Security
Is It Safe to Send Passwords Over Email or Slack?
No. Email and Slack were built for conversation, not secrets. A password sent in either sits in message history you don't control, where it can be exported, searched, or forwarded. Use an encrypted expiring link or a password manager instead.
No. Email and Slack were built for conversation, not secrets. A password sent in either lands in message history you don't control. Email lingers in sent folders and backups with no expiry, and Slack stores messages, including direct messages, on its servers, where workspace admins can export and read them and connected apps can reach them. If you have to move a credential, use an encrypted, expiring link or a password manager, not a message.
Why email leaks passwords
Email isn't encrypted end to end. A message passes through servers along the way, and it stays in the sender's sent folder, the recipient's inbox, and both providers' backups. There's no expiry, no record of who opened it, and no way to pull it back. One mistyped address is enough to send a login to the wrong person.
Why Slack is not private for secrets
Slack feels internal, so it feels safe. It isn't, for credentials. Messages are retained on Slack's servers, around 90 days on free plans and indefinitely on paid ones. On paid tiers a workspace admin can run a Compliance Export that includes private DMs, so a secret you sent one person is readable by others. Connected third-party apps can also reach message content. And in any group thread, you can't tell who viewed or forwarded a password, or revoke it from one person without changing it for everyone.
How the channels compare
| Channel | Encrypted for the recipient? | Lives in history you don't control? | Can you revoke it? |
|---|---|---|---|
| No | Yes | No | |
| Slack / chat | No | Yes | No |
| Password manager sharing | Yes | No | Yes |
| Encrypted one-time link | Yes | No | Yes |
What to do instead
- Don't paste a password into email, Slack, WhatsApp, or a shared document.
- If it's a login you can avoid sharing, grant access instead, for example by adding the person as a user.
- If you must send it, use a one-time or expiring encrypted link, and send any passcode on a separate channel.
- For secrets the team reuses, use a password manager with proper sharing.
- If a password already went out over email or Slack, rotate it.
Where doconvoy fits
When your team needs to collect a credential from a client, or hand one to a teammate or contractor, doconvoy replaces the Slack or email message with an encrypted request or an expiring one-time link. The secret is encrypted before it leaves the sender's browser and never sits in chat history. For a team's standing internal logins, pair it with a password manager.
Send credentials through encrypted, expiring links instead of Slack or email.
Share secrets without the chat logRelated: How to ask clients for passwords securely · Sharing client credentials across an agency team · Secure Sharing · For remote teams
Common questions
Is Slack secure enough for passwords?
No. Slack stores messages, including direct messages, on its servers, roughly 90 days on free plans and indefinitely on paid ones. Workspace admins on paid tiers can export and read those messages, and connected third-party apps can reach them. A password posted in Slack is not private.
Can workspace admins read my Slack DMs?
On paid Slack plans, admins can run a Compliance Export that includes private direct messages. So a credential you send in a DM is readable beyond the person you sent it to.
What should I do if I already sent a password over email or Slack?
Treat it as exposed and rotate it. Change the password, and where possible check access logs for unexpected use.
What's the safe alternative?
Send the credential through an encrypted link that expires, or a password manager's secure sharing, so it never lives in a message. Send any passcode on a separate channel.