The safest way to share documents with your solicitor is through the firm's own secure client portal. If they don't have one, send an encrypted or password-protected file and give them the password by phone or text - never in the same email. Plain email, the shared family cloud, and your ex's old laptop are the three things to avoid.

That's the short version. The rest of this is the how, so you can do it once and stop thinking about it.

When I went through my divorce, nobody told me my paperwork was a target. I emailed my lawyer a scan of my bank statements like I'd email a colleague a spreadsheet. It worked. It also sat in two inboxes and probably a phone backup somewhere - account numbers, my address, my kids' names. I got lucky. You don't have to rely on luck.

Key Takeaways

  • Email was never built to be private. In 2024, Gmail still left around 10% of outbound messages unencrypted in transit because the receiving server didn't support it (Google Transparency Report).
  • Email is the number-one way attacks get in - roughly 68% of cyberattacks start there, and the 2024 Verizon DBIR found 94% of malware arrives via email (Proofpoint).
  • The most common reported data incident isn't hacking - it's sending email to the wrong person, around 21% of cases (Egress).
  • Law firms get breached too. The average law-firm breach cost $5.08 million in 2024, up more than 10% year over year (Embroker).
  • The fix is boring and it works: a secure portal, encrypted files, and passwords sent over a separate channel.

Why can't I just email my divorce documents?

Because email is a postcard, not a sealed letter. It can pass through several servers between you and your lawyer, and it only stays encrypted if every one of those servers agrees to encrypt it. They don't always agree.

Google's own numbers make this plain. In 2024, about 90% of messages Gmail sent and 96% it received were encrypted in transit - which sounds great until you realize the missing slice is millions of messages a day traveling in the clear. That gap exists because the old email protocol never required encryption. It still doesn't.

Around 10% of Gmail's outbound mail in 2024 wasn't encrypted in transit, because the receiving server didn't support it. Source: Google Transparency Report - Email encryption in transit.

There's a second problem, and it's bigger than interception: once you send an email, you've lost control of it. It lives in your sent folder, the recipient's inbox, and any backup either side keeps. Years later it's still there. A divorce file you sent in July is still sitting in three places at Christmas.

If you're still untangling shared accounts and devices, start with the divorce digital security checklist before you send a single file.

What makes divorce paperwork so sensitive?

It's the exact bundle a criminal would build by hand if they could. In one folder you've got bank statements, tax returns, pay stubs, your driver's license or passport scan, your address, your kids' details, maybe a Social Security number. That's identity theft, account takeover, and stalking risk in a single zip file.

And the people you're sending it to are themselves a target. Law firms hold concentrated personal and financial data, which makes them worth attacking.

Up to 40% of law firms reported a security breach, and the average law-firm breach cost $5.08 million in 2024 - more than 10% higher than the year before. Source: Embroker - Law firm cyberattacks: stats and trends.

This isn't a reason to distrust your lawyer. It's a reason to make the handoff clean, so there are fewer loose copies for anyone to find. One real breach - the Orrick incident - exposed names, birth dates, and Social Security numbers of more than 600,000 people whose data the firm was simply holding (eMazzanti). Fewer copies, smaller exposure.

What's the safest way to send documents to my lawyer?

Use the firm's secure client portal first. Most established firms have one - a login-protected website where you upload files directly to your case. The document never travels through open email; it goes from your browser straight into their system over an encrypted connection.

Ask for it by name. A simple line works: "Do you have a secure client portal I should use for uploading documents? I'd rather not send these by regular email." Any decent firm will say yes and send you a link. If the person you ask doesn't know, ask whoever handles their IT or billing - portals are common enough now that the answer is usually just "oh, yes, here."

A portal also keeps everything in one place. No hunting through your sent folder for which version you shared, no wondering if it arrived. You upload, it's there, and it's not copied into a dozen inboxes along the way.

If the firm genuinely has no portal, don't force email. Move to the next option.

How do I password-protect or encrypt a PDF?

You add a password when you save the file, then share that password separately. It takes about a minute and it means a stray copy is useless to anyone who doesn't have the key.

On most computers you don't need extra software:

  • On a Mac: open the file in Preview, choose File then Export, and tick "Encrypt." Set a password.
  • On Windows: open the document in Word, go to File, Info, "Protect Document," then "Encrypt with Password." Save it as a PDF.
  • From your phone: most scanning apps (including the built-in Notes scanner on iPhone) let you lock a PDF with a password before you share it.

Use a strong password you don't use anywhere else - a few random words strung together beats a clever-looking short one. If you're not already using a password manager to keep track, that habit is worth building now; here's the password manager basics version.

One caution: encrypting the file protects the file, not the email it rides in. So you still send the password by a different route. More on that in a moment.

Are encrypted file links with expiry safe to use?

Yes, when you set them up properly - and they're often the most convenient option. Services like a personal cloud drive let you create a share link that's encrypted in transit, restricted to specific people, and set to expire on a date you choose.

