Resources 5 min read

Email-to-Fax Security Considerations

Email-to-fax joins two systems with different assumptions. The security of the result is not a property of either one on its own, and most of what determines it sits in the mail platform rather than in the fax service.

A support specialist wearing a headset smiles at her screen at a multi monitor desk in a blue lit office.

Email-to-fax joins two systems that were designed under different assumptions, and the security of the result is not a property of either one alone. Most of what determines it sits in the mail platform, which is the part people examine least, because the fax service is the thing being bought.

Where the boundary actually is

Draw the path and the division becomes obvious. From the person to the mail platform, and from the mail platform to the service, is email's territory. From the service to the destination is the fax service's. What arrives at the far end, and what happens to it there, is nobody's but the recipient's.

A supplier can describe the middle leg precisely. It can say very little about the first, and nothing at all about the last. Any assessment that examines only the middle is examining the shortest part of the path.

What the mail platform contributes

  • Who can send. Authorization becomes an entitlement of a mailbox. Whatever governs mailbox access now governs fax sending.
  • What happens to the attachment on the way. Mail platforms scan, archive, journal and retain. A document faxed from email may exist in more places afterwards than the sender expects.
  • The sent folder. A copy of every document sent, in a mailbox, for as long as that mailbox retains it. This is frequently the longest-lived copy in the whole arrangement, and it is rarely the one anybody thinks about.
  • Forwarding and delegation. Rules set for convenience can move documents somewhere nobody assessed.

What the service contributes

Transport protection to and from the service, the conversion, the transmission itself, the retry behavior, and the record of what happened. Those are describable, contractible and testable, and they are the part a provider can be held to.

The two properties worth asking about specifically are retention and reporting. How long does the service hold the document and the record, is that configurable, and can you export the record. Retention that is longer than your obligations is as much a problem as retention that is shorter.

The failure that no control addresses

A number typed wrongly produces a perfectly successful transmission to the wrong recipient. Encryption does not help. Authentication does not help. The confirmation will be positive, because a machine did answer and did accept the pages.

This is the dominant real-world failure mode for fax of any kind, and the only controls that touch it are workflow controls: where numbers come from, whether they are validated against a source rather than retyped, and whether high-sensitivity destinations are constrained to a maintained list rather than free text.

Assessing the arrangement as a whole

The useful frame is that the security of email-to-fax depends on the implementation, and the implementation has more parts than the purchase does. The ones that determine the outcome are ordinary and none of them is exotic.

  • Email security, including how the mail platform authenticates and what it does with attachments.
  • Identity and access controls, and how they are maintained when people change roles or leave.
  • Service configuration, including retention and who can administer it.
  • Document handling at both ends, particularly where received documents land.
  • Encryption where it applies, and knowing where it stops applying.
  • Audit and logging, and whether anyone reads the result.
  • Retention requirements, which are usually set outside IT.
  • Endpoint security, because a document that arrives in a mailbox arrives on a device.
  • Organizational policy, which is what makes the other eight enforceable.

Where documents fall under a specific rule, the obligation stays with the organization holding them. Our page on electronic fax and HIPAA compliance works through what that means for one of them, and the general threat discussion is in electronic fax security and risk.

What to ask before relying on it

  • What is the retention on the sent folder, and is that the answer you want?
  • Who can send, how is that list maintained, and what removes someone?
  • Is the destination number ever transcribed by hand, and from what?
  • What does the service retain, for how long, and can you export it?
  • Where do received documents land, and who else can read that location?

Two things that are commonly assumed and are not true

The first is that encryption in transit settles the question. It protects the document between defined points. It says nothing about who was entitled to send it, whether the destination was right, who can read it on arrival, or how long copies persist at either end. It is necessary and it is not sufficient, and treating it as sufficient is how an assessment ends up examining the shortest leg of the path.

The second is that fax is inherently more private than email because it is older and point to point. A fax arrives on a shared device in a shared room, and stays there until somebody collects it. Whether that is better or worse than a mailbox depends entirely on the room and the mailbox, which is to say it depends on the implementation rather than on the technology.

Where to go next

For the mechanics this discussion sits on, see how email-to-fax works. For what LABUSA provides on this path, the feature overview, or tell us what you are working with.

Who owns this assessment

In most organizations the fax service is bought by one team and the mail platform is run by another, and the arrangement above spans both. That division is the reason these questions go unasked rather than unanswered: each side can reasonably say the other part is not theirs.

The practical remedy is to name one owner for the path rather than for the products. Somebody has to be able to describe what happens to a document from the moment it is attached to the moment it is disposed of, and that description is the assessment.

Sources

  • 45 CFR 164.312, Technical safeguards, Government Publishing Office. Audit controls, transmission security, and the required or addressable marking on each specification.
  • NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations. The access control and Audit and Accountability families.

About LABUSA

LABUSA is a managed service provider that enables organizations to build a robust digital business model. We provide managed services through an open hybrid cloud strategy integrating public, private, and on-premises computing systems with intelligent edge devices. The company is ISO 9001:2015 certified, and our solution enhances the efficiency, security, reliability, and cost-effectiveness of the information technology environment.

For more Information Contact LABUSA at

+1-281-393-8003