I already sent a password by email. What now?
You have just sent a password in an email, or you have realised that one went out last week. It happens to everyone, and it is rarely a disaster. But it is not fixed by deleting the message, and it is worth ten minutes now rather than wondering about it later.
Assume the email is permanent
An email is not one copy that you control. By the time you notice, it is likely to exist in several places:
- Your Sent folder, and the recipient's inbox.
- The mail servers of both of your providers, and their backups.
- Every phone, laptop and mail app either of you is signed in on.
- Wherever it was forwarded, and the archive of any shared or group mailbox it went to.
Most mail travels between servers encrypted these days, but that protects it on the way, not where it is stored. Nothing in an ordinary email stops the password from being read by anyone who later gets into either mailbox.
Deleting and recalling do not undo it
You can delete the message from your own mailbox, and that is worth doing. You cannot delete it from the recipient's. The "recall" feature in some mail programs only works in narrow circumstances, typically when both of you are in the same organisation's mail system and the message has not been opened. Outside those, the recipient gets a second email asking them to ignore the first, which is not the same thing.
So treat the password as known to more people than you intended, and move on to the part that actually helps.
Change the password
This is the real fix, and it makes every copy of the email harmless: a password that no longer works cannot be misused, however many mailboxes it sits in.
- Change it now, on the account it belongs to. Make the new one long and random; the password generator makes one in your browser without sending it anywhere.
- If the same password is used anywhere else, change it there too. Reused passwords are how one exposed email turns into several compromised accounts.
- While you are in the account settings, turn on two-factor authentication if it is available. It means a password that leaks in future is not enough on its own.
- Look at recent activity and signed-in sessions, if the service shows them. Sign out sessions you do not recognise.
If it was an API key or a token
Do the same thing with a key: create a new one, put it where the old one was used, and then revoke the old one. Most providers keep a log of requests per key; check it for use you do not recognise between the time the email was sent and the time you revoked the key. If the key was yours and the recipient needs access, consider giving them a separate, limited key instead, as described in How to give an API key to a contractor.
Send the new one properly
If the person you emailed genuinely needs the password, they now need the new one. Do not send it by email again, or in a reply to the same thread. Send it through a one-time link instead:
- Open PassAlong and paste the new password. Add the username and the sign-in address if they help; all of it is encrypted together in your browser.
- Keep "Destroy after it is opened" on and pick a short lifetime.
- Send the link. The key travels inside it, so an email still carries the secret; what changes is that a one-time link stops working after one use, and if someone in either mailbox opens it before your recipient does, your own link tells you so. A password typed into an email offers neither.
- Keep your own link, which shows when the password was opened and lets you revoke it before then.
If you typed or pasted the password yourself, PassAlong also checks, in your browser, whether it appears in known data breaches, sending only the first five characters of its hash. A warning there is a good reason to pick a different one; how the leak check works explains what it sees and what it means. How the encryption works, and what our server can and cannot see, is described in How it works.
Tidy up what you can
- Delete the original email from your Sent folder and your deleted items.
- Ask the recipient to do the same with their copy. It reduces the number of copies, even if it cannot remove all of them.
- If it was a work account, tell your IT or security team. For them this is routine, and they may know about copies you do not, such as mail archiving.
Next time
The habit that prevents this is small: when a message is about to contain a password, send a link instead. For passwords shared inside a team, see how to share a password with a colleague without leaving it in the chat, which covers the same problem in Slack and Teams.