We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
Security - sending confidential document by email
Evening
I have been asked to supply a SA100 (full tax return) to a referencing agency as additional info and it was suggested this could be done by replying to their email!
My understanding is that this isn't secure enough and therefore should only be uploaded via a secure link.
Are there any IT wizards who know if gmail is secure enough for confidential information?
Thanks
Comments
-
I'm not aware of any difference in security between different email providers, they're all as (in)secure as each other. Encrypt it and transmit the password by a separate method.
4 -
Gmail has some protection. Can you create the document as a pdf? Maybe ask if they have WhatsApp (assuming you do too) and send via that.
What details / information is in the tax return that concerns you? I have had to send several much more detailed financial documents to solicitors recently using gmail.
2 -
Email is secure enough in the direction you're sending. Once it's received by their server it should only be accessible via a password anyway. Any meaningful interception would involve having access to their server.
Most of the insecurity of email is in spoofing the sender, in that you can send an email claiming to be from anyone and containing anything.
If you want to make it more secure:
1. Don't send it from a public network (i.e. use your home network and not a coffee shop)
2. Password protect or encrypt it, and give them the password via a different mechanism to the file (i.e. email them the file and call them with the password). Though it's worth noting that the password will be written on a post-it and they'll save the unencrypted version anyway. Neither is really a concern because if anyone is on premises to get the file and/or post-it, they'd be able to get to it however it was secured.0 -
Its not going to be with the likes of consumer gmail -v- icloud for example. If you run your own servers you can setup enforced TLS 1.3 or similar so it will only send via encypted connection and wont follow the opportunistic nature of normal email which will look at unencrypted connections if encrypted fail.
0
Confirm your email address to Create Threads and Reply
Categories
- All Categories
- 355.6K Banking & Borrowing
- 254.8K Reduce Debt & Boost Income
- 456.1K Spending & Discounts
- 248.2K Work, Benefits & Business
- 605.7K Mortgages, Homes & Bills
- 179K Life & Family
- 263.5K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.7K Read-Only Boards

