Is fax more secure than email, really
Fax is not inherently more secure than email. That is true whatever the reason someone has given you for insisting on it, whether it's a solicitor, a GP surgery, an insurer or a court.
The belief that fax is the safer option usually comes from the fact that it doesn't touch the internet. A fax travels over telephone lines rather than through an email server, so it feels separate from things people worry about with email, like hacked accounts or a message forwarded to the wrong person. Feeling separate from a risk is not the same as being protected from it.
What actually decides how safe a document is
Whether a document stays private has less to do with which technology carries it and more to do with what happens at either end: who is standing near the machine when it prints, how long the page sits there before someone collects it, and whether anyone has bothered to lock down access on either side. A fax can sit on a shared printer in an open office for an hour. An email can sit unread in an inbox that half the office can log into. Neither method decides that for you.
Before you choose how to send something sensitive, it's worth being clear on what actually happens to a document once it leaves your phone or computer, and whether a fax is even the right tool for what you're trying to do. If you haven't already worked out whether you need to send a fax at all, that's the question worth settling first.
What actually happens to a document you fax
A fax leaves your phone or computer, gets converted into a signal, and travels down the ordinary telephone network to the machine or online inbox on the other end. That is the public switched telephone network (PSTN), the same wiring that carries a phone call, and it was never built with encryption in mind.
A phone call on that network can, in principle, be listened to at various points along the line. A fax is no different. There is no scrambling of the data, no password on the transmission itself, and no way to check afterwards that nobody was on the line while it went through.
Where the document ends up
If you are sending to a physical fax machine, the document prints out on whatever is on the other end. That is often a shared machine in an office, sitting in a tray until someone collects it. Anyone walking past can pick it up and read it, which is the opposite of what most people picture when they hear the word secure.
Many institutions now receive faxes into an online fax service, which converts the incoming signal into a PDF and puts it in an inbox. That removes the shared-tray problem but does not add encryption to the leg of the journey that still runs over the phone network.
How that compares with email
Email sent between two modern providers is usually encrypted in transit, meaning the contents are scrambled while travelling and only readable at either end. A fax has no equivalent step. So the claim that fax is inherently more secure than email does not hold up when you look at what actually happens to the data.
The more useful question for a specific document is who can see it once it arrives. A fax sitting in a shared office tray and an email sitting in an inbox with a weak password carry different risks, and neither is automatically the safer choice.
If security is your actual concern rather than the fax being a formality, it is worth asking the person requesting it whether a secure portal upload or a signed PDF sent by email would be accepted instead. The guide on whether you need to send a fax at all covers how to have that conversation.
What happens to your document once it reaches the fax provider
When you send a fax through an online fax service, the document does not simply disappear once it is transmitted. It usually passes through the provider's own servers first, because that is how the service converts your file into a signal the receiving fax machine can read. What happens to it after that depends on the provider.
What tends to be stored
Most online fax services keep a copy of the document you sent, at least for a period, along with a transmission confirmation showing it was delivered. Some keep this in an account history you can log into later. Others treat a one-off fax as disposable and delete it after a set number of days.
The retention period, and whether the document sits on a server in the UK or elsewhere, is set out in each provider's own privacy policy. If the content of the document matters to you, that policy is worth opening before you upload anything.
Why this differs from a fax machine
A traditional fax sent machine to machine leaves no copy anywhere except the paper that comes out the other end. Routing the same document through a website adds a step a paper fax never had: a company now holds a digital copy of what you sent, for as long as its policy says it will.
That is not necessarily worse. A signed PDF sent by email sits on a mail server in much the same way. But it is a different kind of exposure to weigh up, and it is worth knowing about before you decide how to send something.
What to check before you send
- How long the provider says it retains sent documents
- Whether the document is stored encrypted, or just the connection to upload it is
- Whether an account is required, and what is kept against that account
- Whether the free tier and the paid tier of the same service have different retention terms
None of this is usually hidden. It is normally written into the provider's privacy policy in plain terms, it is just rarely read before people upload a document under time pressure. If you are still deciding whether you need to send a fax at all, that question is worth settling first.
Why some institutions still insist on fax
A GP surgery, a court or HMRC asking for a fax is not making a judgement about which channel keeps your document safest. It is following an internal process that was built around fax long before email existed, and updating that process is not high on anyone's list.
A fax number points at one place
A fax number is usually tied to a specific machine in a specific department, sometimes a specific desk. That gives an institution a level of certainty that a document has landed where it was meant to: nobody typed the wrong address, and nothing bounced into a shared inbox by mistake. Email addresses get mistyped, forwarded and abandoned far more easily than a fax line that has sat in the same office for years.
Old procedure, not a security decision
Solicitors, courts and GP surgeries often specify fax because it is what their compliance or filing procedure already names. The same goes for US employers who still list a fax number on a form. Changing that instruction means updating a procedure document, training staff, and satisfying whoever signed off on the original process, and that work rarely happens unless something forces it.
What this means for you
You are not choosing a less safe option by sending a fax instead of an email, and you are not choosing a safer one either. The two carry different risks. If an institution asks for a fax, sending one gets the document to the right place inside their system, which is the thing they actually care about.