Tutorials

How to Send a Self-Destructing Message, Step by Step

A step-by-step guide to sending a message that deletes after reading, plus where app-based disappearing messages still leave copies behind.

To send a self-destructing message, put the text in a one-time link instead of a chat thread. Create a self-destructing note, set it to delete after one view or a short time limit, add a passcode if the content is sensitive, and send the link. Once it is read or expires, the link stops working.

Key takeaways

  • Disappearing messages in chat apps can still survive in notifications, backups, linked devices and screenshots.
  • A one-time link keeps the secret out of the chat thread entirely. All that stays behind is a dead link.
  • Set the note to burn after one view and the shortest time limit that works for the recipient.
  • Send the passcode through a different channel than the link, such as a phone call or a separate app.
  • Nothing stops a recipient from taking a screenshot, so for passwords and keys, change them after they have been used.

What counts as a self-destructing message?

A self-destructing message is one that stops being readable after a set event: someone opens it, a timer runs out, or both. The point is that the content does not sit around in an inbox or chat history for months.

There are two common ways to do it. You can turn on disappearing messages inside a chat app, or you can send a self-destructing note: a link that opens the message once and then stops working.

Both sound similar. They behave very differently once you look at where copies end up.

Do disappearing messages in WhatsApp, Signal and Telegram really disappear?

They disappear from the chat window. That is not the same as disappearing everywhere. Chat apps delete the message from the conversation on schedule, but the content may already have been copied somewhere the timer does not reach.

Here is how the common options compare. Exact behavior depends on app version and settings, so treat this as a guide to where to look, not a guarantee.

OptionHow it deletesWhere copies can still survive
Signal disappearing messagesTimer set per chatNotification previews, screenshots, photos of the screen
WhatsApp disappearing messagesTimer per chat (such as 24 hours, 7 days or 90 days)Backups made before the timer ran out, forwards, screenshots, messages a participant chose to keep
Telegram secret chatsSelf-destruct timer on that device's chatNotification previews, screenshots where the app cannot block them, photos of the screen
Snapchat chatsClear after viewing by defaultSaved chats, screenshots (the sender may be told, but it is not prevented)
Gmail confidential modeExpiry date, sender can revoke accessYour own Sent folder, screenshots, retyped copies
One-time link (self-destructing note)Destroyed after a set number of views or a time limitScreenshots or copy-paste by the recipient. The chat only holds a link that no longer works

Notice the pattern. Every option is vulnerable to a determined recipient with a camera. The difference is how many copies get made automatically, without anyone meaning to.

Where do copies of a disappearing message still end up?

Most leaks are not deliberate. They happen because phones and computers are built to save things.

Notifications

If the recipient's phone shows message previews, the text can appear on a locked screen, a smartwatch or a notification history log. Anyone glancing at the phone sees it, whatever the chat timer says.

Backups

Cloud backups capture the chat at the moment the backup runs. If the message was still there at 2 a.m. when the phone backed up, a copy may live in that backup after the chat deletes it.

Linked devices

Many apps sync to a laptop or tablet. A desktop session left open at the office is one more place the message is displayed and possibly cached.

Screenshots and forwards

A recipient can screenshot or forward the message before it vanishes. Some apps notify you or block screenshots for certain message types, but none can stop someone photographing the screen with another phone. Our post on designing secret-sharing workflows that survive screenshots and human error covers how to plan around this.

A one-time link sidesteps the first three. The secret never enters the chat thread, so notification previews, chat backups and synced desktops only ever see a URL. After the note is opened or expires, that URL leads nowhere.

How to send a self-destructing message with a one-time link

Say you are a landlord texting a tenant the code for a key lockbox, or a developer sending an API key to a new hire. Here is the safe way to do it with SecureNotes. It is free and needs no account.

  1. Open SecureNotes and paste your text. Go to the homepage and create a self-destructing note. Paste the message, up to 10,000 characters. Text only, no attachments.
  2. Choose when it self-destructs. Pick a view limit (1, 3, 5 or 10 views), a time limit (1 hour, 24 hours, 7 days or 30 days), or both, in which case whichever comes first wins. For a password or code, one view is usually right.
  3. Add a passcode if the content is sensitive. The recipient will need to enter it before the note opens. This protects you if the link lands in the wrong inbox or gets forwarded.
  4. Turn on the read notification (optional). SecureNotes can email you when the note is opened, so you know the recipient got it.
  5. Send the link. Paste it into a text, chat or email, or have SecureNotes email it to the recipient for you.
  6. Send the passcode another way. If the link went by email, read the passcode out on a call or send it by text. Never put both in the same message.
  7. Confirm it was received. Once the recipient has what they need, the note is gone. If they say the link was already dead when they tried it, treat the secret as exposed and change it.

