50% off Agency for 3 monthsStart free

How to password-protect a PDF (and when not to)

Add a password to a PDF on Mac, Windows or the web — free, in a couple of minutes. Then the part nobody mentions: what a password on a sent file cannot do.

Richard Henney5 min read

Someone asks you for the contract, the pricing sheet, the report with real numbers in it. You do the sensible thing: you put a password on the PDF before you send it.

This is a genuinely good instinct, and it takes about two minutes. Here is how to do it on whatever you’re using — and then the part that tool pages never mention, which is what a password on a sent file can and can’t actually do.

On a Mac

Preview does this natively, so you don’t need to install anything.

  1. Open the PDF in Preview
  2. File → Export as PDF…
  3. Click Show Details if you don’t see the options
  4. Tick Encrypt, type your password twice, and save

That’s it. The exported copy needs the password to open. Your original stays unprotected, so keep track of which is which — a surprising number of people email the wrong one.

On Windows

Windows has no built-in way to encrypt a PDF, which surprises people. Two realistic options:

If you have the source document in Word: File → Save As → PDF, then Options → Encrypt the document with a password. This is the cleanest route, because the protection is applied at export rather than bolted on afterwards.

If you only have the PDF: you’ll need a tool. Adobe Acrobat does it properly if you have it. Otherwise a web tool will, with the caveat below.

With a free web tool

Smallpdf, iLovePDF and PDF2Go all password-protect a PDF free, in a browser, in about thirty seconds.

The caveat is worth taking seriously: you are uploading your confidential document to a stranger’s server in order to make it confidential. For a menu, fine. For a contract, salary data or anything under NDA, think about whether the file should be leaving your machine at all. Most of these services delete uploads after an hour or so — but you’re trusting a privacy policy, not a guarantee.

Which password to use

Skip the advice about symbols and capitals. Two things actually matter:

  • Length beats complexity. A four-word phrase you can say down the phone is stronger than Tr0ub4dor&3 and far easier to communicate.
  • Don’t reuse it. Not across documents, and definitely not one you use anywhere else. Client documents get forwarded, and passwords travel with them.

Now the part nobody mentions

Password-protecting a PDF works exactly as advertised. The document can’t be opened without the password, and modern AES encryption is genuinely strong.

The problem isn’t the encryption. It’s everything around it.

You almost always send the password down the same pipe as the file

The document goes by email. Then, moments later, the password goes by email — often in the same thread, sometimes in the same message. Anyone who can read one can read the other. You’ve locked the door and taped the key to it.

Sending it by text or saying it on a call genuinely helps. Most people don’t, because it’s friction, and friction is what security dies of.

You cannot un-send it

This is the big one, and it’s structural rather than a flaw you can work around.

The moment that file lands in someone’s inbox, you have permanently lost control of it. You cannot:

  • Change the password
  • Revoke access
  • Expire it after a deadline
  • Update the document if something in it was wrong
  • Stop it being forwarded to someone you never intended

A contract you sent in March, with a price you no longer honour, is still sitting in an inbox with its original password, readable forever. If it gets forwarded to a competitor, the password goes with it.

It tells you nothing

You have no idea whether the document was opened, when, by whom, or whether anyone read past page one. For a menu that doesn’t matter. For a proposal you’re waiting on, it’s the only thing you actually want to know.

When a password is the right answer

To be clear, because this isn’t an argument against passwords:

  • The recipient must be able to keep the file — offline, in their records, in their own system
  • You’re satisfying a policy that specifically requires an encrypted file
  • The document is genuinely final and will never need correcting
  • You’re handing it over on a USB stick or something else that isn’t a link

In those cases, encrypt it, send the password separately, and you’re done.

If what you actually want is “only the right people should read this, and I want to stay in control” — a file is the wrong shape for that job. A link fits it better, because a link is something you still own after you’ve sent it.

With a document behind a link, you can:

  • Unpublish it. Deal’s off, deadline passed, sent to the wrong person — it stops opening, everywhere, immediately.
  • Update it. Fix the typo or the price without sending anything. Everyone who follows the link sees the current version.
  • See whether it was opened. And how far they read, which for a proposal is the whole game.
  • Ask for an email first, if you want to know who’s looking rather than just how many.

You can still put a password in front of a link, and that combination is usually what people wanted in the first place: a gate you can move, on a document you can still change.

Living Page does this — you upload the PDF, get a link, and can put a password or an email gate in front of it. Passwords and the email gate are on the Solo plan and above; the link, the reader and read analytics come with the free plan.

The honest summary

Encrypting a PDF protects the file. It’s the right tool when the recipient needs to keep a copy.

But most of the time, what people mean by “protect this document” is I want to control who reads this, and I want to be able to change my mind. A password can’t do that, because you can’t reach a file you’ve already sent. A link can, because you never let go of it.

Work out which of those two things you actually need. It’s usually the second one.

Frequently asked questions

How do I password-protect a PDF for free?
On a Mac, open the PDF in Preview and choose File → Export as PDF, tick Encrypt, and set a password — no extra software needed. On Windows there is no built-in option, so use a free web tool or Microsoft Word's Save As → Options → Encrypt with password when exporting to PDF. Web tools like Smallpdf and iLovePDF also do it free, though you are uploading the file to someone else's server, which matters if the document is confidential.
Can a password-protected PDF be cracked?
A strong, unique password with modern AES encryption is genuinely hard to break. The realistic weak points are elsewhere: short or guessable passwords, and the fact that you almost always send the password to the same person, in the same channel, as the file itself. If someone can read the email containing the file, they can usually read the email containing the password.
Can I remove a password from a PDF I already sent?
No. Once the file has left your hands, you cannot change it, revoke it or expire it. Every copy in every inbox keeps its original password forever. If you need to withdraw access after sending, a password on a file is the wrong mechanism — you need a link you control, which you can unpublish.
What is the difference between a PDF password and a protected link?
A PDF password protects the file. A protected link protects access to the document. The practical difference is control after the fact: a file you have sent can never be recalled or updated, while a link can be unpublished, replaced or expired at any time. A password also tells you nothing about who opened it; a link can.
Does password-protecting a PDF stop it being forwarded?
No. The file can be forwarded exactly as before — the recipient simply needs the password to open it, and people routinely forward both together. Passwords control opening, not distribution. Nothing you attach to an email can stop it being passed on.

Turn your next PDF into a living page

Upload a PDF and share a page-turning link in about a minute. Free to try — no page caps, no ads on your work.