Partly. The document you upload to an online fax service travels to the provider over an encrypted browser connection. PayPerFax and other reputable providers keep it encrypted at rest on their servers. The part that is not encrypted is the final leg: the phone-line transmission from the provider to the receiving fax machine. No fax service can encrypt that leg, and the reason is a property of the fax protocol, not of the phone network.
The rest of this page explains what that means in practice: what is encrypted, what is not, why the last leg cannot be, and what that changes for the reader.
Where an online fax is encrypted
For a fax handled by PayPerFax, three stages sit under our control before the final phone-line leg, and each one is encrypted.
First, the upload. Your browser sends the document to our servers over TLS, the same transport encryption a bank login uses. That protects the upload from anyone sitting between you and us on the network.
Then, storage. Once the file lands on our systems, it is stored encrypted with AES-256 by default, using keys managed by our storage provider. This covers the document itself, the preview we generate, and the transmitted fax image.
Between systems, traffic that flows from us to the services that process data on our behalf is encrypted in transit as well.
The authoritative version of all three claims lives in the PayPerFax Security Statement. This page is the plain-English summary; the Security Statement is the record.
The one part that is not encrypted
The final leg is the phone-line transmission from the fax carrier we hand your document to, out to the receiving fax machine, and it is not encrypted. That has one specific cause and it is worth being precise about, because most explanations get it slightly wrong.
The fax protocols in use worldwide (ITU-T Group 3 for standard fax, Group 4 for ISDN fax) do not negotiate encryption between the sending and receiving endpoints. Standard fax machines do not add any encryption of their own. So the image travels across the phone network unencrypted. Not because the phone network refuses to carry encrypted content, but because the fax protocol never learned to speak encryption, and the receiving fax machine has no way to decrypt it if it did. That is the same for a fax sent from any physical machine or through any online service. It is a property of fax as a medium, not of any one provider, and no fax service can change it.
What “encrypted fax” claims from other services usually mean
If you have seen a competitor advertise “end-to-end encrypted fax” and wondered whether we are behind, the honest answer is no. Those claims almost always cover one of three specific things, and none of them is what most senders think they are.
The most common is fax-to-email with TLS. Some providers route incoming faxes to a recipient’s email inbox rather than a receiving machine. When both mailboxes support modern TLS (Gmail, Outlook, Fastmail, and similar do by default), the delivery leg is encrypted in transit. That is real, and it is useful. It is not the same as the sender’s fax being end-to-end encrypted; it is a different delivery model that avoids the phone-line leg entirely.
The second is fax-over-VoIP inside one provider’s network. If both the sender and the receiver are on the same VoIP-fax carrier, the carrier can encrypt the leg between them, because it controls both endpoints. As soon as the fax needs to leave that carrier to reach a standard fax number, the encryption ends and the ordinary unencrypted phone-line leg takes over.
The third is end-to-end encrypted fax between arbitrary fax numbers. This is not possible with standard fax equipment. The receiving endpoint has no way to negotiate keys with the sender. Any claim of end-to-end encryption over the public phone network is a marketing shorthand for one of the two situations above, or for something narrower still.
None of this makes online fax unsafe. It means the honest picture is more specific than “encrypted” or “unencrypted” as a single label.
When this actually matters
For most senders, the unencrypted final leg is a smaller risk than it sounds. Tapping a phone line to intercept one fax requires physical access to the line, knowledge of which line to tap, and timing. Compared to the automated attacks that hit email at scale, it is a rare threat model.
For a narrower set of workflows, “encrypted end to end” is not the standard the sender needs to meet. What matters is a specific compliance regime, and each one has its own requirements.
If you are sending anything covered by HIPAA (patient records, insurance authorizations, medical test results), the requirement is a fax service with a signed Business Associate Agreement, a covered inbound number, and an audit trail. That is not what PayPerFax is built for, and we say so plainly: for HIPAA-covered fax you should use a service that carries a BAA. See our HIPAA-compliant fax explainer for what a covered service actually looks like, and our fax comparison list for services that do.
If you are sending a legal document under a court’s sealed-filing rules, follow the court’s fax instructions, which sometimes require a specific covered service.
For everything else – the one-off contract, the payment authorization, the utility bill, the signed document a lender wants by morning – the practical security question is not whether the phone-line leg is encrypted. It is whether the service holding your document is a service you trust with it, and for how long.
What PayPerFax’s design protects, and what it does not
The way PayPerFax is built has direct consequences for that trust question, and they are worth naming.
There is no account. No username, no password, no dashboard, so there is nothing to phish and nothing to breach months later. You are not creating a permanent record of your interaction with us. There is no stored history to manage either: documents are retained only long enough to complete the send, and the transactional record for billing and tax purposes is what remains, not the document.
The parts we can encrypt, we do encrypt. TLS on upload, AES-256 at rest, encrypted internal traffic, and only a small number of administrators can see document contents, for specific operational reasons defined in the Security Statement.
The phone-line leg is unencrypted, like every fax provider on standard fax numbers. There is no provider you can pay to make that leg encrypted, so the honest comparison is what happens to your document before and after that leg, not the leg itself.
For related questions: is fax more secure than email? covers the direct comparison. Is it secure to use an online fax service provider? covers the provider-trust question in general. Is PayPerFax safe? covers the specific-service version of the same question.
The one-line answer, again
Is online fax encrypted? The upload is encrypted, the storage is encrypted, and the phone-line leg to the receiving fax machine is not. No provider can encrypt that final leg, so the practical question for most senders is who they trust with the document before and after that leg. If your document requires a specific compliance regime, pick a service built for that regime. If it is confidential but not regulated, the shape of the service you use matters more than the label “encrypted.”
Last reviewed/updated: July 30, 2026
