Most firms never actually decide to use email for client tax documents. It’s just what everyone already has open, so it becomes the default without anyone weighing the risk. Standard email relies on encryption that can fail without any warning, and even when it works, that protection only covers the trip between mail servers. Once a message lands in an inbox, it typically sits there, unencrypted, for as long as anyone leaves it. Here’s what email actually protects, and where that protection runs out.
Key takeaways
- Standard email relies on opportunistic TLS. Encryption applies only if both mail servers support it, and the message falls back to unencrypted transmission silently when they don’t.
- Even when TLS works, it only protects a message in transit between servers. Once the message lands in an inbox, that protection ends.
- A single email gets copied multiple times as it moves through mail servers, with no guarantee those copies get purged on any schedule.
- Account compromise is the more common way tax data in email actually gets exposed, more so than interception. A weak password or a phishing click hands over everything already sitting in that inbox.
- A secure client portal solves the persistence problem directly: access gets logged, links can expire, and there isn’t a permanent unencrypted copy sitting in an inbox for years.
Table of Contents
Why “email is basically secure” is the wrong assumption
Email feels secure mostly because it feels routine. Nobody sends a client’s return by email and thinks about encryption at all, the same way nobody thinks about it sending a text message. That absence of a decision is itself the risk.
A firm that consciously chose email after weighing the alternatives is in a different position than a firm that simply never considered anything else. The first firm can at least defend the choice. The second one has a real gap in its WISP. IRS Publication 4557 and the FTC Safeguards Rule both expect a firm to actually evaluate how client data moves, rather than default to whatever’s already open.
What TLS actually protects, and where it stops
Most email encryption in practice is opportunistic TLS. The sending and receiving mail servers negotiate encryption for that specific connection, and if the receiving server doesn’t support it, the message falls back to sending unencrypted. That fallback happens silently, with no alert to the sender or the recipient.

Even when TLS does apply, it only covers the message while it travels between mail servers. The protection ends the moment the message reaches its destination. From there, the email sits in an inbox exactly like any other message, typically without encryption, for however long anyone leaves it there. A message also gets copied multiple times as it passes through different mail servers along the way. There’s no guarantee those intermediate copies get deleted on any predictable timeline.
| What TLS covers | What it doesn’t cover |
|---|---|
| The connection between two mail servers, when both support encryption | What happens if either server doesn’t support it, since the fallback is silent |
| The message while it’s actively in transit | The message once it’s sitting in an inbox, sent folder, or backup |
| A single hop between servers | Every intermediate copy created as the message moves through the system |
The bigger risk sits after the email arrives
Interception in transit gets most of the attention, but account compromise is the more common way client tax data in email actually gets exposed. A weak password, a successful phishing attempt, or a missing second factor hands over everything already sitting in that inbox at once.
An attacker who gets into an email account doesn’t need to intercept anything new. Years of past attachments, sent copies, and forwarded threads are often just sitting there already, unencrypted, waiting. That’s a fundamentally different exposure than a single message getting intercepted mid-transit. It’s the scenario a firm’s actual email habits create every time a client’s return gets sent as an attachment. A system built to limit how long a document stays reachable closes that specific gap.
What a secure portal does differently
A secure client portal solves the specific problem email creates: a document that persists indefinitely, unencrypted, with no record of who accessed it. A portal logs access, can expire a link after a set period, and doesn’t leave a permanent unencrypted copy scattered across inboxes and backups.

That’s a difference in design, going well beyond marketing language. An email attachment is a copy the recipient now owns, sitting wherever their inbox happens to live. A portal keeps the document in one controlled location and grants temporary, logged access to it instead. Verito hosts TaxDome as a client portal and document management platform at no additional cost on any hosting plan. That gives a firm somewhere real to put this, instead of falling back to whatever’s already open.
Talk to us about moving client documents off email →