Government documents often carry more information than the person receiving them needs. An Aadhaar copy may reveal a full identity number and address. A driving licence can show a date of birth. A certificate may include a registration number that should not be posted in a public chat or left in a shared downloads folder. The safest way to handle these files is to use an official source, confirm the recipient, share only what the process requires, and remove temporary copies when the task is finished.
How to Download and Share Government Documents Safely
Download and share Indian government documents more safely using official portals, DigiLocker, Masked Aadhaar, verified recipients, and careful cleanup.

This guide focuses on Indian government documents and official services such as DigiLocker and UIDAI. The same decision process also works for many tax records, education certificates, licences, and benefit documents. Menu labels and acceptance rules can change, so follow the instructions shown by the issuing department or the organization requesting the document.
The short answer
Download a government document only from the issuing department, DigiLocker, MyAadhaar, or another official government service. Type the address yourself or use a trusted bookmark instead of opening a link from an unexpected message. Before sharing, ask the recipient which document, fields, format, and verification method are required.
Use a document fetched into DigiLocker's Issued Documents section when that option is available. DigiLocker explains that issued documents come from integrated issuers, while files in DigiLocker Drive are uploaded by the account holder. Those two files may look similar, but they do not have the same source trail.
For Aadhaar, check whether the organization accepts Masked Aadhaar, a Virtual ID, or Aadhaar Paperless Offline e-KYC. UIDAI says Masked Aadhaar hides the first eight digits and shows only the last four. A VID is a temporary, revocable number that can be used instead of the Aadhaar number for supported authentication and e-KYC services.
Share through the recipient's official upload portal or a consent-based document request whenever possible. If a PDF must be sent, confirm the address through a second trusted channel, send only the required file, and avoid leaving it in a public link or group conversation.
Confirm what the recipient actually needs
A request for identity proof is not automatically a request for every document you own. Ask four questions before downloading anything:
- Which exact document is accepted?
- Does the recipient need the complete document or only selected fields?
- Must it be an issuer-fetched record, a digitally signed PDF, an offline verification file, or a normal scan?
- Which official portal, office, or verified address should receive it?
This check prevents two common mistakes: sending a full identity document when a less revealing version would work, and sending a genuine document to an impersonator. Do not rely only on a logo, display name, or caller ID. Open the organization's website yourself and compare the request with its published process. If the request came from an employer, bank, university, insurer, or government office, confirm it with a known contact or the number published on that organization's official site.
Never share an OTP, DigiLocker security PIN, MyAadhaar login code, account password, or device unlock code. A recipient may need a document or a consent action, but it does not need the secret that unlocks your account. The National Cyber Crime Reporting Portal describes phishing and vishing as attempts to obtain personal or account information through deceptive messages and calls. An urgent request for both a document and an OTP should be treated as suspicious.
Start from the official document source
Use the issuing authority's website or app first. A search advertisement, shortened link, messaging attachment, or lookalike app can send you to a fake sign-in page. Check the domain before entering an identity number or requesting an OTP. The DigiLocker FAQ identifies https://digilocker.gov.in as the official service address. UIDAI directs Aadhaar holders to MyAadhaar or the mAadhaar app for e-Aadhaar.
DigiLocker separates records into two useful groups:
| Document location | What it means | Best use |
|---|---|---|
| Issued Documents | The integrated issuer supplies the electronic record and its URI | When the recipient wants an authentic record that can be traced to the issuer |
| DigiLocker Drive | You uploaded the file yourself | Personal storage or a process that specifically accepts an uploaded copy |
A self-uploaded scan does not become an issuer-fetched record simply because it is stored in DigiLocker. When a department is integrated, fetch the document through Browse Documents and follow the issuer's requested fields. If the record cannot be found, check the document number, name, date, and issuing database rather than uploading a different file and presenting it as issued.
The Tutorils guide to storing, accessing, and sharing documents in DigiLocker covers the account workflow in more detail. For identity and education records, see the separate guide to using DigiLocker for PAN, Aadhaar, and certificates.
Prepare the phone or computer before downloading
A correct government website does not protect a file after it reaches an unsafe device. Install current operating system and browser updates, use a screen lock that other people do not know, and avoid downloading sensitive records on a public computer. Do not use a borrowed phone unless there is no safer option and you can remove the file, browser download, and account session afterward.
Check where downloads are saved. Browsers often place every file in one Downloads folder, which makes it easy to attach the wrong document later. Create a private folder with a neutral name and move the file there after download. Avoid putting the full Aadhaar number, PAN, passport number, or date of birth in the filename. A name such as identity-proof-application.pdf reveals less than a filename containing the complete identifier.
If the device automatically uploads the Downloads folder to a cloud account, decide whether that account is appropriate for identity records. Protect it with a unique password and a second sign-in factor. The Tutorils cloud backup setup guide explains how to choose folders deliberately instead of syncing every download. Android users should also review privacy settings that limit unnecessary app access.
