MaarifaStudio
← The journal
· 4 min read

Is it safe to send a password by email? No — and here is why.

Not because anyone was careless. Because email does not move a message — it copies one. Where those copies end up, why the password someone sent you is still sitting in them, and the single thing that makes it harmless.

A woman working at a laptop and notebook at an outdoor cafe
Photograph: FOTOGRAFÍA EDITORIAL

Somebody sets up your new email address, or your domain account, or the login for your own website. Then they send you the password. It arrives, it works, you get on with your day. Nothing goes wrong, which is exactly why nobody thinks about it again.

The trouble is that the message did its job and then carried on existing. Months later that password is still sitting there, in more places than either of you would guess, and it still opens the thing it opened on day one.

Where an emailed password actually ends up

A sent email does not go anywhere. It copies itself. There is a copy in their Sent folder and a copy in your inbox — that is two, and they are the only two most people picture. Then there is a copy on their mail provider's servers and one on yours, a copy on every phone, laptop and tablet either of you has ever set that account up on, and a copy in whatever backup those providers quietly keep.

You can check the first one yourself in about ten seconds. Open your own Sent folder and search for a password you once sent somebody. It is there, in plain text, exactly as you typed it. That is one copy out of perhaps a dozen, and it is the only one you can see or delete.

Who else reads it on the way

Mail is not a sealed envelope. Between the two of you it passes through spam filters and corporate security products, some of which open messages, scan what is inside, and rewrite the links before passing them on. That is not sinister — it is how they catch the genuinely nasty ones. But it means the message was read by machinery neither of you chose.

Then there is forwarding, which is where most of the copies actually come from. You forward it to your business partner so they can log in too. They forward it to the person who does the books. Somebody replies to the thread three months later about something unrelated, and the whole chain — password included — comes along underneath.

A password sent once is not a password sent once. It is a password quietly published to everywhere that message landed.

Why a strong password does not help here

This is the part worth sitting with. A long random password and a terrible one are equally exposed once both are sitting in a mailbox. Length and randomness protect you against somebody guessing. Nobody is guessing. It is written down, in readable text, in a dozen places, and being strong does not make it any less readable.

Which is why the usual advice — pick a longer one, use a manager, turn on two-step — is all sound and all beside the point for this particular problem. It answers a question nobody asked. The password was never guessed. It was filed.

What to do about one you were already sent

You cannot chase the copies. There are too many, most of them are not yours, and deleting an email has never reliably deleted an email. So do not try. Make the copies worthless instead:

01Change it, now, to something only you have ever seen. The moment you do, every copy in every mailbox becomes a string of characters that opens nothing. This one action does more than the other three together, and it takes about a minute.
02Turn on two-step for that account. Then even a password that does leak is not enough on its own. This is the one piece of standard advice that genuinely applies here, because it changes what a leaked password is worth.
03Do not send the new one back the same way. If somebody needs a credential from you, read it down the phone, or send half on one channel and half on another. A password and the way to open it should never travel together.
04Then delete the thread, both ends. It will not remove every copy — see above — but it removes the two easiest ones to stumble across. Ask the sender to clear their Sent folder too. Most people are glad to be asked.

How to send a password securely instead

You can push back on how you are handed things. When somebody sets up an account for you, it is entirely reasonable to say: send it in something that expires, or tell me the password over the phone and email me only the username. Nobody competent will be offended. The request tells them you have thought about it, which is not a bad first impression to make on the person holding your keys.

For what it is worth, we hand passwords over on a link that opens once and then deletes itself, and the key is never in the email — but the point of this piece is what to do about the one already sitting in your inbox, and that works the same whoever sent it.

One honest caveat: none of this means the person who emailed you a password was careless. Almost everybody does it, including people who know better, because for a long time the alternative was more trouble than it was worth. The problem was never the care taken in the moment. It is that the copies outlive the moment, and they do not know the job is finished.

Not sure what is still floating about?

If somebody set up your email, your domain or your site and you have no idea what was sent where, tell us what you are running and we will tell you what to change first.

Talk to us →
Keep reading