Fax security and encryption
Fax security and encryption: a reputation without a protocol
Fax is treated as safe in professions that handle sensitive documents. That reputation rests on no encryption at all: it rests on a network topology that has gone.
Short answer
Fax is not encrypted. T.30, the protocol that governs transmission between two fax machines, provides no encryption mechanism: pages travel in the clear. What protects a fax in practice is therefore not the protocol but the way it is sent: a known destination machine, a cover page that gives nothing away, and retention you have thought about.
T.30 provides no encryption
The standard describing negotiation and transmission between two fax machines defines speeds, coding formats and control messages. It defines no key, no shared secret and no verification of the remote machine's identity beyond the identifier that machine declares about itself. A fax is therefore sent in the clear, and nothing in the protocol lets the sender know who is actually at the other end of the line.
What actually protects a transmission
Three things, none of them cryptographic. The destination machine: a number confirmed with the recipient, and a machine whose location is known — the most common leak is not interception but a wrong digit, or a fax machine standing in a corridor. The cover page: a file reference is enough, while a reason or an amount already tells whoever walks past. Retention: a fax leaves traces on both sides — the machine's memory, the transmission log, a copy on an online service's server — and knowing how long each one survives is better than assuming none exists.
What the move to IP removed without saying so
The security attributed to fax was a property of the transport, not of the document: tapping a switched line meant reaching the physical circuit, which in practice limited who could do it. Over IP transport, the page crosses equipment that handles it and, depending on the service, servers that store it. The protocol has not changed — T.30 never encrypted anything — but the implicit protection around it has gone. Practices built on that protection, not least where medical or professional confidentiality applies, therefore rest on an assumption that now has to be checked rather than presumed.
Frequently asked questions
- Is fax safer than email?
- It was, while it travelled over a switched line. Today an encrypted email protects the content where a fax does not; on the other hand a fax is delivered to a known machine, whereas an email is forwarded with no effort at all. The two risks are not of the same kind.
- Is fax suitable for health data?
- It remains widely used, and medical or professional confidentiality applies to the document whatever the means of sending. The useful precaution is not to trust the channel but to check the number, limit what the cover page reveals, and know where the transmitted copy is kept.
Send a fax now
The form fits on one page: a PDF, a recipient and a return address. No account, no card.
Open the form