Download from DigiLocker without confusing the file type
Sign in through the official DigiLocker app or website. Open Issued Documents, select the required record, and use the download or share option displayed for that record. DigiLocker's current FAQ says its Activity section records actions such as uploads, downloads, and shares. Review that log if you are unsure whether a document was shared or accessed.
The exact download format can depend on the issuer and service. A PDF may be convenient for a person to read, while a URI, QR code, JSON record, or consent flow may be better for machine verification. Do not convert or edit the file unless the receiving process specifically permits it. Conversion can remove a digital signature, break a QR code, or separate the visible page from verification data.
After downloading, open the file locally and check four things: the correct name, the correct document type, the current details, and the expected issuer. Do not assume the most recent filename contains the correct record. If the file opens blank, shows another person, or contains outdated details, stop and resolve the issue with the issuer before sharing it.
DigiLocker's terms state that users must explicitly consent before documents are fetched or shared. Read the organization name and the requested document during a consent flow. Cancel if the requesting organization, purpose, or data does not match the task you started.
Share Aadhaar with less exposure
Aadhaar requires an extra decision because different processes may accept different official forms. Do not create your own edited Aadhaar and assume it will pass verification. Use a privacy-preserving option supplied by UIDAI when the recipient supports it.
Masked Aadhaar
UIDAI defines Masked Aadhaar as an e-Aadhaar in which the first eight digits are replaced with xxxx-xxxx and only the last four remain visible. Choose the masked option during the official e-Aadhaar download when the receiving organization confirms that it is accepted. The rest of the document still contains personal information, so it should not be posted publicly or shared without checking the recipient.
Virtual ID
UIDAI describes VID as a temporary, revocable 16-digit number mapped to the Aadhaar number. It can replace the Aadhaar number in supported authentication or e-KYC flows, and the Aadhaar number cannot be derived from the VID. A VID is not a universal substitute for every document request. Use it only when the official process offers that choice.
Aadhaar Paperless Offline e-KYC
UIDAI's Offline e-KYC service creates a digitally signed XML file inside a ZIP protected by a Share Code. It is designed for offline identity verification without requiring the verifier to collect or store the Aadhaar number. UIDAI says the Aadhaar holder shares the ZIP and Share Code with a service provider that supports the process.
Do not upload this ZIP to a public link or send it to a person who cannot explain how it will be verified. The package can include personal fields selected during generation. Confirm which fields are necessary and use the service provider's official channel. UIDAI also states that a service provider must not share, publish, or display the XML, Share Code, or its contents to anyone else.
The UIDAI Masked Aadhaar FAQ explains which digits are hidden. The UIDAI Virtual ID FAQ explains where a VID can replace the Aadhaar number. Its Paperless Offline e-KYC FAQ explains the XML and Share Code workflow.
Choose the safest sharing route available
The best route is usually the one that keeps the document inside an official verification process. Use the recipient's secure upload page, an in-person verification desk, DigiLocker consent request, issuer URI, or supported QR verification before sending a loose PDF. These options reduce the number of uncontrolled copies, although you should still confirm the requester and purpose.
Use this order when more than one method is offered:
- An official portal that you opened from the organization's published website.
- A DigiLocker or issuer-based consent and verification flow.
- A verified organization account or address that the published process names.
- A direct transfer to a known person only when the first three options are unavailable and the organization accepts it.
If email is required, type the verified address yourself and inspect the attachment before sending. Check for auto-completed recipients with similar names. Use a new message instead of replying inside an unexpected request. Ask the recipient to confirm receipt through the official case or application channel.
If a messaging app is the only accepted route, use a one-to-one conversation with the verified recipient, not a group. Avoid forwarding the document through several people. Do not include an OTP, login PIN, or complete identity number in the accompanying message. Delete the local chat copy only after the receiving process is complete and after considering whether you need evidence of submission.
A password-protected file does not make an unverified recipient safe. It can reduce casual access if the file is misdirected, but the same person still receives the document once the password is known. If the receiving process supports a separate password or Share Code, provide it through a different verified channel. Do not invent encryption steps that prevent the recipient's official system from opening or verifying the file.
Preserve authenticity and verification data
A readable screenshot is not always a verifiable government document. It can omit the digital signature, QR code, URI, page count, or document metadata that a verifier needs. Send the original issued file or use the platform's share function when the process requires authenticity checks.
Do not place marks over a QR code or digital signature. Do not crop the issuer name, document number, or validation area if the recipient needs those fields. If you need to hide information, ask whether the issuer provides an official masked version or whether the recipient accepts a clearly labelled redacted copy for that purpose. Keep the untouched original separate.
DigiLocker says issued driving licence and vehicle registration records can be checked through the document's digital signature or the QR scanning facility in its mobile app. Other issuers may use different methods. Follow the validation instructions for the specific document instead of assuming every QR code or PDF signature works the same way.
For paper records that have no official electronic version, make a clear scan with every required edge and page visible. The Tutorils guide to free document-scanning apps can help with capture quality, but inspect the app's storage and sharing settings before scanning identity records.
