Short answer: in 2026, there is no universal channel. Fax remains unbeatable when the recipient accepts nothing else and you need an immediate record of transmission; encrypted email (S/MIME, PGP, secure healthcare messaging) wins as soon as both parties are equipped; the secure upload platform is the obvious choice for large files and ongoing exchanges; qualified eIDAS registered electronic mail is the only option that legally matches postal registered mail. The right reflex: choose the channel based on the recipient and the proof required, never on habit.
About MondialFax. This guide is a comparison of channels, independent of any provider. MondialFax sends faxes free of charge and without registration to seven destinations (France, Belgium, Germany, Spain, Italy, Portugal, Canada). It does not assign a number and does not handle reception: the reception scenarios discussed below assume a third-party provider. See receiving a fax and our fax-to-email guide.
The scene plays out every week in practices, law firms and administrative departments. A document has to go out. Someone asks: "how do I send this?" And the answer is almost always the wrong one, because it is a reflex. The accountant says "by email", the lawyer says "by registered mail", the assistant says "by fax, that's what they want". Nobody has asked the three questions that actually decide: who needs to receive it, what proof do you need to keep, and what is in the file.
This article is not trying to bury fax, nor to rehabilitate it. It offers a decision framework, channel by channel, covering what each one guarantees — and above all what it does not.

The three questions that settle the choice of channel
1. Who is receiving?
This is the criterion that overrides all the others. A channel only exists if the other end is equipped. Secure healthcare messaging (MSSanté) is excellent — between professionals listed in the national health directory. It is useless for reaching a private insurer, a foreign court registry or a supplier who never moved on from their fax machine.
In practice, the question comes down to this: does the recipient have an address I can verify, and do they actually use it? A fax number published on a company registration extract, an MSSanté address found in the directory, a platform whose link was sent to you: those are real channels. A personal email address scribbled on a sticky note is not, no matter how strong the encryption.
2. What proof do you need?
Three levels of proof, not to be confused:
- Proof of sending: I can show that I sent something, at a given time, to a given number or address. That is the fax transmission report, or a platform's upload receipt.
- Proof of receipt: I can show that the recipient actually received it. That is the acknowledgement of receipt from registered electronic mail, or a portal's timestamped log.
- Proof of content: I can show that the document transmitted was indeed that one, unmodified. That is the cryptographic hash, the electronic signature.
Fax delivers the first level properly, the second imperfectly (the report attests that a machine answered, not that a human read anything), and the third not at all. We covered this point in detail in our article on the legal value of fax.
3. What is in the file?
A plumbing quote and a histopathology report do not fall under the same regime. The GDPR does not say "encrypt everything": its Article 32 requires measures appropriate to the risk. Health data, judicial data, banking data and identity documents trigger a higher level of requirement. The rest can legitimately travel through simpler channels.
The comparison, channel by channel
| Channel | Proof of sending | Proof of receipt | Confidentiality in transit | Recipient requirement | Indicative cost |
|---|---|---|---|---|---|
| Fax (PSTN or online) | Good (timestamped report) | Partial (machine handshake) | Low to moderate (no end-to-end encryption) | An active fax number | Free to a few cents per page |
| Plain email | Weak (optional read receipt, unreliable) | Weak | Transport encryption only (opportunistic TLS) | An email address | None |
| Encrypted email (S/MIME / PGP) | Weak | Weak | High (end-to-end) | Recipient's certificate or public key | Certificate ≈ €20–80/year |
| MSSanté | Good | Good | High (closed ecosystem, HDS-approved) | Professional listed in the health directory | Often included |
| Secure upload platform | Good (upload log) | Good (download log) | High | Account or invitation link | €0 to €20/month |
| Registered electronic mail (eIDAS RM) | Excellent | Excellent (equivalent to postal AR) | High | Email address + recipient's consent | €3–6 per item |
The table reads diagonally: the further down you go, the stronger the proof and the greater the constraints on the recipient. Fax occupies a singular position — mediocre proof, mediocre confidentiality, but almost no constraint on the recipient. That is exactly what explains its survival.
Why fax still hasn't disappeared
The classic argument is "professional conservatism". It is only partly true. What keeps fax alive is an interoperability problem nobody has solved.
A fax machine talks to any other fax machine, in any country, with no shared directory, no account, no prior key exchange. No encrypted email system can claim as much: S/MIME assumes you hold the recipient's certificate, PGP that they have shared their public key with you. As soon as the exchange is one-off and unplanned — a Belgian notary who needs to reach an Italian civil registry office, a pharmacy contacting a laboratory abroad — setting up encryption costs more than the transmission itself.
Add the French technical context: Orange stopped selling new PSTN lines in November 2018, and the technical shutdown by geographic area has been under way since 2023 under Arcep supervision. Analogue fax machines are therefore migrating to VoIP, with the T.38 protocol difficulties we documented in Fax over VoIP: why T.38 fails. The paradoxical result: hardware fax is declining, online fax is growing, because it keeps interoperability while doing away with the physical line.

