Skip to content

Preparing a scanned document to send

A scan that has to go to somebody else rarely needs one thing done to it. It needs to be readable, it needs the parts that should not travel taken out, it usually needs signing, and it should not arrive carrying the name of whoever scanned it. The order those happen in matters more than people expect.

First, make it readable

A scan is a photograph of paper: you can read it, and your computer cannot. Nothing that follows works properly until that is fixed. Redaction cannot find words it cannot see, and the recipient cannot search a document that contains no text.

Recognition adds an invisible text layer over the picture of each word. The page still looks exactly as it did — signatures, stamps and letterhead intact — and the document becomes searchable.

Then take out what should not travel

Do this before signing rather than after. A signature is a statement about the document as it stands; removing content afterwards means you signed something other than what you sent.

Remove pages that are not relevant, and redact the content within the pages that are. Both are worth doing: the strongest protection for a page is that it was never sent.

Then sign, and decide about the form fields

If the document is a form you have filled in, decide whether the recipient should be able to edit your answers. Leaving it fillable is right when they may need to correct something; flattening is right when the answers are final and you would rather they arrived as they left.

Flattening is one-way. Once the values are page content, they cannot be edited back into fields.

Strip the metadata last

Every step so far rewrites the document, and rewriting stamps fresh properties on it. Strip the metadata at the end and it stays stripped; strip it in the middle and the steps after it put a producer and a timestamp straight back.

This is the step most often skipped, and it is the one that quietly carries the author's name, the original filename and the software they used to whoever receives the file.

Protect it, if it needs protecting — and only at the very end

An encrypted document cannot be edited without being decrypted first, so anything you want to do to it has to happen before this point.

Two honest caveats. The strength of the result is the strength of the password you choose, and permissions such as 'do not print' are requests the reader's software may honour rather than locks the file enforces.

Doing the whole thing in one pass

Done by hand, this sequence means five tools and five rounds of downloading and re-uploading a document you would rather not have lying around in a downloads folder.

The same steps can be arranged as a single workflow and run once, with the document passing from step to step inside the browser tab and one file at the end. The ordering rules above are enforced there too: merge can only come first, protect can only come last.

Last, check it the way the recipient could

Every step above can appear to have worked and not have worked, so the final job is to inspect the file you are about to send rather than the one you remember making.

Open the finished PDF, select all, copy, and paste into a plain text editor. Anything you redacted that appears in that paste is still in the document. This takes ten seconds and it is exactly what anybody receiving the file could do.

Then check what the file says about you rather than about its subject. A scan carries the device that produced it and often the software; a document assembled from several sources can carry the author name of each. None of that appears on the page and all of it travels with the file.

Finally, consider whether the whole document needs to go at all. Three pages of a contract at readable quality is a better thing to send than forty — smaller, faster to read, and the thirty-seven you kept back were never disclosed.