Clean up temporary copies after submission
Once the organization confirms that the document was received and the application no longer needs another upload, remove copies that have no continuing purpose. Check the Downloads folder, desktop, scanner app, photo gallery, messaging attachment folder, email drafts, and recently deleted or recycle folder. A file may exist in more places than the one you opened.
Do not delete the only official copy or destroy records that you must retain. The goal is to remove uncontrolled temporary duplicates, not to erase your personal archive. Keep the master copy in a protected folder or trusted document service. Record where it came from and when you downloaded it without putting sensitive numbers in the filename.
Review DigiLocker's Activity section after a sensitive share. Also review the account's phone number, security PIN, and active sessions if the service provides those controls. Sign out of devices you no longer own. On a shared browser, clear the downloaded file and sign out, but remember that browser cleanup cannot guarantee removal from a computer controlled by someone else. Avoid shared devices for future downloads.
Respond to a suspicious request or mistaken share
Stop communicating through the suspicious message. Open the real organization website independently and ask whether the request is genuine. If you entered credentials on a lookalike site, change the affected account password from a clean device, secure the email or mobile account used for recovery, and review recent activity. Do not approve new OTP requests.
If you sent a document to the wrong person, ask the service owner whether a link, consent, or session can be revoked. A normal email attachment or downloaded copy usually cannot be remotely retrieved, so focus on securing related accounts and watching for misuse. If Aadhaar information was exposed, review the privacy and security options available through UIDAI, including VID and authentication history, according to the official service instructions.
Preserve evidence before deleting a phishing message. The National Cybercrime Reporting Portal manual advises keeping the original email, full headers, screenshots, and attachments when reporting email phishing because they may be needed as evidence. Use cybercrime.gov.in for India's official reporting process. Contact the affected issuing department or organization through its published support channel as well.
A repeatable document safety checklist
Before sending any government document, confirm that:
- The file came from the issuer, DigiLocker, UIDAI, or another official source.
- You opened the service through a known government domain or official app.
- The requester's identity and receiving channel were verified independently.
- You know the exact document, fields, and format required.
- A masked, revocable, or consent-based option was considered when supported.
- The file has not lost a required signature, QR code, URI, or page.
- The recipient address and attachment were checked immediately before sending.
- No OTP, password, PIN, Share Code, or device unlock secret is in the same message unless the official process specifically requires a separate code flow.
- Temporary local, chat, scanner, and cloud copies will be reviewed after completion.
- You know how to contact the issuer and preserve evidence if the request turns out to be fraudulent.
Safe document sharing is a short chain of decisions. Verify the request, obtain the record from its real source, reveal only what the process needs, use the strongest accepted transfer route, and clean up temporary copies. That process protects the document without making it unusable to the organization that must verify it.
Reader answers
Frequently asked questions
Open a question to read the answer. Opening another answer closes the previous one.
What is the safest way to share a government document online?
Use the recipient's official upload portal, DigiLocker consent flow, or issuer verification link when available. Confirm the requester through a published contact before uploading, and send only the document and fields the process requires.
What is the difference between issued and uploaded documents in DigiLocker?
Issued documents come from integrated issuers and appear as issuer-linked records. Uploaded documents are files you placed in DigiLocker Drive yourself. An uploaded scan does not become an issuer-fetched record.
Can I send my Aadhaar PDF through WhatsApp?
Use an official portal or DigiLocker flow when possible. If a verified organization accepts WhatsApp, use a one-to-one chat, consider Masked Aadhaar when accepted, and never send an OTP, account PIN, or login code.
What is Masked Aadhaar and when should I use it?
Masked Aadhaar is an official e-Aadhaar option that hides the first eight digits and shows the last four. Use it when the receiving organization confirms that a masked copy is accepted.
Can I edit my Aadhaar number out of a PDF before sharing it?
Do not alter an official file and assume it remains verifiable. Download UIDAI's official Masked Aadhaar when accepted, or ask the recipient whether a clearly labelled redacted copy is suitable for that specific purpose.
Is an issued DigiLocker document legally valid?
DigiLocker states that issued documents are treated at par with physical originals under its governing rules. Acceptance and the required verification method can depend on the service, so follow the receiving authority's current instructions.
What is Aadhaar Paperless Offline e-KYC?
It is a UIDAI-generated, digitally signed XML package for offline identity verification without requiring the verifier to collect the Aadhaar number. Share it and its Share Code only with a supported, verified service provider.
How can a recipient verify a digital government document?
Use the method named by the issuer, such as a digital signature, QR code, document URI, or official portal check. A screenshot may omit the data needed for verification.
What should I do if I sent a document to the wrong person?
Ask the service whether a link or consent can be revoked, secure related accounts, and monitor for misuse. Preserve evidence if fraud is suspected, then use the issuer's support channel or the National Cybercrime Reporting Portal.
Should I keep government documents in cloud storage?
Keep a protected master copy only if it serves a clear purpose. Secure the cloud account, choose the synced folder deliberately, avoid sensitive numbers in filenames, and remove temporary duplicates after submission.