How to Share a PDF Safely
"Sharing a PDF safely" means three different things at once: protecting the file itself (so the wrong person cannot open it), protecting what the file reveals about you (metadata), and protecting the channel (so the file is not intercepted in transit). This guide covers all three layers, in the order you should apply them, and is honest about which layers a browser-based tool like IXPDF can handle today.
Learn more aboutwhy local PDF processing mattersfor document security.
The three layers of safe sharing
- Strip metadata — the PDF's Title, Author, Subject, Keywords, CreationDate, ModDate, Producer, and Creator fields can reveal who made the document, when, and with what tool. This is the cheapest layer and the one most people skip. IXPDF does this locally with Edit Metadata.
- Password-protect the file — add encryption so the file cannot be opened without a password. This is the strongest layer when applied correctly (AES-256, a strong password). IXPDF'sProtect PDF tool is currentlyResearch Required — see the section below for why, and which tools to use instead today.
- Use an encrypted channel — even a password-protected file should travel over TLS, and for sensitive content, end-to-end encryption. Email is TLS by default; end-to-end requires a provider like ProtonMail or Tresorit, or a separate step (e.g., encrypting the file with GPG before attaching).
Layer 1: strip metadata before sharing
Every PDF carries a document information dictionary with fields like Title, Author, Subject, Keywords, CreationDate, ModDate, Producer, and Creator. These are visible in any PDF reader's "Document Properties" dialog. They travel with the file wherever it goes — email, cloud storage, a public website. If you wrote the document in Word and exported to PDF, the Author field is probably your name. If you edited it in Acrobat, the Producer field says so.
To strip metadata locally:
- Open /tools/edit-metadata/.
- Drop in your PDF. The tool reads the metadata and shows every field.
- Clear the fields you do not want to share — typically Author, Title, Subject, Keywords, and Creator.
- Download the cleaned PDF. The file never leaves your device.
For the full picture of what each field reveals and how to clear it, see How to Remove PDF Metadata.
Layer 2: password-protect the file
Password protection adds encryption so the file cannot be opened (or, optionally, printed, copied from, or edited) without a password. This is the strongest layer when applied correctly: AES-256 encryption with a strong password is, as of 2026, not practically breakable.
Trusted local tools for password protection:
- Adobe Acrobat Pro (paid) — File → Protect Using Password, choose AES-256.
- Preview on macOS (free, built-in) — File → Export → Encrypt, set a password. Uses AES-128 on recent macOS.
- qpdf (free, command line) —
qpdf --encrypt "userpw" "ownerpw" 256 -- input.pdf output.pdf. The most flexible option; lets you choose AES-128 or AES-256 and set permission flags independently. - PDF24 Creator (free, desktop) — has a "Set PDF password" tool that runs locally after install.
For the full guide on password types, encryption algorithms, and which to pick, see How to Password Protect a PDF.
Layer 3: use an encrypted channel
A password-protected PDF is safe at rest, but it still has to travel from you to the recipient. The channel matters.
- Standard email (Gmail, Outlook, Yahoo): transport is TLS between mail servers, so the file is encrypted in transit. But the email provider can read the attachment at rest on their servers. For non-sensitive content, this is fine. For sensitive content, it is not.
- End-to-end encrypted email (ProtonMail, Tresorit Mail): the attachment is encrypted on your device and only the recipient can decrypt it. The provider cannot read it. This is the right channel for sensitive PDFs.
- Cloud-storage link (Drive, Dropbox, OneDrive): the file is uploaded to the cloud provider; access is controlled by the share settings. Set an expiry, restrict to the recipient's email, and prefer this only when the file is not sensitive enough to warrant end-to-end encryption.
- Signal, WhatsApp, Wire: end-to-end encrypted messengers. Good for small PDFs; size limits apply (100 MB on WhatsApp, 100 MB on Signal).
Send the password through a different channel
If you password-protect the file and send it by email, do not send the password in the same email. That defeats the purpose — anyone who compromises the email gets both the file and the key. Send the password through a different channel: a text message, a phone call, a separate email to a different address, or a password-sharing tool like OneTimeSecret. This is called out-of-band key exchange and it is the single highest-leverage habit in secure file sharing.
Step-by-step: the safe-sharing workflow
- Strip metadata. Open /tools/edit-metadata/, clear Author/Title/Subject/Keywords/Creator, download.
- Password-protect (if sensitive). Use Acrobat Pro, Preview, or qpdf to add an AES-256 password. IXPDF's Protect PDF is under research — see above.
- Pick the channel. Standard email for non-sensitive, end-to-end encrypted email or messenger for sensitive, cloud link with expiry for large non-sensitive.
- Send the password out-of-band. Text, call, or separate channel — never the same email as the file.
- Confirm receipt. For sensitive files, ask the recipient to confirm they opened it. Silent failures are how shared files get lost.
Common mistakes
- Password-protecting but leaving metadata. The password stops a stranger opening the file, but the Author field still says your name. Strip metadata first.
- Sending the password in the same email. The most common mistake. Anyone who reads the email has both the file and the key.
- Using RC4 encryption. Old PDFs (and old tools) use RC4, which is deprecated and breakable. Re-encrypt with AES-256. qpdf and recent Acrobat default to AES.
- Sharing a Drive link with "anyone with the link".That link can be forwarded. Restrict to the recipient's email and set an expiry.
- Trusting "secure" in a tool's marketing copy."Secure sharing" usually means TLS in transit, not end-to-end encryption. Read the provider's documentation, not the landing page.
For broader best practices on handling sensitive documents, read ourSafe PDF Handling guide.
Try it now
Ready to put this into practice?
Run the tool locally in your browser — no upload, no account, no watermarks. Your file never leaves your device.