Faxing identity documents is still common with healthcare providers, financial institutions, courts, and government offices. But a quick scan-and-fax can expose more personal information than necessary, from full ID numbers to machine-readable barcodes. This guide shows you how to send ID documents by fax safely, step-by-step: what to redact, how to handle metadata, and how to confirm delivery without leaving an unnecessary paper or digital trail.
Why Faxed IDs Can Be Risky
Faxing feels old-school, but the risks are modern. Photocopiers, scanners, and fax apps often save images to memory or cloud accounts. Barcodes and MRZ (machine-readable zones) can encode your full name, ID number, birth date, address, and more—even if they look like harmless stripes. And recipients sometimes store incoming faxes in shared folders or unprotected inboxes. Minimizing what you send and controlling the copy you keep protects you from downstream exposure.
Decide If Fax Is Necessary—and Clarify Required Fields
Before sending anything, confirm whether a faxed ID is truly required. Ask the recipient:
- Can I verify identity in person or via a secure portal?
- Exactly which fields do you require? (e.g., full name and expiration date only)
- Can I mask the ID number or barcode?
- Do you accept a notarized statement or alternative verification?
Push for a minimal-data option. Many organizations only need a small set of fields to comply with their policy.
What to Redact on an ID
Redaction is the privacy cornerstone when sending IDs. When policy allows, consider masking:
- ID number: Mask all digits or show only the last 2–4 if allowed.
- Barcode/MRZ/magnetic stripe: Fully cover. These often encode full PII.
- Date of birth: Mask full DOB when not required. If they need age, consider month/year only if accepted.
- Address: Redact unless proof of residence is required. If needed, send a utility bill instead.
- Issuing authority and document number variants: Mask unused identifiers to avoid cross-matching.
- Photograph: Keep visible if identity verification is required; otherwise confirm if it can be masked.
When in doubt, ask the recipient to confirm in writing which fields are mandatory. Save that message with your fax confirmation.
How to Redact Properly (Physical and Digital)
Physical Redaction
- Print a clear copy of your ID at 100% scale.
- Use an opaque black marker or removable opaque tape to cover fields. Ensure no edges or shadows reveal data.
- Make a photocopy of the redacted version to confirm bleed-through is not visible.
- Fax the redacted photocopy, not the original ID or a marker-only copy.
Digital Redaction
- Scan or photograph your ID at high resolution (300 dpi is usually enough).
- Use a PDF editor that truly removes content—not just overlays a black box. Look for “redact” tools that delete pixel data beneath the box.
- Flatten or rasterize the document after redaction to prevent layer recovery.
- Export as a PDF or image with redactions burned in. Reopen the export and zoom in to ensure nothing is recoverable.
Avoid “draw a rectangle” alone—overlayed shapes can be removed, revealing sensitive text beneath.
Metadata Hygiene: Remove Hidden Data Before Faxing
Even if you redact visible fields, hidden data can leak through source files or device storage. Clean up:
- File metadata: Remove author, device model, GPS, and timestamps. Many PDF and image tools have “remove metadata” or “sanitize” options.
- Photo EXIF data: If you photographed your ID, strip EXIF (location, camera serial, date/time) before attaching.
- Scanner memory: If using a multi-function printer (MFP), avoid storing scans to email/cloud. Use local scan-to-USB, then clear temporary files and remove the USB safely.
- Fax app accounts: If using a mobile fax app, review its privacy policy, disable cloud backups, and delete sent items after confirmation.
Choose the Safest Fax Method Available
Fax transmission paths vary. Pick the option that reduces exposure and keeps an audit trail you control.
- Direct machine-to-machine fax: Traditional phone-line fax between trusted offices can limit cloud storage. Confirm the recipient’s number by voice before sending.
- Secure fax services with TLS: Some services secure the internet leg and offer restricted inboxes. Use providers that enable two-factor authentication and access logs.
- Avoid email-to-fax with unsecured email: If you must use it, encrypt the email or use the service’s secure upload portal.
- Do not fax from public kiosks where copies can be stored or reprinted later.
Prepare a Minimal, Professional Fax Packet
A clean packet reduces confusion and accidental data sharing within the recipient’s organization.
- Cover sheet: Include sender and recipient names, department, phone, and a short purpose (e.g., “Identity verification for account 12345”). Add a confidentiality notice reminding staff to limit internal distribution.
- Redacted ID pages: Place your redacted ID behind the cover sheet so casual viewers see the cover first.
- Optional supporting docs: Only attach what’s required (e.g., a statement authorizing use for a specific transaction).
Number pages (1 of 3, 2 of 3, etc.) so the recipient can confirm completeness without requesting a resend.
Dialing, Sending, and Transmission Checks
- Verify the number by voice: Call the recipient using a published phone number and read back the fax number.
- Use a descriptive header: If your fax machine allows, set a header with your name and phone number for callbacks—but avoid IDs or account numbers in headers.
