Payslips, tax returns, medical letters, bank statements and HR documents travel by email every day, and email is easy to misdirect, forward or leave sitting in a shared inbox. Adding a password to the PDF means that whoever ends up with the file still can’t read it without the password. This guide explains what a PDF password actually protects, how to choose one, how to encrypt a PDF without uploading it, and how to get the password to the recipient safely.
Why encrypt a PDF before you email it
Email wasn’t designed for confidential documents. A message can be sent to the wrong “Sam”, forwarded on without a second thought, synced to several devices, and kept in sent and received folders for years. Many services encrypt messages while they travel between servers, but the attachment sits readable in every mailbox it reaches.
Encrypting the PDF itself changes that. The protection travels with the file: a misdirected email, a forwarded attachment or a copy on a lost laptop all stay unreadable without the password. It’s a small step that addresses the most common way personal documents leak, which is simply ending up in the wrong place.
What a PDF password does, and doesn’t, do
PDFs support two passwords with different jobs:
- The open password encrypts the document. Protect PDF uses AES-256, the strongest encryption method the PDF standard offers. Without the password, the content is unreadable, not just hidden.
- The permissions password controls what people may do once the document is open, such as printing or copying text. These restrictions are instructions to the PDF reader; well-behaved readers follow them, but they aren’t encryption.
So for confidentiality, the open password is the part that matters. Permissions are useful for signalling intent (“please don’t edit this”) but shouldn’t be relied on to stop a determined recipient.
Choosing a password that’s strong and usable
AES-256 is far beyond brute-force attack in practice, so the weak point is always the password. Someone who obtains the file can try guesses as fast as their computer allows, without any lockout. That makes common choices risky:
- Avoid dates of birth, names, postcodes, account numbers and anything else that’s printed in the document or easy to find online.
- Avoid very common passwords and keyboard patterns. The strength hint in Protect PDF flags these as you type.
- Prefer a passphrase of three or four random words with a number, such as
maple-orbit-lantern-42. Length does most of the work, and it’s easy to read out over the phone.
If you’d rather not invent one, press Suggest a strong password. The suggestion is generated in your browser; copy it into your password manager or message before you download.
Step by step: encrypt a PDF on your device
- Open Protect PDF and choose the file. It’s processed in your browser tab, never uploaded.
- Type the password twice, or use Suggest a strong password. The strength hint updates as you type, and the tool tells you if the two entries don’t match.
- Set permissions if you want them (optional; see below).
- Download. The file is named after the original with -protected on the end. Before handing it over, the tool checks that the result really is encrypted and opens with your password.
- Test it. Open the protected copy yourself. Your PDF reader should ask for the password before showing anything.
Encryption is done by qpdf, a long-established open-source PDF library, running inside your browser. Neither the document nor the password leaves your device, and the password isn’t stored once the job finishes.
If the PDF is already protected, unlock it first with Unlock PDF using its existing password, then protect it again with the new one.
Permissions explained
| Permission | What it controls | When you might turn it off |
|---|---|---|
| Printing | Whether the document can be printed | Draft documents you don’t want circulating on paper |
| Copying text and images | Selecting and copying content | Discouraging copy-paste reuse of a report |
| Editing | Changing pages and adding comments | Final versions you don’t want annotated |
| Filling in forms | Typing into form fields | Completed forms that shouldn’t be changed |
Restrictions are protected by a separate permissions password, which must be different from the open password. If you leave it blank, Protect PDF sets a long random one that nobody sees, so the restrictions can’t simply be lifted later with a known password. Remember that compliant readers honour these settings and others may not; they’re a signal, not a lock.
Sharing the password safely
Encrypting the file achieves nothing if the password travels in the same email. Send it by a different route:
- A text message or messaging app to a number you already know is theirs.
- A phone call, which is where a passphrase of real words pays off.
- An agreed password for regular documents. For monthly reports to the same accountant, agree a strong password once, in person or by phone, and reuse it for that relationship only.
Avoid putting hints in the email (“the password is your surname”) and avoid sending the password as a follow-up email a minute later; anyone with access to the inbox gets both.
Protecting several documents at once
If you’re sending a pack, say three months of payslips and a bank statement for a rental application, one protected file is easier for everyone than four. Combine them first with Merge PDF, check the order, then protect the merged file once. The recipient enters one password instead of four, and you only have one password to share.
If the source documents arrived password-protected themselves, Merge PDF asks for each password as you add the file and saves the combined document without them, so protecting the result with your own new password is the natural last step. Large scanned packs may also need Compress PDF before protecting, because many email services cap attachments, often at around 20–25 MB.
What encryption doesn’t cover
- The email itself. The subject line, message body and the attachment’s file name aren’t encrypted. Don’t name the file Jane-Smith-HIV-test-result.pdf; something neutral is better.
- What happens after opening. Once the recipient opens the file, they can screenshot, photograph or retype it. Encryption protects the file, not the information once it’s been shared with the right person.
- Forgotten passwords. Nobody can recover them, us included. Keep your unencrypted original safe.
- Visible labelling. If you want readers to see that a document is confidential, add a watermark such as CONFIDENTIAL as well. A watermark marks a document; the password protects it.
Checklist: strong passphrase, AES-256 encryption, test the protected copy, neutral file name, password sent by a different route, original kept safe.
Frequently asked questions
How secure is a password-protected PDF?
With AES-256 encryption, the content can’t be read without the password, so security comes down to how strong the password is. A long passphrase of random words is very hard to guess; a date of birth is not.
Will the recipient need special software?
No. Current PDF readers, including those built into browsers, phones and computers, ask for the password and open the file.
Can I password-protect a PDF without uploading it?
Yes. Protect PDF encrypts the file inside your browser, so neither the document nor the password is sent to a server.
What if I forget the password?
It can’t be recovered: we never see or store it, and strong encryption has no back door. Keep the unencrypted original somewhere safe, or store the password in a password manager.
Do permissions stop people copying or printing?
Only in PDF readers that respect them. Many do, but some don’t, so treat permissions as a polite request. The open password is what actually protects the content.