Which encryption should you choose?
AES-256 is the current standard and what every reader made in the last decade supports. Older files use RC4 at 40 or 128 bits, which is broken and should never be chosen for something new.
The strength of the encryption is capped by the password: a six-character word falls to a dictionary attack whatever the cipher. A short passphrase of unrelated words beats a clever short password.
How should you send the password?
Not in the same email. An attachment and its password in one message protect nothing — anyone reading the mailbox has both.
Send it by a different channel: a text message, a phone call, a chat app, or a shared secret the recipient already knows. For repeat correspondence, agree a scheme once rather than inventing one each time.
What else is inside the file?
Run the scanner before sending. It looks for personal data in the text (emails, phone numbers, card and ID numbers), metadata fields, text hidden behind images, embedded attachments and JavaScript actions, and it tells you which page each one is on.
Attachments and scripts are worth special attention: a PDF can carry another file inside it, and readers that honor scripts will run them.
What should you decide about the recipient?
Permissions are a statement of intent, not a lock: printing and copying restrictions are honored by well-behaved readers only. Use them to say what you expect, and encryption to actually control access.
If the document should not be altered — a signed agreement, a filled form — flatten it so the fields and annotations become part of the page.
- Encrypt with AES-256 and a passphrase, not a word.
- Send the password by a different channel.
- Clear metadata, or set it deliberately.
- Scan for personal data, hidden text, attachments and scripts.
- Redact anything that must not be read, rather than covering it.
- Flatten forms and signatures so they cannot be changed.
- Keep the original: the encrypted copy is for sending, not for your archive.