Sending a document as an email attachment: what your mail provider really does with it
Emilien Mantel
"I'll email it, it's between two professional addresses, it's secure." We hear this sentence every week. It is reassuring, and it is wrong. Not because email is badly designed, but because it was designed for one precise thing: getting a message to someone. Not protecting a document.
This article follows an attachment from the moment you click "Send" to its destination, and shows at each step who can read it. No technical knowledge is required.
A picture to start with: the photocopied letter
Imagine an important letter you hand to the post office. It travels in a locked van between post offices: nobody can read it on the road. But at every office it passes through, it is opened, read to check that it is not dangerous, photocopied for the archives, then put in a new envelope. On arrival, the recipient receives the original, keeps a copy, and can make more for whomever they like.
Once posted, you can no longer recall it. You do not know how many copies exist, nor where. That is exactly how an email with an attachment works.
The real journey of an attachment
When you send a document by email, here is what happens, in order:
- Your email software keeps a copy in "Sent items". It will stay there for years, on your computer, on your phone, and in backups.
- Your provider's server (Microsoft, Google, OVH, your hosting company) receives the message, analyzes it, stores it, then dispatches it.
- Your recipient's provider's server receives it, runs it through its antispam and antivirus filters, which open the attachment to examine it, then files it in the inbox.
- The recipient reads it on their computer, on their phone, sometimes on their tablet. Each device keeps a copy. Their mail service backs it up. Their company may archive it, by legal obligation.
- The recipient forwards it, or replies leaving the attachment in the thread. The journey starts again from step 1, with someone you do not know.
After a few days, your document exists in a dozen copies, at no fewer than two providers, on five or six devices, in several backups. None of these copies can be recalled. Outlook's "Recall this message" feature only works inside your own organization, and only if the message has not yet been read.
"But it's encrypted, isn't it?"
Yes, in two places, and it does not change much.
In transit. Between two mail servers, the message travels through an encrypted tunnel, like the locked van in our picture. This is widespread: Google reports that about 95% of emails exchanged with Gmail are encrypted in transit. It is a standard, not a security argument. And that tunnel stops at every server, where the message is opened.
On the servers. The major providers store mailboxes in encrypted form on their disks. But they are the ones who know how to read them, and they do so all the time: spam filtering, antivirus scanning, searching your messages, making them available to an administrator in the event of legal proceedings. This is what we called the "warehouse safe" in our article on the three levels of encryption.
Even the "Encrypt" button in Outlook, in Microsoft 365, does not change this: it relies on a Microsoft service, which keeps what it takes to decrypt the message. It prevents a recipient from forwarding the message or easily taking a screenshot. It does not prevent Microsoft from reading it.
Sources: https://transparencyreport.google.com/safer-email/overview and https://learn.microsoft.com/en-us/purview/ome
Five concrete reasons why it is not secure
1. The wrong recipient. You type the first three letters of a name, the mail client autocompletes, you confirm. The document goes to a namesake, a former client, a supplier. This is not a hypothetical: according to the CNIL, the French data protection authority, sending data to the wrong recipient accounted for 13% of the data breaches notified to it in 2025, making it the second cause after hacking. With an attachment, the mistake is final: the document is with the wrong person, and you cannot take it back.
2. Forwarding. You chose your recipient carefully. They forward the message to a colleague "for information", who forwards it in turn. Nobody asks your opinion, and you will never know. Each forward creates new copies at new providers.
3. The mailbox is hackers' number one target. One guessed password, one phishing link clicked, and a stranger reads the whole mailbox, including attachments received years ago. In 2025, the FBI recorded more than 24,000 complaints for business email compromise, for 3 billion dollars in losses. In France, Bio en Hauts-de-France confirmed in September 2026 the theft of the content of emails and internal messages during a cyberattack. An attachment sent three years ago is exposed exactly like the one sent yesterday.
4. Duration. An email does not go away. It stays in mailboxes, archives and backups on both sides, long after the end of the business relationship, the employee's departure or the closing of the case. The document you send today will still be readable in ten years, in places you do not control.
5. The provider. Even if everything goes well, your mail providers, and those of your recipients, can read the document. They are subject to their own laws, sometimes foreign, and to their own security incidents. This point alone is enough to disqualify email for a document covered by professional secrecy.
"What about between two Microsoft 365 accounts, in the same company?"
That is the most favourable case, and it is still insufficient. The journey is shorter, encryption in transit and on the servers is assured. But all five reasons above apply: wrong recipient, forwarding, hacked mailbox, duration, provider. The security of a document does not depend on the quality of the mail system. It depends on whether the document is, or is not, in the mail system.
What to do instead
The solution fits in one sentence: do not put the document in the email, put a link in it.
The document is encrypted on your computer before it leaves, deposited on a service that cannot read it, and your email only contains a download link. What changes, concretely:
- No copy of the document circulates through mail systems. Not at your provider, not at the recipient's, not in backups, not in forwards.
- You stay in control. The link expires on the date you choose. You can disable it at any time, including after sending to the wrong recipient. You know who downloaded what, and when.
- A hacked mailbox does not give up your documents. The attacker finds expired or revoked links, not files.
- The recipient has nothing to install. They click, they download.
This is what the Retyc plugins for Outlook, Gmail and Thunderbird do: you write your email as usual, you attach your files through the Retyc button instead of the paperclip, and nothing else changes. The files are encrypted on your computer, Retyc cannot read them, and the email goes out with a link.
Three habits to adopt
- A sensitive document never goes in an attachment. Contracts, payslips, bank statements, identity documents, medical records, drawings: always through an encrypted link, with an expiration date.
- A received attachment gets stored somewhere other than the mailbox. Save it in your secure workspace, then delete the email. A mailbox that no longer contains documents no longer gives them up in the event of a hack.
- Re-read the recipient before sending. It is the simplest habit and the least practised. With a revocable link, the mistake can still be fixed. With an attachment, it cannot.
In short
An email with an attachment is a letter opened, photocopied and archived at every step, impossible to recall, and readable by your providers as well as by anyone who gets into a mailbox. Encryption in transit and on the servers protects against interception, not against these five risks. "Between two professional addresses" changes nothing about that. The answer is not a better mail system, it is taking the document out of the mail system.
Sources:
- CNIL, 2025 annual report, 6,167 breaches notified: https://www.cnil.fr/fr/rapport-annuel-2025
- Breakdown of causes (13% sent to the wrong recipient): https://next.ink/238330/la-cnil-confirme-un-record-de-fuites-de-donnees-en-2025-et-promet-plus-de-controles/
- FBI IC3, 2025 report, business email compromise: https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- Google, email encryption in transit: https://transparencyreport.google.com/safer-email/overview
- Microsoft, how message encryption works in Microsoft 365: https://learn.microsoft.com/en-us/purview/ome
- Bio en Hauts-de-France, stolen email content: https://frenchbreaches.com/alertes/bio-en-hauts-de-france-mtiikognot4hbi60ug
Retyc and AI: connecting your agent to your transfers and datarooms with MCP
Retyc embeds no AI. But your agent can drive Retyc: the command-line client exposes an MCP server that runs on your machine. What it enables, how to install it, what the agent sees and does not see, and the limits to know before using it.
"Encrypted" does not mean nobody can read your files
Almost every file sharing service is "encrypted". Yet in most cases, the service can read your documents. A jargon-free explanation, examples from 2026, and a single question to ask: who can read my files in plaintext?