Fax Encryption: TLS, AES-256 & How to Verify Your Provider

Not all fax services encrypt your documents the same way. Learn how TLS and AES-256 protect faxes in transit and at rest — and how to verify your provider's security before sending sensitive data.

Fax Encryption: TLS, AES-256 & How to Verify Your Provider

By Alexey Spasskiy · Published August 24, 2025 · Updated June 8, 2026 · 6 min read

Quick Answer: Fax encryption protects your documents with TLS (in transit) and AES-256 (at rest). Traditional fax machines have zero encryption — only online fax services add these safeguards.


Fax encryption is the process of scrambling fax data so only the intended recipient can read it. If you send contracts, medical records, or tax forms by fax, encryption is what stands between your sensitive information and anyone trying to intercept it.

The problem: not every fax service encrypts your documents the same way — and traditional fax machines don't encrypt them at all. This guide explains the two encryption layers that matter, how they work, and gives you a practical checklist to verify your provider's security.

Two Layers of Encryption

A properly secured fax service uses two separate encryption layers: one protects data while it's moving (TLS), and another protects data while it's stored (AES-256). Both are required for true security.

What Is Fax Encryption?

Fax encryption converts your document into unreadable ciphertext before it leaves your device. Only the recipient's system — which holds the matching decryption key — can convert it back into a readable fax.

There are two stages where encryption matters:

StageWhat's ProtectedEncryption Standard
In transitData moving between your device and the fax serverTLS 1.2 or TLS 1.3
At restData stored on the provider's serversAES-256

Without both layers, your fax is vulnerable at some point in the delivery chain. A service that encrypts in transit but stores documents in plaintext still exposes your data if the server is breached.


How TLS Protects Faxes in Transit

TLS (Transport Layer Security) creates an encrypted tunnel between your device and the fax service's server. Every byte of data that passes through this tunnel is scrambled — including the fax content, recipient number, and metadata.

Here's what happens when you send a fax through a TLS-secured service:

  1. Handshake — your device and the server agree on an encryption method and exchange keys
  2. Encryption — the fax data is encrypted before it leaves your device
  3. Transmission — encrypted data travels over the internet
  4. Decryption — the server decrypts the data using the agreed-upon key

TLS Versions: What to Accept and What to Reject

Not all TLS versions are created equal. Older versions have known vulnerabilities.

ProtocolStatusShould You Use It?
SSL 2.0 / 3.0DeprecatedNo — has critical vulnerabilities
TLS 1.0DeprecatedNo — vulnerable to POODLE and BEAST attacks
TLS 1.1DeprecatedNo — no longer considered secure
TLS 1.2CurrentYes — minimum acceptable standard
TLS 1.3CurrentYes — fastest and most secure option

Watch for 'SSL Encryption' Claims

If a fax service advertises "SSL encryption" in 2026, that's a red flag. SSL was deprecated years ago. The service may actually use TLS (many providers use "SSL" as a generic term), but you should verify the exact protocol version.


How AES-256 Protects Faxes at Rest

AES-256 (Advanced Encryption Standard, 256-bit key) protects your fax documents while they're stored on the provider's servers. It's the same encryption standard used by banks, government agencies, and military organizations.

Why 256-bit? The key is so long that brute-forcing it would take longer than the age of the universe with current computing technology. AES-256 has 2²⁵⁶ possible key combinations — roughly 1.16 × 10⁷⁷.

What "At Rest" Means for Faxing

When you send or receive a fax through an online service, the document is temporarily stored on the provider's servers. "At rest" encryption means that even if someone gains unauthorized access to the server's storage, the fax files are unreadable without the decryption key.

This matters because:

  • Server breaches happen — even large companies get hacked
  • Compliance requires it — HIPAA fax requirements mandate encryption of stored PHI
  • Insider threats exist — encryption prevents unauthorized employees from reading stored faxes

Are Traditional Fax Machines Encrypted?

No. Traditional fax machines transmit data as analog audio signals over the Public Switched Telephone Network (PSTN). There is no encryption at any stage.

FeatureTraditional FaxOnline Fax Service
In-transit encryptionNone (analog signal)TLS 1.2+
At-rest encryptionN/A (paper output)AES-256
Interception riskPhone line tappingVery low with TLS
Audit trailConfirmation page onlyFull digital logs
Physical security riskHigh (paper on tray)None

Traditional faxing over PSTN is sometimes called "secure by obscurity" — it's harder to intercept than email because you'd need physical access to the phone line, but it's not truly encrypted. For anyone handling sensitive data, this distinction matters.

