To email a password securely, don't put the password in the email itself. Paste it into a one-time self-destructing note, add a passcode, and email only the link. Then send the passcode by a different channel, such as a text or phone call. The link stops working after it's read, so nothing usable sits in the inbox.
Key takeaways
- Never type the password into the email body. Email a one-time link that self-destructs after it's read.
- Protect the link with a passcode and send that passcode by text, phone call or chat, never by email.
- Splitting a password across two emails puts both halves in the same inbox, where one compromise exposes everything.
- For logins people use every day, a password manager or a forced password change at first sign-in beats any email method.
- If you already emailed a password, change it. Deleting the email doesn't remove every copy.
Is it safe to email a password?
Not on its own. When you send a password by email, you create copies you can't control: one in your Sent folder, one in the recipient's inbox, and more in server backups, synced phones and any mailbox the message gets forwarded to.
Those copies don't expire. A password emailed three years ago is still searchable today by anyone who later gets into either mailbox. Attackers who take over an email account often search for words like “password”, “login” and “credentials” first.
Email has other weaknesses too, from misaddressed messages to spoofed senders. We cover those in why email isn't secure enough for sensitive information. This guide sticks to the fix: how to keep using email, which your recipient already checks, without the password ever living in it.
How to email a password securely, step by step
The idea is simple. Email carries a link that only works once. A second channel carries the passcode that opens it. Neither piece is useful on its own, and the link dies after it's read.
Here's how to do it with SecureNotes. It's free and needs no account. Each note is encrypted with AES-256 using its own random key before it's stored.
- Paste the password into a note. Go to SecureNotes and create a self-destructing note. Paste the password, plus the username and system name if the recipient needs them.
- Choose when it self-destructs. For one recipient, pick 1 view. Add a time limit too, such as 24 hours, so an unopened link doesn't sit live in an inbox for weeks. The note is destroyed at whichever comes first.
- Add a passcode. Set a passcode the recipient must enter to open the note. This protects you if the email is forwarded, misaddressed or read by someone else with access to the inbox.
- Turn on the read notification. Ask to be emailed when the note is opened. If the alert arrives before your colleague says they've opened it, you know something is wrong.
- Email the link. Paste the link into a normal email, or let SecureNotes email it to the recipient for you. Keep the message plain: “Here's the login for the new payroll account. The link works once and expires tomorrow.”
- Send the passcode another way. Text it, say it on a call, or send it in Teams or Slack. Not in the same email, and not in a follow-up email.
- Confirm and clean up. Once they've signed in, ask them to change the password if the system allows it. The link is already dead, so there's nothing left in the inbox to delete.
Why splitting the password across two emails is weaker than it sounds
A common workaround is to send the first half of the password in one email and the second half in another. Or the username in one and the password in the next. It feels like two-factor protection. It isn't.
Both halves land in the same place
Two emails to the same address arrive in the same inbox, protected by the same login. Anyone who gets into that mailbox, through a phished password, an unlocked laptop or a forwarding rule an attacker quietly set up, gets both halves. Often they're even in the same thread.
Both halves last forever
Neither email expires. Both sit in your Sent folder, the recipient's inbox and every backup. Searching for the recipient's name, or the word “password”, turns up both in seconds.
Half a password is a head start
If someone only gets one email, they still have half the characters. Guessing the remainder is far easier than guessing the whole thing. And usernames are rarely secret anyway, since they're often just the person's email address.
What actually counts as a second channel
A real second channel is a different system that someone would have to break into separately: a phone, a text message, a chat app, a conversation in person. Combine that with a link that self-destructs and the email half stops being useful the moment it's read.
Secure ways to email credentials, compared
Email-based methods aren't equal, and sometimes email isn't the right tool at all. Here's how the common options stack up.
| Method | Usable copy left in inbox? | Works for any recipient? | Best for |
|---|---|---|---|
| Password typed in email | Yes, permanently | Yes | Nothing. Avoid it. |
| Password split across two emails | Yes, both halves | Yes | Nothing. Same inbox, same risk. |
| Your organization's encrypted email | Yes, readable once the recipient opens it | Only if they can open encrypted mail | Internal messages where it's already set up |
| One-time link by email, passcode by text or call | No, the link stops working after it's read | Yes | One-off handovers to colleagues, clients, contractors |
| Password manager sharing | No password in email at all | Only if both sides use it | Credentials a team uses repeatedly |
| Temporary password with forced change at first sign-in | Short-lived only | Yes, on systems that support it | IT support setting up new accounts |
If the same login will be shared again and again, a password manager is the better home for it. We break down that choice in one-time links vs password vaults.