Five real-world situations and the right channel for each
Sending a medical report between professionals
Recommended channel: MSSanté. The system, operated under the authority of the Agence du Numérique en Santé, is the reference framework for exchanges between identified healthcare professionals. It offers encryption, traceability and HDS-compliant hosting. Fax has no justification here, except to reach an organisation not listed in the directory — which is becoming rare. Our article Fax and healthcare in 2026 covers the transition in detail.
Sending a formal notice of default
Recommended channel: qualified registered electronic mail. It is the only mechanism which, under the eIDAS Regulation and Article L.100 of the French Postal and Electronic Communications Code, produces the same effects as a paper registered letter with acknowledgement of receipt. A fax here is worth no more than a courtesy copy alongside a formal channel. Note: for a private individual recipient, qualified registered electronic mail requires their prior consent to receive registered electronic items.
Sending an 80 MB case file to a consultancy firm
Recommended channel: secure upload platform. Neither fax (designed for a few black-and-white pages) nor email (attachment limits around 20–25 MB with most providers) will do. An encrypted sharing platform with expiring links and download logging solves the problem, proof included. If the source documents are on paper, a duplex document scanner with automatic feeder will save far more time than any choice of channel.
Confirming an order with a foreign supplier
Recommended channel: online fax, or email if the supplier works that way. Many industrial supply chains, particularly in Germany and Italy, still keep fax procedures for purchase orders. Here, the question of proof is secondary: what matters is that the document enters the recipient's workflow. See our guide to sending a fax abroad for dialling codes and number formats.
Sending an identity document to an organisation
Recommended channel: the organisation's own portal, nothing else. Not fax, not email, not a third-party platform. Serious organisations — Assurance Maladie via Ameli, DGFiP via impots.gouv.fr, France Travail — all have an authenticated upload area. A copy of an ID document travelling through an uncontrolled channel is a security incident waiting to happen, and the GDPR holds you responsible for it as data controller.
What confidentiality really means
A stubborn misconception: "fax is confidential because it doesn't go over the internet." That was partly true in 1995. It no longer is.
A fax sent from an online service passes through servers, exactly like an email, before being converted into a telecom signal. A fax received on a physical fax machine comes out in plain sight in an output tray, in a corridor, within reach of anyone walking past. The CNIL has repeatedly pointed out that fax, particularly in medical settings, carries a real risk of disclosure through a mistyped number — one digit off and the file lands with a stranger, with no way to recall it.
The measures that really count:
- Check the number twice before sending anything containing sensitive data, and never trust a device's stored memory that hasn't been reviewed.
- Put the fax machine in a restricted-access room, or switch to fax-to-email to eliminate automatic printing.
- Add a cover page carrying a confidentiality notice and the sender's identity.
- Wipe device memory before any disposal or lease return.
- Encrypt archives: an encrypted external hard drive or a digital safe for retained copies, rather than a shared folder open to everyone.
For the full applicable framework, see Fax confidentiality: what the GDPR requires.

Building your internal matrix in an hour
The best investment for a small business or a professional practice is neither software nor a subscription: it is a one-page table, posted near the workstations, answering "what am I sending, and through which channel". Three columns are enough:
- Document type (quote, medical report, deed, identity document, purchase order, etc.)
- Mandatory channel (not "recommended": ambiguity is what produces mistakes)
- What gets archived (transmission report, acknowledgement, copy of the document, retention period)
This document serves as an internal procedure within the meaning of the GDPR and proves invaluable in the event of an audit. A simple all-in-one printer with scanner is enough to feed the chain on the hardware side; most of the work is organisational. For retention periods, our guide to archiving your faxes sets out the benchmarks by document type.
A few additional good practices, often overlooked:
- Name files according to a stable convention (
YYYYMMDD_recipient_subject.pdf): that is what makes an archive findable five years later. - Keep acknowledgements with the document, not in a separate folder.
- Back up offline: an encrypted external hard drive kept somewhere other than the office protects against fire as well as ransomware.
- Train newcomers in ten minutes on the matrix — most leaks come from a transmission made "the way I was told to do it".
Frequently asked questions
Is an encrypted email worth more than a fax in court?
Not automatically. Under French law, evidence is freely admissible between traders and the judge has full discretion to assess it. An email electronically signed within the meaning of eIDAS carries greater evidential weight than a fax report, because it guarantees the integrity of the content. An email merely encrypted in transit, unsigned, brings no decisive evidential advantage.
Does secure healthcare messaging completely replace fax?
For exchanges between listed healthcare professionals, yes. It does not cover exchanges with parties outside the healthcare perimeter: private insurers, employers, non-integrated administrations. These residual flows often continue to go by fax or through dedicated portals.
Is online fax safer than a physical fax machine?
On confidentiality at the receiving end, yes: nothing comes out into an accessible tray. In transit, both ultimately rely on the telephone network, which is unencrypted. The difference lies mainly in access control and traceability, which are far better with an online service, provided you choose a European provider that clearly publishes its retention policy.
Should you keep a fax number in 2026?
Only if it appears on documents that can be held against you (company registration extract, prescriptions, terms and conditions, correspondence from partners) or if contacts still use it. If so, porting to a fax-to-email service avoids any break in service. See keeping your fax number after the PSTN shutdown.
How long should you keep proof of sending?
Align the period with that of the document itself: 10 years for accounting records (Article L.123-22 of the French Commercial Code), 5 years for most civil and commercial claims, 20 years for a medical file from the date of the last consultation. Proof of sending orphaned from its document is of little use.
In summary
- No channel is universally superior: the choice depends on the recipient, the proof required and the sensitivity of the data.
- Fax retains a unique advantage — interoperability with no prior setup — but offers only partial proof and no end-to-end confidentiality.
- Encrypted email protects content effectively, provided both parties are equipped; it does not prove receipt.
- MSSanté is the reference channel between listed healthcare professionals; eIDAS registered electronic mail is the only equivalent to postal registered mail.
- Secure upload platforms suit large files and ongoing exchanges, with built-in logging.
- For identity documents and highly sensitive data, always go through the authenticated portal of the organisation concerned.
- Formalise a one-page matrix "document → channel → archiving": it is the most cost-effective measure there is, and it satisfies the GDPR's procedural requirement.
Tagsfaxsecuritypaperlessvoip