Security
Is It Safe to Send Your Passport Over Email or WhatsApp?
Not really. Email isn't encrypted end to end, so a passport copy sits in two inboxes and their backups with no expiry. WhatsApp encrypts messages in transit, but the image saves to the recipient's phone and photo cloud, where it can be screenshotted or forwarded. Ask for an encrypted upload link that expires instead.
Not really. Email isn't encrypted end to end, so a passport copy lands in two inboxes and both providers' backups with no expiry and no way to pull it back. WhatsApp is better, because messages are end-to-end encrypted in transit, but it's still a weak way to send an ID: the image saves to the recipient's phone, often syncs to their iCloud or Google Photos, and can be screenshotted or forwarded. The safer option is a link that encrypts the file in your browser, that only the intended recipient can open, and that expires.
Why email is the wrong place for an ID
Email was built for conversation, not for the most sensitive file you own. It isn't encrypted end to end, so the message passes through servers on the way, and a copy stays in the sender's sent folder, the recipient's inbox, and both providers' backups. There's no expiry, no record of who opened it, and no way to recall it. One mistyped address sends your passport to a stranger.
A passport copy is a complete identity kit. In one image a fraudster gets your full name, date of birth, photograph, signature, document number, nationality, and place of birth. That's why a state-issued ID is enough, on its own, to open new lines of credit in someone's name.
Why WhatsApp is better but still risky
WhatsApp is a real step up from email because chats, photos, and files are end-to-end encrypted in transit by default. The weak point is what happens after the photo arrives. It saves to the recipient's gallery, is often auto-saved and synced to iCloud or Google Photos, and can be screenshotted or forwarded to anyone. Cloud backups are only end-to-end encrypted if the recipient switched that on, and most people never do. So the encryption protects the delivery, then the copy multiplies across devices you have no control over.
How the channels compare
| Channel | Encrypted for the recipient? | Where copies end up | Expires or revocable? |
|---|---|---|---|
| No (not end-to-end) | Both inboxes plus server backups, indefinitely | No | |
| In transit, yes | Recipient's gallery, then iCloud or Google Photos; screenshot- and forward-able | No | |
| Encrypted expiring link | Yes, in your browser | One controlled copy with the intended recipient | Yes |
The 153-million-license breach is the warning
In September 2026, KrebsOnSecurity reported that a dark-web service was selling scans of more than 153 million US and Canadian driver's licenses, plus millions of ID cards and travel documents. The images were siphoned for over a year from a KYC and identity-verification vendor, and the FBI's New Orleans office opened an inquiry (Malwarebytes, Engadget).
The lesson isn't "never let anyone check your ID." It's that stored copies are the risk. Every place your passport comes to rest, an inbox, a chat backup, a vendor's database, is a copy that can be stolen later. You can't control the vendor a business uses. You can control whether your own copy is sitting in someone's email forever. The goal is to leave as few lasting copies as possible.
If you have to send it anyway
Sometimes a real process needs your ID and there's no portal on offer. Reduce the damage a leak could do:
- Ask for a secure link first. A short reply works: "Happy to send it, can you give me a secure upload link instead of email or WhatsApp?"
- Redact what they don't need. Cover the document number, the machine-readable zone, your date of birth, and your signature, leaving only the fields the recipient has to match.
- Watermark it. Overlay "For [name], [purpose] only, [date]" so a leaked copy can't be reused cleanly and its source is obvious.
- Delete the copies afterward. Clear it from the chat, empty your phone's recently-deleted, and check that auto-save didn't push it to your cloud photo library.
If you're on the other side of this, the one asking clients for IDs, don't put them in this position. A copy you collect by email is a copy you now have to protect. Give people a link that encrypts in the browser and expires, so you never become the inbox full of passport scans a breach goes looking for. Under GDPR, UK GDPR, and PIPEDA, that's the same instinct the law expects: collect the minimum and keep it only as long as you need it.
Where doconvoy fits
When you're the one who needs a client's passport or ID, doconvoy replaces "email me a photo" with a secure request. The client opens a link, and the file is encrypted in their browser before it's sent, so the service only ever stores ciphertext it can't read. The request expires, and nothing is left sitting in an inbox or a chat thread. doconvoy secures how the document reaches you. It doesn't verify identity or run liveness checks, so you still do the human check, just on a clean file instead of an email attachment.
Collect passports and ID documents through an encrypted link that expires, instead of email or chat.
Ask for IDs the safe wayRelated: Collect identity documents securely · Collecting a client's passport and ID · Secure Requests · Is it safe to send passwords over email or Slack? · The best way to protect sensitive data is not to have it
Common questions
Is WhatsApp safe for sending a passport photo?
It's safer than email because messages are end-to-end encrypted in transit, but it's still a poor choice for an ID. The photo saves to the recipient's phone, is often auto-saved to their camera roll and synced to iCloud or Google Photos, and can be screenshotted or forwarded. Cloud backups are only end-to-end encrypted if the recipient turned that setting on. Once it arrives, its safety depends entirely on their device and habits, not yours.
Is it safe to email a photo of my ID?
No. Standard email isn't encrypted end to end, and a copy stays in the sender's sent folder, the recipient's inbox, and both providers' backups indefinitely, with no expiry and no record of who opened it. A passport copy gives a fraudster your name, date of birth, photo, signature, document number, nationality, and place of birth in one file.
What's the safest way to send my passport to a lawyer, agent, or landlord?
Ask them to send you a secure upload link rather than requesting it by email or chat. A good link encrypts the file in your browser before it's sent, is scoped to that recipient, and expires, so no lasting copy is left in an inbox or a message thread. A professional who handles IDs regularly should be able to offer one.
Should I redact my passport before sending it?
Where you can, yes. Hide the document number, the machine-readable zone at the bottom, your date of birth, and your signature, keeping only what the recipient actually has to match. Adding a watermark that names the recipient and the purpose makes a leaked copy harder to reuse and obvious about where it came from.