For a deeper dive into online fax security, read our guide: Is Online Fax Secure? The Truth About Encryption & HIPAA.


How to Verify Your Fax Provider's Encryption

Don't take "we use encryption" at face value. Use this checklist to verify what your provider actually does.

  • ✓TLS version: Confirm TLS 1.2 or higher. Ask specifically — "TLS" without a version number is not enough.
  • ✓At-rest encryption: Verify AES-256 or equivalent for stored documents.
  • ✓Enforced encryption: Check that TLS is enforced by default, not optional. Some services only encrypt if the recipient also supports TLS.
  • ✓BAA availability: If you handle PHI, the provider must sign a Business Associate Agreement. No BAA = not HIPAA compliant. See our HIPAA compliant fax guide.
  • ✓Compliance certifications: Look for SOC 2 Type II, ISO 27001, or HITRUST. These prove the encryption claims have been independently audited.
  • ✓Data retention policy: How long are faxes stored? Can you set auto-deletion? The less time data sits on a server, the smaller the breach window.
  • ✓Audit logs: Does the service log who sent what, when, and to whom? Audit trails are essential for HIPAA compliance.

Quick Test

Open your fax provider's web portal and check the URL bar. You should see https:// (not http://). Right-click → "View Certificate" to confirm TLS 1.2 or 1.3. If the certificate shows TLS 1.0 or SSL, switch providers.


Why Encryption Matters Beyond HIPAA

Fax encryption isn't just a healthcare requirement. Any business that faxes sensitive information benefits from encrypted transmission:

  • Legal firms — attorney-client privileged documents
  • Financial services — loan applications, tax returns, bank statements
  • Real estate — contracts, title documents, SSNs on applications
  • Insurance — claims, medical reports, policy documents
  • Government — tax filings, permits, identification documents

Even if your industry doesn't have a specific encryption mandate, sending sensitive data over an unencrypted channel is a liability risk. If a breach occurs and you used an unencrypted fax service, you may face negligence claims.

For healthcare-specific guidance, see our HIPAA fax requirements checklist.


Choosing an Encrypted Fax Service

When evaluating fax services for security, focus on these encryption-related features:

FeatureMinimum StandardBest Practice
In-transit encryptionTLS 1.2TLS 1.3
At-rest encryptionAES-128AES-256
Key managementProvider-managedCustomer-managed keys (BYOK)
Data residencyAny regionYour country/region
Auto-deleteManual deletionConfigurable auto-purge
Compliance auditSelf-assessedSOC 2 Type II certified

For a side-by-side comparison of secure fax providers, see our review of the best HIPAA-compliant fax services.


Send Encrypted Faxes with mFax

mFax encrypts every fax with TLS in transit and AES-256 at rest — no extra configuration needed. Upload your document, enter the fax number, and send. Your data is protected from the moment it leaves your device.

For business teams, mFax Business adds HIPAA compliance features, a signed BAA, virtual fax numbers, and audit logging — starting at about $9/mo (billed annually). There are no rigid fixed tiers: you build your own plan by setting the exact number of seats and pages you need with a live calculator, and pay only for what you use.

Frequently Asked Questions

Are traditional faxes encrypted?
No. Traditional fax machines send data as unencrypted analog signals over the public telephone network (PSTN). Anyone with access to the phone line can intercept the transmission. Only online fax services add encryption.
What encryption should a HIPAA-compliant fax service use?
HIPAA requires TLS 1.2 or higher for data in transit and AES-256 (or equivalent) for data at rest. See our [HIPAA fax requirements checklist](/blog/hipaa-fax-requirements/) for the full list of safeguards.
Is faxing more secure than email?
It depends on the setup. A properly encrypted online fax service with TLS 1.2+ and AES-256 is comparable to encrypted email. Traditional fax over PSTN is harder to intercept remotely but has no encryption. Read our [fax vs. email comparison](/blog/fax-vs-email/) for a detailed breakdown.
How do I send an encrypted fax?
Use an online fax service that supports TLS 1.2+ encryption. Upload your document, enter the recipient's fax number, and send. The service encrypts the transmission automatically — no extra steps required.
What is the difference between TLS and SSL for faxing?
SSL is the predecessor of TLS and is now considered insecure. TLS 1.2 and TLS 1.3 replaced SSL with stronger encryption algorithms and better handshake protocols. Any fax service still advertising "SSL encryption" may be using outdated security.
Home Business Pricing Fax API Blog Document Converter Company
Terms of Service Privacy Policy