a copy of my passport. Should I?

Ask whether they have an upload link first. If you must email it, encrypt it, share the password by phone, and consider adding a watermark that states the recipient, purpose and date.