Bank statements, tax filings, medical records and signed contracts all get emailed around as PDFs. PDF encryption is a real protection for those, but the feature sitting next to it - permissions - is widely misunderstood, and the gap between the two is where people get caught out.
Want to skip the reading? The tool this guide covers is free and needs no sign up.
Password Protect PDFEncryption: the part that genuinely protects the file
Setting an open password encrypts the document with AES-256, the strongest algorithm the PDF standard supports. Without the password the file is mathematically unreadable - not hidden, not restricted, actually unreadable. There is no recovery, by us or anyone else.
That cuts both ways. If you lose the password, the document is gone. Store it in a password manager before you send the file, not after.
Never send the password in the same email as the file. Use a different channel entirely - a phone call or a message - or the encryption has protected nothing.
Permissions: an instruction, not a lock
The printing, copying and editing checkboxes work differently. They set flags that tell reader software what it should allow. Mainstream readers respect them, which makes them useful for signalling intent to a colleague.
They are not a security control. Anyone determined enough can ignore those flags, and plenty of tools do. Treat permissions as a "please do not" sign rather than a locked door, and never rely on them for anything that would genuinely harm you if copied.
Choosing an algorithm
AES-256 is the right default and works in every reader made in roughly the last decade. AES-128 and RC4-128 exist for very old software - RC4 in particular has known weaknesses and should only be chosen if a specific old system demands it.
What encryption does not cover
Encrypting a PDF protects the contents of the file. It does not remove metadata that may already identify you - author name, the software you used, creation and modification dates - and it does not remove anything visible on the pages themselves.
If you are sending a document to someone who should not know who prepared it, clear the metadata before you encrypt. If the pages contain personal details that the recipient should not see, redact them properly first - covering text with a black box leaves the words underneath fully recoverable unless the tool also removes them.
Frequently asked questions
Is a password protected PDF safe to email?
The file itself is, provided you used a strong password and sent it separately from the document. Email is not a private channel, but AES-256 encryption means an intercepted file is useless without the password.
Can you recover a PDF password for me?
No, and no honest tool can. Removing a password requires knowing it. Anything advertising password recovery for arbitrary files is either guessing common passwords or misrepresenting what it does.
How long should the password be?
Length beats complexity. Four random words are stronger and far easier to relay over the phone than eight scrambled characters.
Tools mentioned in this guide
Remove owner passwords and printing restrictions from your PDF files.
Strip author name, creation dates, and hidden details from your PDF before sharing.
Permanently blackout SSN, credit cards, bank accounts, and personal data from PDF.
Last updated 18 February 2026. Back to all guides