How to Send a Copy of Your Passport or ID Safely: Watermark, Encrypt, Stay Local
Banks, landlords, employers, and visa services routinely ask for a scan of your passport or ID card, and refusing is rarely an option. The risk is not the legitimate request itself but what happens to the copy afterwards. An unmarked, high-resolution ID image is a reusable asset: if it leaks from an inbox or a poorly secured database, it can be resubmitted elsewhere to open accounts, pass identity checks, or register services in your name. The goal, therefore, is not to avoid sharing your ID but to make each copy useless anywhere except its intended destination.
The classic and remarkably effective defense is a visible watermark stating the purpose and date, for example 'For ACME Bank account opening only, 2026-06-27'. A fraudster who resubmits that image to a different service is presenting evidence of misuse on its face, and many automated checks reject visibly restricted copies. With PdfWill's watermark tool, place the text diagonally across the document, overlapping the photo and data fields, at an opacity around forty to fifty percent: strong enough to survive casual cropping or brightness tricks, light enough that the details remain legible for the legitimate reviewer.
Where you create that watermark matters as much as the watermark itself. Uploading an ID scan to a random online editor just to stamp it defeats the purpose, since you have now handed a pristine copy to yet another server you know nothing about. PdfWill runs entirely in your browser: the ID image, the watermarked version, and everything in between stay in your device's memory and never touch a server. Convert the photo with Image to PDF, apply the watermark, and the only copies in existence remain the ones on your own machine.
Next, protect the file for transit. Email passes through servers you do not control, so encrypt the watermarked PDF with the protect tool, which applies AES-256 encryption locally. Send the password through a different channel, such as a text message or phone call, never in the same email as the attachment. If the request only concerns your identity page, share only that page. And when a form exposes more than required, for instance a bank statement used as address proof, use the redact tool to permanently remove account numbers and balances the recipient does not need.
Finally, build small hygiene habits around every ID share. Keep a simple note of who received a copy, when, and for what purpose, so a future leak can be traced. Delete stray copies from your downloads folder and sent-mail drafts once the transaction concludes. If an organization insists on an unwatermarked copy, ask why and ask how they store it; legitimate verifiers usually accept purpose-marked documents. None of these steps takes more than a minute, and together they convert your most sensitive everyday document from a reusable skeleton key into a single-purpose, dated, and encrypted record.