Skip to content

Password protect a PDF before emailing it, and send the password the right way

By the getPDF team · Published 11 October 2026

The short answer

Drop the PDF into the tool below, type a password under Password to open, click Protect and then Download PDF. The file is encrypted with AES-256 in your browser, so nothing is uploaded and the password never leaves your device. Then attach the file to your email and send the password another way: a text message, a call, or in person, never in the same email.

Try it here, nothing is uploaded

PDF · any size

How to password protect the PDF, step by step

  1. Drop the PDF on the tool above, or click Choose files. The file list shows its name, the number of pages and the size. If the file is very big for email, compress it first; the attachment limits guide has the numbers. If the PDF already has a password, the tool asks for it when you click Protect, and the result carries only the new one.
  2. Type a password under Password to open. This is the one that matters: without it, nobody can read the file.
  3. Leave Owner password empty unless you want restrictions. Empty means it is the same as the password to open, which is fine as long as you restrict nothing.
  4. Leave the 4 boxes under Allow ticked (Print, Copy text, Change, Annotate and fill). They are restrictions a reader’s app is asked to honour, not protection; user vs owner password explains the difference.
  5. Click Protect. The tool encrypts every text and picture in the file, then opens the result again with your password to check it works before you get it.
  6. Click Download PDF. The file is saved with -protected added to its name.
  7. Open the downloaded file once yourself. Your browser or PDF reader should ask for the password. Type it, check the pages, close it.

On our 3-page sample invoice the encryption and the check take a fraction of a second (0.2 seconds on a mid-range laptop), plus a few seconds the very first time while the engine downloads. The result screen lists what was done: “Set a password to open the file (AES-256)” and “All permissions allowed”.

The 1 rule: the password travels a different way

A password in the same email as the file protects nothing. Whoever gets the email gets both. The same goes for a second email a minute later: a wrong address, a forward or a mailbox someone else has broken into exposes both messages together.

You send the protected PDF by email and the password by a text message or a call. A wrong recipient or a stolen mailbox gets only the encrypted file, which it cannot open.Youfile plus passwordRecipientopens the fileEmail: the locked PDFText or call: the passwordA wrong forward or a stolen inbox gets the locked file and nothing to open it with.
The file and its password travel by 2 different routes, so 1 mistake or 1 break-in exposes only half of what is needed.

Good second routes, from most to least convenient:

  • A text message or messenger to the recipient’s phone number you already had, not one given in the email.
  • A phone call. Say it slowly; spell any word that could be written 2 ways.
  • Agreed in advance, in person, for people you send to regularly. Change it now and then.

Choosing a password that survives guessing

AES-256 cannot be broken by trying keys. What can be tried is the password, and an attacker with the file can try millions of guesses offline with no lockout. So the password carries the whole weight.

  • Length beats cleverness. Vienna2026! looks complicated and falls quickly, because a city, a year and a symbol is exactly the pattern guessing tools try first. 4 random words, such as kettle orbit lantern meadow, are longer, easier to type on a phone, and far harder to guess. The UK’s National Cyber Security Centre recommends exactly this in its advice “Three random words”, and the US standard NIST SP 800-63B-4 (2025) asks for at least 15 characters when a password is the only protection (both checked on 11 October 2026).
  • Random means picked by chance, not by you. A password manager’s generator or 4 words chosen with dice will do; a line from a song will not.
  • Never reuse a password from an account. If the PDF password leaks, nothing else should open with it.
  • Keep to plain letters and spaces or hyphens. The recipient has to type it, maybe on a phone; accented letters and symbols are where typing goes wrong.

Store the password in your password manager when you set it. If you lose it before the recipient has opened the file, nobody can get it back, including us: the tool never stores it, and there is no reset.

What the recipient sees

The protected file opens in any current PDF reader after the password is typed. Tell the recipient in the email that a password is coming separately, so a prompt does not surprise them.

Where they open it What happens
Chrome or Edge (built-in viewer) Asks for the password, then shows the file
Firefox (built-in viewer) Asks for the password, then shows the file
Acrobat Reader Asks for the password, then shows the file
Preview on a Mac, Files on an iPhone Asks for the password, then shows the file
The preview pane of a mail app or webmail Varies: some ask for the password, some cannot show encrypted files. Downloading the file always works

If the preview in the mail app does not work, the fix is always the same: download the attachment and open it in the browser or a PDF reader. Tell the recipient 1 more thing: Gmail notes that attachments which need a password cannot be scanned for viruses, so it may show a warning on yours (Gmail Help, “Open & download attachments in Gmail”, checked on 11 October 2026). That is expected for any encrypted file.

What the password protects against, and what it does not

Risk Protected?
The email goes to the wrong person Yes, if the password went another way
Someone reads the mailbox later (a stolen or shared account, a breached provider) Yes
The email is intercepted on the way Yes; the content is encrypted inside the file, whatever route it takes
The recipient forwards the file and the password No
The recipient saves an unprotected copy, prints it or takes a screenshot No
The file name, subject line and email text No: they are not part of the encryption

That last row catches people out. A file called Jana-Cermak-salary-2026-protected.pdf, with the subject “Jana’s salary review”, has told the wrong recipient most of the story before any password prompt. Name the file neutrally and keep the details inside it.

The honest part

A password protects the file on its way and in mailboxes. It does not protect it from the person you send it to, and it is only as strong as the password you pick.

  • The author name and dates are encrypted too, but the recipient sees them once the file is open. If they should not, run Remove PDF metadata first, then protect the result.
  • Redact before you protect when the recipient should not see everything. A password decides who opens the file; redaction decides what is in it.
  • A digitally signed file is written anew when protected, so its signature no longer checks out, and the result tells you so. Keep the signed original for anything that counts, and send it unprotected through a channel you trust if the signature must stay valid.
  • Some mail systems at companies scan attachments and quarantine encrypted files they cannot read. If a protected file does not arrive, that is the likely reason; a shared link from a drive you both use is the usual alternative, compared in send a confidential PDF by email.

Questions

Can I send the password in a second email?

Better not. Anyone who can read the first email (a wrong recipient, a forward, a stolen mailbox) can usually read the second. Send it by text message, say it on a call, or agree it in person.

Does the recipient need Acrobat to open it?

No. The file uses AES-256, the standard every current PDF reader supports: Chrome, Edge, Firefox, Acrobat Reader and Preview on a Mac all ask for the password and then open it.

Is the file name protected too?

No. The password protects the content of the file. The file name, the email subject and the email text travel as they are, so do not put the confidential part in any of them.

What if the recipient forgets the password?

Send it again by the same separate channel. Nobody can recover it from the file, which is the point of the encryption; keep the password in a password manager until the recipient confirms the file opened.

Does the protected PDF get bigger?

Usually a little. Our 2 KB invoice came out at 3 KB. A long text file can grow more, because the tool writes it without compressed object streams: a 500-page text file went from 117 KB to 239 KB.

The tools for this job