- Send during business hours: A live recipient can confirm receipt, reducing unattended exposure in a shared fax tray.
- Retry policy: If transmission fails, confirm the number again before resending. Frequent retries to a wrong number increase exposure.
Secure Confirmation Without Oversharing
A confirmation process should prove delivery without disclosing extra PII.
- Transmission report: Save the machine or service’s confirmation page or PDF. This is your proof of delivery.
- Recipient confirmation: Ask the recipient to confirm the number of pages and the specific required fields visible (e.g., “name and expiration date visible; ID number masked”).
- Avoid email chains with attachments: Request confirmation in a short text-only email or phone call to minimize new data copies.
After Sending: Minimize Your Residual Footprint
- Delete temporary copies: Remove files from scanner memory, fax apps, and cloud sync folders. Empty trash bins.
- Store one clean record: Keep the signed cover sheet and the fax confirmation report in a secure folder or encrypted vault. No need to keep the ID image itself once the action is complete.
- Document the redactions: Note what fields were masked and why. This helps if a future request escalates.
When the Recipient Demands More Than Necessary
If an organization requests full, unredacted IDs without clear justification:
- Ask for their written policy and the regulation requiring the specific fields.
- Offer a live video verification, in-person check, or a notarized copy limited to a single purpose.
- Provide a selective disclosure: show full ID in person or on a secure video call, but submit only the minimal faxed copy to their records.
- Escalate to a supervisor or compliance contact if frontline staff cannot articulate the need.
Special Considerations by Document Type
Driver’s License
- Mask the license number, barcode, and address unless specifically required.
- If proof of age is needed, keep name and photo visible; ask if birth year alone suffices.
Passport
- Mask the MRZ (two lines of characters at the bottom) if not required; it encodes extensive PII.
- If citizenship is the purpose, confirm whether passport card is acceptable with fewer exposed fields.
State ID or National ID
- Treat similarly to driver’s licenses. Watch for 2D barcodes on the back—mask fully.
Social Security Card
- Avoid faxing entirely if possible. If absolutely required, seek a secure portal and transmit only when a policy citation is provided.
Red Flags and How to Respond
- Unverified fax number: Pause, call a published phone number, and verify.
- Requests for full barcode: Ask why. Propose manual field entry instead of barcode scanning.
- Third-party “broker” intake: Ask if you can send directly to the primary organization’s secure line.
- Staff insist on full DOB or address without basis: Request policy citation and escalate.
Privacy and Identity Monitoring After Sharing ID
Any time you share ID information—fax or otherwise—monitor for misuse such as new accounts, unexpected credit pulls, or address changes. If you routinely verify your identity for banks, insurers, or healthcare, a monitoring tool can provide early alerts and help you respond quickly to suspicious activity. For ongoing visibility into credit changes and potential identity misuse, consider a service designed for credit and identity monitoring such as SmartCredit.
Quick Checklist: Safe Faxing in 10 Steps
- Confirm fax is necessary and list required fields in writing.
- Redact nonessential data (ID number, barcode/MRZ, address, DOB as allowed).
- Use true redaction (opaque tape/marker on a photocopy or digital redact tools) and verify.
- Strip metadata and EXIF; avoid cloud backups.
- Choose a secure fax method; avoid public kiosks.
- Prepare a minimal cover sheet and page numbering.
- Verify the fax number by voice from a published source.
- Send during business hours and obtain a transmission report.
- Get recipient confirmation of pages and visible required fields.
- Delete residual copies; keep only the confirmation and cover sheet.
Frequently Asked Questions
Is fax more secure than email?
It depends. Traditional phone-line fax avoids email compromise risks, but many faxes now travel via internet-based systems and land in shared inboxes. Security comes from the entire process: redaction, number verification, limited retention, and responsible recipient handling.
Can I legally redact parts of my ID?
Often yes, as long as required fields remain visible. Confirm what the recipient’s policy demands. If they need to compare face-to-photo, keep the photo visible; if they need proof of age, full DOB may not be necessary.
What if the fax confirmation shows “OK” but they say they didn’t receive it?
Call the recipient, verify the number, and ask where incoming faxes route (front desk, secure inbox, or a different department). Offer to resend to a verified line. Do not send to multiple numbers at once.
Should I keep a copy of my ID on my phone for future faxes?
Prefer a secure, encrypted vault if you must store one. Otherwise, delete images after use to reduce exposure from phone loss or malware.
Conclusion
Faxing an ID can be done safely when you send only what’s necessary, remove hidden data, and verify delivery without creating extra copies. Start by clarifying the exact fields required, apply reliable redaction to visible and machine-readable elements, strip metadata, and choose a secure fax route. Confirm receipt the same day, retain a minimal proof-of-delivery record, and delete the rest. With these steps, you reduce the chance of identity exposure while still meeting documentation requirements.
Good to Know
If a recipient claims they need “the whole ID,” ask exactly which fields are required and cite policy. Many organizations only need name, last four digits, or expiration date—not the full number or barcode.