Security Guide

Is It Safe to Email Tax Documents?

The short answer is no. Here's why, and what to do instead.

Why email isn't safe for tax documents

Email was designed in the 1970s to pass messages between university researchers. It was never intended to carry sensitive financial data. The fundamental problems haven't changed:

  • Not encrypted end-to-end by default

    Standard email (SMTP) can transmit in plaintext between mail servers. Even when TLS is used, it only protects data in transit, not at rest on either end.

  • Stored on multiple servers you don't control

    Your email passes through your provider's servers, potentially intermediary relay servers, and your recipient's provider. Each one stores a copy.

  • Attachments persist indefinitely

    That W-2 you emailed in February? It's still sitting in your sent folder, your client's inbox, and their trash folder, potentially years later.

  • Trivially easy to forward

    Anyone with access to the email can forward your client's tax documents to any address. There's no access revocation, no expiration, no control.

  • No way to revoke access

    Once you hit send, the document is out of your hands. If you realize you sent a W-2 to the wrong address, there's nothing you can do.

What's actually at risk

Tax documents aren't just paperwork. They're concentrated identity data. Here's what a single intercepted email can expose:

DocumentContains
W-2Social Security number, wages, employer ID
1099 (any type)SSN or EIN, income amounts, payer details
Bank statementsAccount numbers, routing numbers, balances
Engagement lettersFull legal name, address, scope of work

The IRS reported over 294,000 identity theft cases related to tax fraud in 2023. Compromised email is one of the most common vectors.

"But my email uses TLS..."

This is the most common misconception. When you see "TLS" in your email settings, it means your email provider encrypts the connection between mail servers. That's genuinely better than sending in plaintext. But it's not the same as encrypting the email itself.

Here's the distinction that matters:

TLS (what email does)

  • ~Encrypts data in transit between servers
  • ~Emails are readable at rest on both mail servers
  • ~Your email provider can read the content
  • ~A server breach exposes all stored email

End-to-end encryption (what you need)

  • ✓Encrypts the data itself, not just the connection
  • ✓Data is encrypted at rest on all servers
  • ✓Only the intended recipient can decrypt
  • ✓A server breach exposes only encrypted data

Think of TLS like an armored truck. It protects the mail while it's moving, but once it arrives at the warehouse, the doors are open. End-to-end encryption is like locking the package inside a safe that only the recipient has the key to. It doesn't matter who handles the safe along the way.

IRS guidance on the matter

The IRS doesn't leave this to interpretation. Publication 4557 ("Safeguarding Taxpayer Data") outlines specific requirements for anyone who handles tax information:

  • Encrypt all sensitive data transmitted electronically
  • Encrypt sensitive data stored on computers and devices
  • Use secure methods when sending or receiving taxpayer data
  • Maintain access controls to restrict who can view client information
  • Implement an incident response plan for data breaches

The key point

Email with TLS alone does not satisfy the "encryption at rest" requirement. Emails stored on mail servers are not encrypted at rest unless additional measures are taken. Tax professionals who rely solely on standard email for transmitting client documents are not meeting IRS guidelines.

Safer alternatives

There's no single perfect solution: the best option depends on your practice, your clients, and your budget. Here's an honest comparison, ranked by overall security and practicality:

1

Encrypted file transfer services

DeadVault, ShareFile, Kiteworks

Pros

Purpose-built for sensitive documents. End-to-end encryption, access controls, audit trails, automatic expiration.

Cons

Monthly cost. Requires sending the client a link instead of an attachment.

Best option for most professionals.

2

Encrypted email (both parties)

ProtonMail, Tutanota

Pros

True end-to-end encryption when both sender and recipient use the same service.

Cons

Both parties must use the same provider. Asking clients to create a ProtonMail account adds friction. Attachments still persist in the inbox indefinitely.

Good if you can standardize, impractical for most client-facing work.

3

Password-protected PDFs

Adobe Acrobat, free online tools

Pros

Free, no special software needed to open. Better than plaintext email.

Cons

No audit trail, no expiration, password must be shared separately (and people often email the password too). Older PDF encryption is easily cracked.

Minimum viable option. Better than nothing.

4

Secure client portals

Canopy, TaxDome, SmartVault

Pros

Integrated into practice management. Clients can upload and download in one place.

Cons

Requires clients to create accounts. Often bundled with software you may not need. Higher cost.

Good for firms already using these platforms.

Frequently asked questions

Common questions about emailing sensitive documents.

Gmail uses TLS to encrypt emails in transit, which is better than nothing. But your emails are stored unencrypted on Google's servers, and Google's systems can access the content for features like search and spam filtering. If either your account or your recipient's account is compromised, every attachment is exposed. Gmail is not designed for sensitive financial documents.
Microsoft 365 offers an "Encrypt" button that uses Office Message Encryption (OME). This is better than standard email, but has limitations: the recipient needs a Microsoft account or must use a one-time passcode (adding friction), encrypted emails can still be forwarded by the recipient, and Microsoft retains the ability to decrypt messages on their servers. It's a step up from plaintext email, but it's not true end-to-end encryption.
It depends on the encryption level. PDFs encrypted with AES-256 (available in Adobe Acrobat Pro and some free tools) provide real encryption. Older 40-bit or 128-bit RC4 PDF encryption is trivially crackable. The bigger issue: most people email the password in the same thread as the document, which defeats the purpose. If you use password-protected PDFs, always share the password through a different channel (text message, phone call).
IRS Publication 4557 ("Safeguarding Taxpayer Data") requires tax professionals to implement a written information security plan. Specific technical requirements include encrypting sensitive data at rest and in transit, using secure methods to send and receive taxpayer information, and maintaining access controls. Email with TLS alone does not satisfy the "encryption at rest" requirement because emails sit unencrypted on mail servers.
This is common. The best approach: send your client a secure upload link and explain it takes 30 seconds to use. Most clients are happy to use a link once they understand the risk. If a client absolutely refuses, have them password-protect the file and share the password by phone or text. Document that you offered a secure alternative. This matters for compliance.
No. Deleting an email from your inbox doesn't remove it from your mail server's backups, the recipient's inbox, any intermediary servers it passed through, or the "Sent" folder. Email deletion is more like hiding than destroying. The data persists in multiple locations you don't control.

Need a secure way to exchange documents with clients?

DeadVault is an encrypted file transfer service built for accountants, lawyers, and financial advisors. Files are encrypted with AES-256-GCM, access is controlled with secure links, and everything self-destructs after your deadline.