Why email isn't safe for tax documents
Email was designed in the 1970s to pass messages between university researchers. It was never intended to carry sensitive financial data. The fundamental problems haven't changed:
Not encrypted end-to-end by default
Standard email (SMTP) can transmit in plaintext between mail servers. Even when TLS is used, it only protects data in transit, not at rest on either end.
Stored on multiple servers you don't control
Your email passes through your provider's servers, potentially intermediary relay servers, and your recipient's provider. Each one stores a copy.
Attachments persist indefinitely
That W-2 you emailed in February? It's still sitting in your sent folder, your client's inbox, and their trash folder, potentially years later.
Trivially easy to forward
Anyone with access to the email can forward your client's tax documents to any address. There's no access revocation, no expiration, no control.
No way to revoke access
Once you hit send, the document is out of your hands. If you realize you sent a W-2 to the wrong address, there's nothing you can do.
What's actually at risk
Tax documents aren't just paperwork. They're concentrated identity data. Here's what a single intercepted email can expose:
| Document | Contains |
|---|---|
| W-2 | Social Security number, wages, employer ID |
| 1099 (any type) | SSN or EIN, income amounts, payer details |
| Bank statements | Account numbers, routing numbers, balances |
| Engagement letters | Full legal name, address, scope of work |
The IRS reported over 294,000 identity theft cases related to tax fraud in 2023. Compromised email is one of the most common vectors.
"But my email uses TLS..."
This is the most common misconception. When you see "TLS" in your email settings, it means your email provider encrypts the connection between mail servers. That's genuinely better than sending in plaintext. But it's not the same as encrypting the email itself.
Here's the distinction that matters:
TLS (what email does)
- ~Encrypts data in transit between servers
- ~Emails are readable at rest on both mail servers
- ~Your email provider can read the content
- ~A server breach exposes all stored email
End-to-end encryption (what you need)
- ✓Encrypts the data itself, not just the connection
- ✓Data is encrypted at rest on all servers
- ✓Only the intended recipient can decrypt
- ✓A server breach exposes only encrypted data
Think of TLS like an armored truck. It protects the mail while it's moving, but once it arrives at the warehouse, the doors are open. End-to-end encryption is like locking the package inside a safe that only the recipient has the key to. It doesn't matter who handles the safe along the way.
IRS guidance on the matter
The IRS doesn't leave this to interpretation. Publication 4557 ("Safeguarding Taxpayer Data") outlines specific requirements for anyone who handles tax information:
- Encrypt all sensitive data transmitted electronically
- Encrypt sensitive data stored on computers and devices
- Use secure methods when sending or receiving taxpayer data
- Maintain access controls to restrict who can view client information
- Implement an incident response plan for data breaches
The key point
Email with TLS alone does not satisfy the "encryption at rest" requirement. Emails stored on mail servers are not encrypted at rest unless additional measures are taken. Tax professionals who rely solely on standard email for transmitting client documents are not meeting IRS guidelines.
Safer alternatives
There's no single perfect solution: the best option depends on your practice, your clients, and your budget. Here's an honest comparison, ranked by overall security and practicality:
Encrypted file transfer services
DeadVault, ShareFile, Kiteworks
Pros
Purpose-built for sensitive documents. End-to-end encryption, access controls, audit trails, automatic expiration.
Cons
Monthly cost. Requires sending the client a link instead of an attachment.
Best option for most professionals.
Encrypted email (both parties)
ProtonMail, Tutanota
Pros
True end-to-end encryption when both sender and recipient use the same service.
Cons
Both parties must use the same provider. Asking clients to create a ProtonMail account adds friction. Attachments still persist in the inbox indefinitely.
Good if you can standardize, impractical for most client-facing work.
Password-protected PDFs
Adobe Acrobat, free online tools
Pros
Free, no special software needed to open. Better than plaintext email.
Cons
No audit trail, no expiration, password must be shared separately (and people often email the password too). Older PDF encryption is easily cracked.
Minimum viable option. Better than nothing.
Secure client portals
Canopy, TaxDome, SmartVault
Pros
Integrated into practice management. Clients can upload and download in one place.
Cons
Requires clients to create accounts. Often bundled with software you may not need. Higher cost.
Good for firms already using these platforms.
Frequently asked questions
Common questions about emailing sensitive documents.