Every year the same exchange happens. Your accountant asks you to upload documents to a portal. You cannot remember the login, the deadline is tomorrow, and it is so much easier to attach the PDF to an email.

Before deciding whether that matters, it is worth being precise about what the risk actually is — because it is not the one most articles describe.

The risk is not interception

Mail between major providers is encrypted in transit. Nobody is plucking your W-2 off the wire.

The risk is that the document stays. A tax return contains your Social Security number, your address, your employer, your bank account and your dependants’ names — the exact set someone needs to open credit in your name. Attached to an email, it now lives in your sent folder, your accountant’s inbox, both mail backups, and every device either of you has signed in to. Years later, one compromised mailbox is a full identity-theft kit.

That is also why your accountant is being stubborn. The FTC’s Safeguards Rule has obliged tax preparers to keep a written information security plan for many years, and a strengthened set of requirements took effect on 9 June 2023; annual PTIN renewal reminds preparers of that responsibility. When client data leaks out of a firm’s mailbox, the firm carries the notification costs and the insurance consequences — regardless of who attached it. The portal is not bureaucracy. It is the thing standing between them and that bill.

You presssendin transit(encrypted)Your phone — chat history, searchableTheir phone — indefinitelyEvery linked device — laptop, tabletCloud chat backupLock-screen preview — anyone nearbyTheir next phone — history transfersforyearsthe risk youworry about ↑the risk thatactually leaks →
The same arithmetic as any secret sent by email — except this one contains a Social Security number.

What actually goes wrong

Four failures account for nearly all of it, and only one is technical.

The portal nobody uses. This is the big one, and practitioners say so constantly in their own forums: the firm buys a portal, tells every client to upload there, and the documents still arrive by email and text. A portal that is not used protects nothing, and the firm has paid for it twice — once in licence fees, once in the breach it did not prevent.

The secure link that looks like phishing. Clients are trained not to click unfamiliar links, and then sent one. Accountants report clients refusing to open legitimate secure-file links because the genuine article is indistinguishable from the fake ones they have been warned about. The better services put the firm’s name and a short explanation in the message; the worst send a bare link from a domain nobody recognises.

The password-protected PDF, done wrong. Two versions of the same mistake. Setting the password to something the recipient already knows — the classic is “the last four digits of your SSN” — means the protection is a value that is also in the document. And emailing the password in the same thread means an attacker who has the email has both. A four-digit numeric password on a PDF falls to an ordinary laptop in under a minute.

The wrong recipient. The dullest failure and the most common. In the UK information regulator’s figures, “data emailed to incorrect recipient” has repeatedly been the single largest category of reported incident. Autocomplete picks the wrong surname; a document goes to a stranger; nobody notices for months.

What to do instead

Use the portal. If your accountant has one, this is the whole answer. It keeps the document out of both mailboxes, and it is what their security plan is built around. Save the login to your password manager the first time and the friction disappears.

If there is no portal, ask. “Do you have a secure way for me to send this?” is a reasonable question to a professional holding your Social Security number, and most firms have something.

If it has to be email, then in order of value:

  1. Protect the PDF with a real password — not your SSN digits, not your date of birth. Generate one.
  2. Send the password on a different channel. Text it, or say it on the phone. Never in the same thread.
  3. Check the recipient before you attach anything. Type the address rather than letting autocomplete choose.
  4. Redact what is not needed. An accountant verifying a bank account needs the last four digits, not a full statement.
  5. Delete it afterwards, from your sent folder too, and empty the trash.

What to never send by email at all: a photograph of a Social Security card, a complete return, or a W-2 — anything pairing a full SSN with a name and address.

For the firm on the other side

If you are the accountant, the pattern in the complaints is consistent and it is not about cryptography: the client will not use a tool they have to learn. Portals fail on adoption, not on encryption. The firms that report success say the same thing — the portal that won was the one that asked less of the client.

That is also the shape of WaxSeal, for the narrower case of handing over a credential or a detail rather than a document: the client is sent an ordinary photo through whatever chat they already use, there is no portal login and no link that looks like phishing, and it opens only on devices you named. The sender can set it to open once, expire, or need a PIN given by phone, and can revoke it afterwards. Those controls govern future access; they cannot erase what has already been read.

Two limits worth stating: WaxSeal carries text — a number, a reference, a credential — not documents or PDFs, so it does not replace your portal for the return itself. And both sides need the app.

The short version

  1. The danger is persistence, not interception. A return in a mailbox is an identity-theft kit with a long shelf life.
  2. Use the portal. It is why your accountant pays for one, and why they carry the liability if you do not.
  3. If you must email: real password, different channel, check the recipient, redact, delete.
  4. Never email a photo of a Social Security card or a complete return.

Frequently asked questions

Is it safe to email tax documents to my accountant?
It usually arrives safely — email between major providers is encrypted in transit. The problem is afterwards: a W-2 or a full return with your Social Security number sits in two mailboxes and their backups for years, and a single compromised mailbox exposes it. Use the portal your accountant already pays for, and if they have not got one, ask.
Why does my accountant insist on a portal when email is easier?
Liability, mostly. The FTC Safeguards Rule has required tax preparers to keep a written information security plan for many years — a strengthened set of requirements took effect on 9 June 2023 — and annual PTIN renewal reminds preparers of that legal responsibility. If client data leaks from their mailbox they face the notification costs and the insurance consequences, whoever sent it.
Is a password-protected PDF good enough?
Only if the password is strong and travels separately. Two habits ruin it: setting the password to something the recipient already knows, such as the last four digits of a Social Security number, and emailing the password in the same thread. A four-digit password on a PDF can be cracked in under a minute on an ordinary laptop.
What should I never send by email?
A complete return, a W-2, a Social Security card photo, or anything pairing a full SSN with a name and address. If you must send a document that contains one, use the portal, or split the password onto a different channel and delete the message afterwards.

Keep reading

  • How to Send Credit Card Details SecurelyUsually the right answer is not to send them at all — use a payment link or a virtual card. When you really must hand over a card number: what never to do, and how to split it.
  • How to Send Bank Details Securely (The Risk Isn't What You Think)Your account number isn't really a secret — it's on every invoice you send. The danger is someone changing it in transit. How to send and receive them safely.
  • How to Send a Self-Destructing Message on iPhoneiMessage has no self-destructing texts. Here is what Signal, WhatsApp and Telegram actually do on iPhone, what 'self-destruct' can and cannot mean once someone has read your message, and a different approach for teams: a message that travels through an ordinary photo and stops opening when you say so.

WaxSeal sends a secret through any chat and keeps you in control after it leaves. Only approved recipient devices can open it; revoke future access, set an expiry, limit reads or require a PIN — even after the photo has been sent. Free app; recipients are always free.

Try WaxSeal on this device — free