Before sharing a pay stub, confirm who is requesting it, why it is needed, and which details they require. Use the recipient's verified submission process and keep the original document. A pay stub can contain sensitive identity and financial information, so the safest approach starts before you attach the file.

1. Verify the recipient independently

Use a contact method you already know or reach the organization through its established website. Do not rely only on a link, phone number, or urgent instruction in an unexpected message. Confirm the person or department handling your application and the exact destination for the document.

The FTC's identity-theft guidance identifies Social Security numbers and financial account information as sensitive data and recommends asking why an organization needs your SSN, how it will protect it, and whether another identifier will work. Apply that same questioning approach to an unfamiliar document request.

2. Ask which documents and fields are needed

Ask for the requested date range, number of statements, accepted file format, and any required visible fields. Also ask whether a privacy-redacted copy is acceptable. There is no universal rule that every recipient accepts the same version of a pay stub.

The stage of the process matters. For mortgage transactions covered by the Loan Estimate rules, the CFPB explains that a lender cannot require documents as a condition of providing a Loan Estimate. After you choose to proceed, verification documents may be required. This distinction is specific to that process; it does not establish document requirements for every loan, rental, or other application.

If you need older statements, our guide to obtaining pay stubs from a former employer explains how to request the records rather than reconstructing a missing employer-issued document.

3. Keep the original and prepare only the agreed copy

Save the unmodified original in your own secure records. If the recipient allows redaction, work on a separate copy and remove only the information they have confirmed is unnecessary. Potential items to discuss include a full SSN, bank account details, or an unrelated employee identifier, if those fields appear on the statement.

Do not change earnings, dates, employer details, or other facts to make the document appear different. A privacy-redacted copy should be identified as such. If the recipient needs an original statement, ask about a secure route for supplying it rather than silently removing required information.

For an electronic file, use a redaction feature designed to remove the underlying information. A colored box, highlight, or drawing may merely cover text visually. Reopen the final copy and check that the removed information cannot be selected, copied, or found through text search; this check helps catch mistakes but is not a guarantee that every hidden element has been removed. Follow the software's documentation for sanitizing hidden content.

4. Review the file and submission destination

  1. Open the exact attachment. Confirm it belongs to you and covers the requested period.
  2. Check every page. Ensure a combined PDF does not include another person's record or an unrelated document.
  3. Use the verified submission channel. Prefer the organization's established secure upload process when available.
  4. Check access settings. If an approved file-sharing link is used, verify the intended recipient and avoid a publicly accessible link.
  5. Keep a record. Save the date, recipient, version sent, and any submission confirmation.

A familiar logo or a padlock icon alone does not establish that an upload destination belongs to the intended organization. Confirm the destination independently before submitting sensitive documents. Do not give someone your payroll password or login code as a substitute for sending a statement.

Our check stub reading guide can help you identify the fields before asking what must remain visible. The pay stub retention guide covers organizing the original records after submission.

What if you sent the wrong file or used the wrong address?

Act promptly. If possible, revoke access to a shared link. Contact the intended organization through a known channel, explain what happened, and record the response. Revoking a link cannot retrieve a copy that someone already downloaded, so avoid assuming the exposure is undone.

If you suspect identity theft, the FTC directs people to IdentityTheft.gov for reporting and a recovery plan. The appropriate next steps depend on what information was exposed and whether it has been misused.

A careful submission process reduces unnecessary disclosure, but it cannot guarantee security or document acceptance. Confirm the recipient's requirements while preserving the accuracy of the underlying pay record.