The settings that matter:

  • Restrict access to the lawyer's email address, not "anyone with the link." A link "anyone can open" is one forwarded message away from being public.
  • Set an expiry so the link dies after a week or two. A live link that works forever is a copy you've left propped open.
  • Turn off downloads if the service allows it and the lawyer only needs to view the file.
  • Delete the share once they confirm they've saved their copy.

The point of expiry is simple: you're not just sending a file, you're closing the door behind it.

How should I share the password?

Over a different channel than the file - that's the whole rule. If you email an encrypted PDF and email the password, you've locked the door and taped the key to it.

So: send the document one way, send the password another. Email the file, then text the password. Or upload to the portal and read the password over the phone. Or use the portal for the file and a messaging app for the key. Any two separate paths work, because an attacker who gets into one is unlikely to also have the other.

Sending email to the wrong person was the single most common reported data incident, around 21% of cases - and about a quarter of adults admit they've done it. Source: Egress - What is a misdirected email.

That stat is the quiet reason separate channels matter. You don't have to be hacked to leak your own divorce file - you just have to let autocomplete pick the wrong "David" while you're tired and moving fast. If the file's encrypted and the password went by a separate path, a misfire is an awkward apology instead of a breach.

[PERSONAL EXPERIENCE] The first time I did this properly, I felt slightly ridiculous reading a password down the phone to a paralegal like a spy. She didn't blink. She told me half their clients now do it, and the ones who don't are usually the ones calling back in a panic about a forwarded statement. It stopped feeling silly after that.

What should I never do when sharing legal documents?

Avoid the three habits that quietly leak your case. None of them feel risky in the moment, which is exactly why they catch people.

Don't reply-all or forward the thread. Divorce email chains grow long, and the original attachment rides along at the bottom every time. One reply that loops in a new person - a real-estate agent, a relative, an accountant - and they've now got everything above it. Start a fresh message when the audience changes.

Don't use the shared family cloud or a shared device. If you and your ex ever linked phones, computers, or a family storage plan, treat all of it as readable by the other side until proven otherwise. Uploading your financials to a drive your ex can still reach is the same as handing them over. Before you share anything, make sure your accounts are actually yours alone - and if you're still untangling phones, how to remove find my iphone when you separate is the place to start. For accounts your ex might still touch, see what to do if your ex still has your passwords.

Don't send to your ex's device or an account they can see. Sounds obvious, but old shared iPads, a work laptop you both used, a Gmail with a recovery number that's still their phone - these are the gaps. Use an account that's clean and only yours. If you don't have one yet, set one up first: how to set up a separate email account during divorce.

[PERSONAL EXPERIENCE] My own slip was the shared cloud. I'd forgotten my laptop still backed up to a drive we'd set up years earlier "for the photos." Nothing came of it, but I spent a bad afternoon working out exactly what had synced and when. Check first. It's a calmer way to live.

A simple order to follow

If you remember nothing else, work down this list and stop at the first option that's available:

  1. The firm's secure client portal. Ask for it. Use it.
  2. A restricted, expiring encrypted link to just the lawyer's address.
  3. A password-protected PDF, with the password sent by phone or text.
  4. Plain email - only as a last resort, and only for documents that aren't sensitive.

Most of the weight on a divorce already lands on you. The mechanics of moving a few files shouldn't add to it, and once you've done it cleanly the first time, it's just how you do it.

Frequently asked questions

Is it safe to email documents to my lawyer at all? For genuinely non-sensitive items, ordinary email is fine. For anything with account numbers, ID, or family details, don't rely on it - email isn't reliably encrypted end to end, and copies linger in both inboxes. Use a portal or an encrypted file with a separate password instead.

My lawyer doesn't have a secure portal. What now? That's common with smaller firms. Send a password-protected PDF or a restricted, expiring share link, and give the password by phone or text. You can also politely ask whether they accept encrypted email - many do, even without a full portal.

Can my ex see what I send to my solicitor? Only if you share a channel they can reach - a joint cloud account, a shared device, or an email with their phone as the recovery number. Send from an account that's solely yours, and confirm your devices aren't backing up to anything shared.

What if I already emailed sensitive documents in plain email? Don't panic - you can't un-send it, but you can reduce future exposure. Switch to a secure method going forward, delete the old copies from your sent folder where you can, and change any passwords or account details that were visible in those files.


If figuring out the digital side of separating feels like a second full-time job, you're not imagining it. I write a quiet, no-hype newsletter for men working through exactly this - one practical thing at a time. If that sounds useful, coping with divorce as a man is a good place to start, or sign up and I'll send the next one your way.

Sources

  1. Google - Email encryption in transit (Transparency Report). transparencyreport.google.com/safer-email
  2. Proofpoint - Email Attacks Drive Record Cybercrime Losses in 2024 (citing the 2024 Verizon DBIR). proofpoint.com
  3. Embroker - Law firm cyberattacks: stats and trends for 2025 (law-firm breach cost and prevalence). embroker.com
  4. Egress - What is a misdirected email? (ICO misdirected-email incident data). egress.com
  5. eMazzanti - Top 5 U.S. Law Firm Breaches (Orrick incident, 600,000+ affected). emazzanti.net