Don't Email Me Your Password!

When clients need to share website access, hosting credentials, or admin logins with us, the most common instinct is to fire off an email. It’s fast, familiar, and feels harmless enough.

But here’s the thing: please don’t email your password to us — or to anyone, for that matter.

Why Email Is Risky

Think of a password emailed as plain text like writing it on a postcard and dropping it in the mailbox for everyone to see. Email messages can be intercepted in transit, accessed by others if your inbox is compromised, or accidentally forwarded to the wrong person.

Passwords are the keys to your online kingdom. They protect your website, your hosting account, your client data, and your business reputation. Treating them casually creates real vulnerabilities.

A Safer Alternative: Password Managers

Password management tools like 1Password, Bitwarden, or LastPass encrypt and store credentials in a secure vault. Many of them allow you to share access with team members or service providers without ever revealing the underlying password.

These tools are inexpensive (or free for basic use) and make strong, unique passwords easy to manage across dozens of accounts.

The No-No List

While we’re here, avoid these common security pitfalls:

  1. Don’t send passwords via email — use a password manager or secure sharing tool
  2. Don’t use weak passwords — “123456” and “password” are among the most commonly compromised credentials
  3. Don’t reuse the same password across accounts — one breach can compromise everything
  4. Don’t write passwords on sticky notes — physical exposure is just as risky as digital

The Better Approach for WordPress

WordPress has a built-in solution that many people overlook: user roles. Rather than sharing your admin password, you can create a separate user account for your web designer or developer with the appropriate access level — Administrator, Editor, Author, or Subscriber.

This means we can access your website without ever knowing your personal credentials. When the work is done, the account can be updated or removed entirely.

If we need access to your website or hosting, we’ll send you instructions on how to create a separate access for us — please don’t email your main login credentials.

Need help setting up secure access to your WordPress site? Get in touch with the Blue Platypus team — we’re happy to walk you through it.

Frequently Asked Questions

Why is emailing a password risky?

Email is stored in plain text in multiple places — your sent folder, their inbox, both mail servers and any backups. A password sent by email stays retrievable long after the conversation, and anyone who later gains access to either mailbox has it.

What should I use instead?

A password manager with sharing built in, such as 1Password or Bitwarden. The recipient gets access without the password travelling through email, and you can revoke it later.

What if I have already emailed passwords?

Change those passwords, then delete the emails from both sent and received folders. Assume anything emailed previously is compromised, particularly if the account has been accessed from a shared or old device.

How should I give a web developer access to my site?

Create a separate user account for them with the access level the work requires, rather than sharing your own login. When the work finishes you delete that account, and your own credentials were never exposed.