How to Send a Passport Copy Securely
You cannot recall a passport scan — renewing changes the document, not the copies. Before you send one: check the request is real, redact, and mark the copy.
Landlords, employers, banks, visa agents, hotels and marketplaces all ask for one. Most of the time you have to comply. But a passport scan deserves more care than a password, for a reason that is easy to miss:
You cannot recall the scan. A leaked password gets changed in a minute and the old one stops working. Renewing a passport changes the live document — a new number, a new expiry, usually a new photograph — but it does nothing to the copies already held elsewhere, and it does not undo the identity data those copies revealed. People have been extorted years after a breach using scans that were long out of date.
So the order of operations matters. Most of the work happens before you attach anything.
First: is the request real?
Identity documents are the most valuable thing a fraudster can ask for, and the request always looks routine — a rental application, an onboarding form, a “verification” email from a service you use.
- Never act on contact details in the message. Find the organisation’s number on its own website and call.
- Ask what they need it for, and who will hold it. A legitimate organisation can answer both.
- Be suspicious of urgency. “Before end of day”, “the flat will go to someone else” — pressure to skip the check is the attack.
- Never send it to an individual’s personal email for a company process.
If this were a password, changing it would end the problem. Here nothing you do afterwards reaches the copy, which is why this step matters more than the encryption.
Second: send less
Ask what they actually need to verify, then give only that.
| They need to verify | They usually do not need |
|---|---|
| Your age | The passport number |
| Your name and photo | Your signature |
| Your nationality | The machine-readable zone, if they are reading the page by eye |
| That the document is valid | A scan of every page |
The two lines at the bottom of the data page — the machine-readable zone — hold your name, document number, nationality, date of birth, sex, expiry date and sometimes a personal number, with check digits, in a form any scanner reads instantly. They do not contain your photo, your signature or your place of birth, but they are what makes a scan most useful to an automated fraud pipeline. If they are not needed, cover them.
Two cautions. Do not redact unilaterally for a bank, a visa or any legal process — a rejected document means sending a second copy, which doubles your exposure. And redact by covering with a solid block in an image editor, then exporting a flattened image. A black rectangle drawn in a PDF viewer can often be moved or deleted by the recipient.
Third: mark the copy
If the recipient allows it, write the purpose and date across the scan:
for ACME tenancy application only · 14 March 2027
Place it so it crosses the photo and the data area but leaves the details legible. A marked copy is far less useful if it is reused somewhere else, and it makes the origin obvious if it does surface. Banks and government processes often reject marked copies — ask first.
Fourth: choose the channel
In order of preference:
- The organisation’s own upload form, reached by typing their address yourself. Best: the document goes straight into their system rather than into somebody’s inbox.
- A secure link they send you — if you verified the request independently first.
- A one-time link you create, with the passphrase given by phone. Watch for link previews spending the single view — see One-Time Secret Alternatives.
- Email with a password-protected PDF, the password sent on a different channel. Not by the same thread, and not your date of birth.
- A chat app, last. If you must, delete it afterwards on both sides and remember that deleting a message does not clear every copy.
Never put it in a photo library that syncs to the cloud, and never leave it sitting in your camera roll afterwards.
Fifth: assume it persists, and plan for that
Even done well, the copy now exists somewhere you do not control — and in many cases the recipient is legally required to keep it. Anti-money-laundering rules, right-to-work checks and tenancy law all set retention periods. This is the honest limit of every “secure sharing” tool: none of them can revoke a document a regulated recipient must retain.
So the useful habits are afterwards:
- Write down who has it and when. If a leak surfaces later, you will want the list.
- Ask for deletion when the purpose ends, and follow up in writing.
- Watch for credit applications you did not make, and consider a credit freeze if a scan is ever exposed.
Where a tool helps, and where it does not
Let us be straight about our own product, because this is a case it only partly fits. WaxSeal carries text — a passport number, a reference, a credential — to named devices, with expiry, read limits and revocation. It does not carry documents or PDFs, so it is not a way to send the scan itself. If a firm needs to pass a client’s details to one colleague without leaving them in a chat history, that is the case it is built for. Sending the image belongs in the organisation’s upload form.
Equally, StegoSafe is for keeping your own secrets — a recovery phrase, a key — encrypted on your devices. It is not a delivery mechanism for identity documents.
The short version
- Verify the request on a number you found yourself. This matters more than anything that follows.
- Send less — ask what they must verify, cover the machine-readable lines if they are not needed.
- Mark the copy with purpose and date, if the recipient allows it.
- Prefer their upload form to any inbox.
- Assume it persists. You cannot reset your date of birth, so keep a record of who holds a copy.
Frequently asked questions
Is it safe to send a passport copy by email?
Should I watermark a passport copy before sending it?
What parts of a passport can I redact?
Someone asked me to send my passport for a job or a rental. Is it a scam?
Keep reading
- How to Send Tax Documents to Your Accountant SecurelyYour accountant's portal exists for a reason, and it is not that email gets intercepted. Here is what actually goes wrong, and the one habit that fixes most of it.
- How to Send Credit Card Details SecurelyUsually the right answer is not to send them at all — use a payment link or a virtual card. When you really must hand over a card number: what never to do, and how to split it.
- How to Send a Self-Destructing Message on iPhoneiMessage has no self-destructing texts. Here is what Signal, WhatsApp and Telegram actually do on iPhone, what 'self-destruct' can and cannot mean once someone has read your message, and a different approach for teams: a message that travels through an ordinary photo and stops opening when you say so.
WaxSeal sends a secret through any chat and keeps you in control after it leaves. Only approved recipient devices can open it; revoke future access, set an expiry, limit reads or require a PIN — even after the photo has been sent. Free app; recipients are always free.
Try WaxSeal on this device — free