Black Friday Our biggest deal of the year is coming soon Get notified →

Self-Destructing Secure Messages

Updated 4 Oct 2026 4 min read

A secure message lets you send sensitive text to anyone, even if they don't use PrMail. It's encrypted in your browser before it's sent. The recipient gets a link, enters a password you give them separately, and the message is destroyed after it's been viewed. This guide shows how to send one and what to expect.

How it works

  • The message text isn't sent as a normal email. Your browser encrypts it before it leaves your device, and we store only the scrambled text.
  • The recipient gets an email from your PrMail address with an Open secure message button. The link contains a key after #k=. The key is part of the link: it passes through our server once, to build the email, and we never store it.
  • They open the link and enter the access password you gave them. The message is decrypted in their browser.
  • Once the message has been viewed the number of times you allowed, it's deleted. It's also deleted once the time limit you chose has passed, whether or not it has been read.

Send a secure message

  1. In PrMail, click Secure message under the Compose button.
  2. Enter the recipient's email address in To. Secure messages go to one recipient at a time.
  3. Enter a subject in Subject. Keep it vague: the subject is not encrypted and appears in the notification email as "Secure message: (your subject)".
  4. Type your message. Secure messages are plain text, up to 40,000 characters.
  5. Under Security settings, check the Access password. A strong passphrase is suggested for you. Use the copy button to copy it, or the dice button (Suggest a new password) to get a different one. You can type your own instead: at least 8 characters, and longer is safer.
  6. Choose Max views: 1 view (recommended), 2, 3 or 5.
  7. Choose Auto-destroy after: 1 hour, 6 hours, 24 hours (default), 48 hours or 7 days. Seven days is the longest a message can last.
  8. Click Encrypt and send.
Never put the access password in an email. Give it to the recipient another way: a text message, a phone call or in person. Anyone who has both the full link and the password can read the message.

After you send it, the Secure messages page confirms who it was sent to. It also shows the full link once, in that browser tab, so if the email doesn't arrive you can click Copy link and send it yourself. We don't keep a copy of the link, so it can't be shown again later.

What the recipient sees

The notification email says who sent it, how many times it can be opened and when it will be deleted, and reminds them they'll need a password that isn't in the email. When they open the link, they see your PrMail address, the views left and when it will be deleted, and a box for the Access password. After they click Open message, the message is shown with a Copy text button. If that was the last allowed view, the page says so and confirms the message has been deleted.

The link only works in full. If they copy it by hand, they need everything after the # sign too. Otherwise the page says the link is incomplete.

A view only counts when the right password is entered, so link scanners and wrong passwords don't use up views. Wrong passwords are limited: after 10 wrong tries in 15 minutes from the same connection, or 60 on one message in a day, the page says Too many attempts and asks them to wait before trying again.

If the link is opened after the time limit, it says the message has expired. After the last view, or if you destroyed it, it says the message is no longer available. The content can't be recovered.

Track and destroy messages you've sent

Click Secure messages under Privacy tools in the PrMail panel to see your 20 most recent secure messages. Each one shows its status:

  • Waiting: it hasn't been opened yet and can still be viewed. You'll also see the views used, for example 0/1.
  • Opened: it has been opened. If it still has views left, you'll see how many it has had, for example 1/2. Once it has been read the number of times you allowed, it's deleted.
  • Expired: the time limit passed and it was deleted unread.
  • Destroyed: you deleted it.

To stop a message being read, click Destroy next to it and confirm. The link stops working straight away.

About the encryption

The message is encrypted with AES-256-GCM in your browser. The key is made from two parts: a random key that goes in the link after #k=, and your access password. We store only the encrypted text and a value that lets us check the recipient has both parts. We never store or log the link key or the password, so neither our database nor the emailed link on its own can open a message. The link key passes through our server once, when we build the notification email.

The access password is what protects the message if the link is seen by someone else, so use the suggested passphrase or another long, unique one, especially for anything that stays readable for days.

Something out of date or unclear? Let us know.

Stay Ahead of Online Threats

Get VPN tips, security insights, and exclusive offers delivered straight to your inbox. No spam — just the essentials.

Unsubscribe at any time. We respect your privacy.

PremierVPN Support