How to Send a Password by Email (and Why You Usually Shouldn't)

Short answer: don't put the password itself in an email. Put a one-time link in the email and give the passphrase another way. Email is fine for the link precisely because the link holds nothing readable.

Why email is a bad place for a password

  • It is stored, at both ends, indefinitely. In your Sent folder, the recipient's inbox, both providers' servers, and every backup, archive, and device that syncs either mailbox.
  • It is protected in transit, not end to end. TLS between mail servers stops eavesdropping on the wire, but each provider can read the message, and so can anyone who gets into either account.
  • It is searchable. "Password" is the first search an attacker runs in a compromised mailbox.
  • It gets forwarded. Into a ticket, to a colleague, to a personal address. Each copy lives on.

What about "confidential" or encrypted email?

  • Gmail confidential mode adds an expiry date and blocks forwarding in the Gmail interface, but it is not end-to-end encryption: Google can still read the message, and the EFF has criticised it for giving a false sense of security.
  • Microsoft 365 message encryption protects the message in transit and controls access, but the content is still held by the sending and receiving organisations.
  • S/MIME and PGP do provide end-to-end encryption, but both sides need keys set up in advance. If you and the recipient already have that, use it — most people don't.

None of these make the password disappear after it has been read, which is the property you actually want.

Sending a password over email, safely

  1. Create a one-time link at oncepad.com. Your browser encrypts the password under a generated seven-word passphrase; the server only ever holds ciphertext.
  2. Email the link. It carries no key, so the email — and every copy of it — reveals nothing. Mail scanners that open links cannot burn it either: opening the link only shows a prompt.
  3. Send the passphrase by a different route: a phone call, a text message, or a chat app.
  4. The recipient enters the words and sees the password once. It is then deleted from the server — or after 24 hours if they never open it.

If you must send it in plain email anyway

Send a temporary password and require it to be changed at first login; never send the username and password in the same message; and delete the message from your Sent folder afterwards. Treat any password that has been through plain email as something to rotate.

Source: the EFF's analysis of Gmail's confidential mode.