How to Share a Password Over Email Safely
Email is the default way people send passwords, and one of the least safe. Here is what to do instead.
Sending a password by email feels normal because everyone does it. But email was never built to protect secrets. A message you send is copied to your sent folder, the recipient's inbox, and the backups of both mail systems. Unlike a spoken word, that copy does not fade. It can be searched, forwarded, and recovered years later, which makes email one of the riskiest possible homes for a live credential.
Why emailing a password is a lasting liability
The core issue is permanence combined with reach. A password in an email is exposed to more than just the two people in the thread:
- It persists indefinitely across inboxes, sent folders, and server backups.
- A single forward can expose it to people you never intended to include.
- Standard email is often not encrypted end-to-end in transit.
- If either mailbox is breached in the future, the credential is sitting there in plain text.
Because the credential outlives the moment it was needed, the window for something to go wrong keeps growing the longer the email exists.
The one-time-link approach
You can keep using email as the delivery channel while removing the password from the email itself. Create a one-time link and send that instead. The password is encrypted in your browser, the link opens exactly once, and the secret is permanently destroyed after the recipient views it. The email that stays in the archive holds nothing but an expired link.
- Paste the password into Burn the Secret and choose an expiry.
- Add a passphrase for sensitive accounts and share it by phone or text.
- Email the one-time link with a clear label instead of the password.
- Ask the recipient to confirm, and verify the link has already been used.
Sending the passphrase through a different channel than the link means an intercepted email alone is never enough. The tool is free, needs no signup to create a link, and never sees your password because everything is encrypted client-side.
About to email a credential? Create a secure link on Burn the Secret instead.