For IT support, the strongest option is often not to send a lasting password at all. Set a temporary one, deliver it with a one-time link, and tick “user must change password at next sign-in”. Even if the old value leaked later, it would no longer work.
Which channel should carry the passcode?
The passcode is only useful if it travels separately from the link. Pick a channel the recipient already uses that has nothing to do with their email account.
- Phone call: the best option when you can manage it. Nothing is written down, and you confirm you're talking to the right person.
- Text message: fine for most office handovers. It sits on a different device and a different account from the email.
- Teams, Slack or another chat app: fine for the passcode when the link went by email. Just don't send both through chat.
- In person: ideal for a new hire on their first day or a colleague at the next desk.
- A second email: no. That puts both pieces back in the same inbox.
Keep the passcode short enough to read aloud but not guessable. “Blue-Harbor-41” works. The company name or the recipient's birthday doesn't. For more on picking and delivering passcodes, see how to send a passcode safely.
Common mistakes that still leak the password
A one-time link removes the biggest risk, but people find creative ways to undo it.
Putting the passcode in the email
“The passcode is your employee ID” is still the passcode in the email. If anyone with inbox access can work it out, it isn't protecting anything.
Setting long expiry and extra views “just in case”
Ten views and 30 days turns a one-time link into a semi-permanent one. Use 1 view and the shortest time limit that fits the recipient's schedule. If they miss it, send a fresh note.
Copying the password somewhere permanent
The recipient reads the note, then pastes the password into a sticky note app, a shared doc or a helpdesk ticket. Now it lives forever again. Tell them where it should go: a password manager, or straight into the login screen and then changed.
Sending to a shared mailbox
A link sent to helpdesk@ or accounts@ can be opened by whoever gets there first. Send to the named person who needs it.
Ignoring a dead link
If the recipient clicks the link and the note is already gone, someone or something opened it first. Some corporate mail scanners open links to check them, but don't assume that. Treat it as a possible leak: change the password and send a new note.
What to do if you already emailed a password
It happens. Fix it in this order:
- Change the password now. This is the only step that actually closes the risk. NIST's digital identity guidelines say a password should be changed when there's evidence it may have been compromised.
- Check for unusual sign-ins on the account since the email was sent, if the system shows sign-in history.
- Turn on multi-factor authentication for the account if it isn't already, so a leaked password alone isn't enough.
- Delete the email from your Sent and Deleted folders, and ask the recipient to do the same. This reduces exposure but doesn't erase backups or synced copies, which is why step one matters most.
- Search your Sent folder for “password”. Most people who find one emailed password find several more. Rotate any that are still in use.
Then send the new password the safe way: a one-time link by email, the passcode by text or call.
Frequently asked questions
Can I send a password-protected attachment by email instead?
It's better than plain text, but the file stays in both inboxes indefinitely, and the protection is only as strong as the file password and the format's encryption. People also tend to email the file password right after the attachment, which undoes it. If you use a protected file, send its password through a separate channel, ideally as a one-time link or by phone.
Does email encryption in transit make it safe to email a password?
No. Encryption in transit protects the message while it moves between mail servers, but it arrives readable in the recipient's mailbox and stays readable in your Sent folder. Anyone who later gets into either account can read it. The problem with emailing passwords is the permanent copy at rest, which transit encryption doesn't solve.
Should IT support send a temporary password or a reset link?
A password reset link from the system itself is usually best, because the user sets their own password and you never handle it. When that isn't possible, send a temporary password through a one-time link with a passcode, and require the user to change it at first sign-in. Either way, avoid sending a lasting password in plain email.
Is texting a password safer than emailing it?
Not much. Text messages also persist on phones, cloud backups and sometimes linked computers, and they can be read over someone's shoulder. Texting works well for a short passcode that unlocks a one-time link sent by email, because neither piece is useful alone. It's a weak place to put the full password.
How long should a one-time password link stay active?
As short as practical. If the recipient is expecting it and online, 1 hour is plenty. For someone in another time zone or a new hire starting tomorrow, 24 hours is a sensible default. Avoid 7 or 30 days unless there's a clear reason. If the link expires unread, simply create a new note and send it again.
What if my company blocks links in external emails?
Some mail filters rewrite or hold links from outside senders. Try sending the one-time link through your normal email client rather than an automated sender, or deliver the link by chat and the passcode by phone instead. The principle stays the same: link and passcode travel separately, and the link expires after one read.