Password protect a PDF before emailing it, and send the password the right way
By the getPDF team · Published 11 October 2026
The short answer
Drop the PDF into the tool below, type a password under Password to open, click Protect and then Download PDF. The file is encrypted with AES-256 in your browser, so nothing is uploaded and the password never leaves your device. Then attach the file to your email and send the password another way: a text message, a call, or in person, never in the same email.
Try it here, nothing is uploaded
How to password protect the PDF, step by step
- Drop the PDF on the tool above, or click Choose files. The file list shows its name, the number of pages and the size. If the file is very big for email, compress it first; the attachment limits guide has the numbers. If the PDF already has a password, the tool asks for it when you click Protect, and the result carries only the new one.
- Type a password under Password to open. This is the one that matters: without it, nobody can read the file.
- Leave Owner password empty unless you want restrictions. Empty means it is the same as the password to open, which is fine as long as you restrict nothing.
- Leave the 4 boxes under Allow ticked (Print, Copy text, Change, Annotate and fill). They are restrictions a reader’s app is asked to honour, not protection; user vs owner password explains the difference.
- Click Protect. The tool encrypts every text and picture in the file, then opens the result again with your password to check it works before you get it.
- Click Download PDF. The file is saved with
-protectedadded to its name. - Open the downloaded file once yourself. Your browser or PDF reader should ask for the password. Type it, check the pages, close it.
On our 3-page sample invoice the encryption and the check take a fraction of a second (0.2 seconds on a mid-range laptop), plus a few seconds the very first time while the engine downloads. The result screen lists what was done: “Set a password to open the file (AES-256)” and “All permissions allowed”.
The 1 rule: the password travels a different way
A password in the same email as the file protects nothing. Whoever gets the email gets both. The same goes for a second email a minute later: a wrong address, a forward or a mailbox someone else has broken into exposes both messages together.
Good second routes, from most to least convenient:
- A text message or messenger to the recipient’s phone number you already had, not one given in the email.
- A phone call. Say it slowly; spell any word that could be written 2 ways.
- Agreed in advance, in person, for people you send to regularly. Change it now and then.
Choosing a password that survives guessing
AES-256 cannot be broken by trying keys. What can be tried is the password, and an attacker with the file can try millions of guesses offline with no lockout. So the password carries the whole weight.
- Length beats cleverness.
Vienna2026!looks complicated and falls quickly, because a city, a year and a symbol is exactly the pattern guessing tools try first. 4 random words, such askettle orbit lantern meadow, are longer, easier to type on a phone, and far harder to guess. The UK’s National Cyber Security Centre recommends exactly this in its advice “Three random words”, and the US standard NIST SP 800-63B-4 (2025) asks for at least 15 characters when a password is the only protection (both checked on 11 October 2026). - Random means picked by chance, not by you. A password manager’s generator or 4 words chosen with dice will do; a line from a song will not.
- Never reuse a password from an account. If the PDF password leaks, nothing else should open with it.
- Keep to plain letters and spaces or hyphens. The recipient has to type it, maybe on a phone; accented letters and symbols are where typing goes wrong.
Store the password in your password manager when you set it. If you lose it before the recipient has opened the file, nobody can get it back, including us: the tool never stores it, and there is no reset.
What the recipient sees
The protected file opens in any current PDF reader after the password is typed. Tell the recipient in the email that a password is coming separately, so a prompt does not surprise them.
| Where they open it | What happens |
|---|---|
| Chrome or Edge (built-in viewer) | Asks for the password, then shows the file |
| Firefox (built-in viewer) | Asks for the password, then shows the file |
| Acrobat Reader | Asks for the password, then shows the file |
| Preview on a Mac, Files on an iPhone | Asks for the password, then shows the file |
| The preview pane of a mail app or webmail | Varies: some ask for the password, some cannot show encrypted files. Downloading the file always works |
If the preview in the mail app does not work, the fix is always the same: download the attachment and open it in the browser or a PDF reader. Tell the recipient 1 more thing: Gmail notes that attachments which need a password cannot be scanned for viruses, so it may show a warning on yours (Gmail Help, “Open & download attachments in Gmail”, checked on 11 October 2026). That is expected for any encrypted file.
What the password protects against, and what it does not
| Risk | Protected? |
|---|---|
| The email goes to the wrong person | Yes, if the password went another way |
| Someone reads the mailbox later (a stolen or shared account, a breached provider) | Yes |
| The email is intercepted on the way | Yes; the content is encrypted inside the file, whatever route it takes |
| The recipient forwards the file and the password | No |
| The recipient saves an unprotected copy, prints it or takes a screenshot | No |
| The file name, subject line and email text | No: they are not part of the encryption |
That last row catches people out. A file called Jana-Cermak-salary-2026-protected.pdf, with the subject “Jana’s salary review”, has told the wrong recipient most of the story before any password prompt. Name the file neutrally and keep the details inside it.
The honest part
A password protects the file on its way and in mailboxes. It does not protect it from the person you send it to, and it is only as strong as the password you pick.
- The author name and dates are encrypted too, but the recipient sees them once the file is open. If they should not, run Remove PDF metadata first, then protect the result.
- Redact before you protect when the recipient should not see everything. A password decides who opens the file; redaction decides what is in it.
- A digitally signed file is written anew when protected, so its signature no longer checks out, and the result tells you so. Keep the signed original for anything that counts, and send it unprotected through a channel you trust if the signature must stay valid.
- Some mail systems at companies scan attachments and quarantine encrypted files they cannot read. If a protected file does not arrive, that is the likely reason; a shared link from a drive you both use is the usual alternative, compared in send a confidential PDF by email.
Questions
Can I send the password in a second email?
Better not. Anyone who can read the first email (a wrong recipient, a forward, a stolen mailbox) can usually read the second. Send it by text message, say it on a call, or agree it in person.
Does the recipient need Acrobat to open it?
No. The file uses AES-256, the standard every current PDF reader supports: Chrome, Edge, Firefox, Acrobat Reader and Preview on a Mac all ask for the password and then open it.
Is the file name protected too?
No. The password protects the content of the file. The file name, the email subject and the email text travel as they are, so do not put the confidential part in any of them.
What if the recipient forgets the password?
Send it again by the same separate channel. Nobody can recover it from the file, which is the point of the encryption; keep the password in a password manager until the recipient confirms the file opened.
Does the protected PDF get bigger?
Usually a little. Our 2 KB invoice came out at 3 KB. A long text file can grow more, because the tool writes it without compressed object streams: a 500-page text file went from 117 KB to 239 KB.
The tools for this job
Keep reading
- PDF user password vs owner password: what each one really protectsA user password encrypts a PDF; an owner password only asks viewers to obey its limits.
- How strong is PDF encryption? AES-256, older schemes and the passwordAES-256 in current PDFs cannot be broken by trying keys; the password is the weak point.
- Send a confidential PDF by email: 6 options, ranked by what they protect6 realistic ways to send a confidential PDF by email, from a password sent by text to an expiring link, ranked by what each protects against and the effort.
- Password protect a PDF without Acrobat: 5 free ways compared5 free ways to password protect a PDF without Acrobat: getPDF in the browser, Mac Preview, LibreOffice, Word and 7-Zip, compared by cipher, effort and catch.
- PDF privacy and protection: the complete guideWhat a PDF password really protects, how true redaction works, what metadata leaks, and how to send files safely.