Each note is encrypted with AES-256 using its own random key before it is stored, and once the view or time limit is reached the link stops working. For more on choosing and sharing passcodes, read when to use passcode-protected notes and how to send the passcode safely.

Which self-destruct setting should you pick?

Match the setting to how quickly the recipient will act and how bad it would be if someone else read it.

  • 1 view, 1 hour: a password you are sending while the person is on the phone with you.
  • 1 view, 24 hours: a door code or Wi-Fi password for someone arriving tomorrow.
  • 3 views, 7 days: instructions a small group needs to read once each, like a shared alarm code for three cleaners.
  • Time limit only: rarely the best choice for secrets, because the note stays readable until it expires.

A view limit means the message deletes after reading. A time limit means it deletes on a schedule, read or not. Combining them gives you a backstop. The trade-offs are covered in more depth in self-destruct vs time-based expiration.

What can still go wrong with a message that deletes after reading?

A self destruct message link removes a lot of risk, but not all of it. These are the mistakes people actually make.

Sending the passcode with the link

Putting "link: ... passcode: 4471" in one email means anyone who reads that email has both. Split them across channels.

Choosing generous limits

Ten views and 30 days is convenient, but it leaves the note readable for a month. Use the tightest settings the recipient can work with.

Leaving your own copy behind

The note self-destructs, but the text you typed might still be in your clipboard, a draft email or a notes app. Clear it.

Forgetting the recipient can save it

Nothing technical stops a screenshot or a paste into a document. If you are sending a password, ask the recipient to store it in a password manager and plan to rotate it if the access is temporary.

Sending to the wrong person

Check the address or contact before you hit send. A passcode is your safety net here, which is one more reason to use it for anything sensitive.

Ignoring a dead link

If the recipient reports the note was already gone, do not just send a new one. Someone else may have opened it. Change the secret first.

When a self-destructing note is the wrong tool

One-time links are built for handing something over once. They are not the answer to every privacy problem.

  • Ongoing shared passwords: if a team needs the same login every week, use a password manager with shared vaults.
  • Payments and card numbers: send a payment link from your payment provider instead of typing card details anywhere.
  • Files and documents: SecureNotes is text only. Use a file-sharing tool with access controls and expiry.
  • A real conversation: if you need back-and-forth on something sensitive, a phone call or an end-to-end encrypted chat with disappearing messages may suit you better.
  • Something that must never be seen by any third party: any hosted service means trusting that service. Weigh that honestly before you send.

If you send secrets from scripts or internal tools, the free SecureNotes REST API lets you generate one-time links automatically instead of pasting keys into tickets.

What to do if you already sent it the normal way

If a password or code is already sitting in a chat or email, deleting the message is a start, not a fix.

  1. Delete it for everyone, if the app allows that.
  2. Change the secret. Assume backups, notifications or synced devices have a copy.
  3. Send the new one as a one-time link so the same thing does not happen twice.

Next time, send a secure note from the start and the chat history will only ever hold a link that no longer works. OWASP's Secrets Management Cheat Sheet is a useful reference if you handle credentials regularly.

Frequently asked questions

Can the recipient screenshot a self-destructing message?

Yes. No app or link can fully stop someone from taking a screenshot or photographing their screen with another phone. Self-destructing messages prevent copies from piling up by accident, not deliberate saving. If you are sending a password or access code, plan to change it once it has served its purpose, especially when the access is temporary.

Will I know when my self-destructing note has been read?

With SecureNotes, you can turn on an optional email notification when you create the note. You will get an email when the note is opened, which confirms delivery. If the recipient later says the link was already dead and you got a notification they did not trigger, assume someone else read it and change the secret.

Can I send a self-destructing message by text message?

Standard SMS has no built-in self-destruct feature, so anything you text stays on both phones until someone deletes it. The workaround is to create a self-destructing note, then text the link instead of the secret itself. The text thread keeps only the URL, which stops working after the note is viewed or expires.

What happens if the link expires before the recipient opens it?

The link stops working and the note cannot be recovered. Just create a new note and send a fresh link. If you are certain nobody opened the original, there is no need to change the secret. If you are unsure, for example because the link may have been forwarded, changing it is the safer choice.

Do I need an account to send a self destruct message link?

Not with SecureNotes. It is free and needs no sign-up. You paste your text, choose the view or time limit, optionally add a passcode, and get a link to share. That makes it practical for one-off situations, like sending a guest a Wi-Fi password or a contractor a temporary login.

Can I create self-destructing notes automatically from a script?

Yes. SecureNotes offers a free public REST API for creating notes from scripts and internal tools. Developers use it to generate one-time links for things like new-hire credentials or temporary API keys, so secrets never get pasted into tickets, shared docs or chat channels. The API documentation is on the SecureNotes website.

S
SecureNotes Team

Security expert and content creator at Secure Notes. Passionate about digital privacy and secure communication.

Featured on The Logo Wall