dipback

Guides / August 31, 2026

Is it safe to share your booking confirmation with a service?

7 min read


Dipback team
A confirmation email is a receipt stapled to an itinerary: names, flights, a record locator, ticket numbers, and the last four digits of a card. Forwarding one hands over that fixed set of facts and nothing else, which is a different thing from account access, and account access is where the usual warnings are really aimed. Here is what each field exposes, and the three questions worth asking before you send it to anyone, us included.

Is it safe to share your booking confirmation? You have the email open, something is asking you to forward it, and you have stopped — a reasonable place to stop, because the advice you find on this tends to answer a different question than the one you are asking. So here is the email itself, field by field: what each line exposes, what it does not, and where the line sits between sending a copy and handing over an account.

What is actually inside a booking confirmation

Read your confirmation the way a stranger would. Take out the logistics — your name as ticketed, the flights, times and airports, the cabin, a fare brand in small type, the total you paid — and two identifiers near the top are what remain.

The record locator, and what someone can do with your flight confirmation number

Six characters, letters and digits, usually set larger than anything else on the page. Airlines call it the record locator, the confirmation code, or the PNR — the handle for your reservation, not a secret about it.

Its whole job is to be looked up. Paired with a surname, it is generally what pulls a trip into an airline's manage-booking screen: the design of the code, not a flaw in it. So what does a booking reference reveal? Your itinerary, to anyone who already has your surname. What someone could then see or change from that screen varies by carrier, so keep the code to yourself rather than assume a limit on it. Whether it is safe to share your PNR is a question about the recipient, not about six characters that sit closer to a utility-bill account number than to a password.

What it will not tell anyone, including you, is which fare you hold; a different field settles that, covered in where the fare brand hides on your confirmation.

Ticket numbers, one per passenger

Longer, usually thirteen digits, and easy to miss down in the receipt block rather than the header. There is normally one record locator per booking and one ticket number per traveler.

A ticket number means the fare was issued and paid for, and it is generally what an airline works from if a ticket is repriced — more specific than the record locator, and more useful to anyone acting on the ticket.

What is not in the email: no card number, no airline password

The absences do the heavy lifting here. A confirmation does not carry your full card number, usually just a card brand and the last four digits. It generally does not carry your airline password, your loyalty PIN, or any credential that would let someone sign in as you. It is a receipt stapled to an itinerary, which is why the question has a calmer answer than the headlines suggest.

Forwarding an email is not the same as account access

Forwarding an airline confirmation to a third party is a one-way transfer of a fixed set of facts, frozen at the moment you press send. It grants nothing, cannot be used to sign in anywhere, and hands over exactly the fields on the page that day and not one more.

An airline login is the opposite shape: live, ongoing, delegating everything the account can reach — saved payment methods, other trips, the ability to change any of it. One is a photocopy; the other is a key.

Forward a confirmation and regret it, and the exposure is bounded by what that email held. Any service that needs a password to do what a copy of an email can do has designed itself wrong.

Why the usual advice says never share it

The advice did not come from nowhere. It is aimed somewhere else — at two scenarios in particular.

What that advice is really about: boarding-pass photos and public lookup pages

The first is the boarding pass in public: a photo posted to social media, a stub left in the seat pocket. Published analyses of boarding-pass barcodes have shown that the encoded data can include more than the printed side shows; the specifics differ by carrier and by barcode format, so treat it as a reason not to post the image rather than a settled description of what any one barcode holds, and a public post stays there for anyone who scrolls past.

The second is the lookup screen. Because a record locator plus a surname is built to retrieve a trip, a code that reaches a stranger is a code a stranger can try. Both warnings are about broadcast, which is a different act from sending an email to one named recipient.

A third case gets blamed on those two: the message that arrives claiming to be your airline, needing something more to fix a problem you did not know you had. The tell is direction — you go looking for a service; a scam comes looking for you.

Is it safe to share your booking confirmation with a company you approached?

Apply this to us as readily as to anyone else. Three questions cover it.

Who is asking, and whether you can reach them

Did you go to them, or did they come to you? Treat anything arriving unprompted about a specific booking as unverified until you reach the company by a route you found yourself, not a link they supplied. Then check the ordinary things: a registered company name, a support address that answers, a domain that matches the mail. Legitimate services are boring to verify.

What they say they do with it, in writing

Look for a published privacy policy that names what it collects and which vendors process it. Named subprocessors are a good sign, because a vendor list is a commitment someone can hold you to. "Your data is safe with us" is not one. Read the retention part specifically: what happens to the email after it is read, and if you close the account.

Whether they ever ask for your airline login

This is the bright line. Nobody legitimate should ask you for your airline password — not to check a fare, not to verify a booking, not to speed anything up. A service that needs your credentials is asking you to carry a risk it should carry itself, and the request is reason enough to stop, whoever is making it. The same goes for anything credential-shaped: a one-time code, a reset link, a security answer.

What we do with a forwarded confirmation

Evidence rather than reassurance, so here is the sequence.

The forward reaches an inbox we run, and the first thing that happens is a match on the sender. A known address, and the message is attached to your account. An unknown one, and it lands in an unmatched queue where nothing follows: no booking created, no monitoring started.

An automated step then reads the flight details out of the message — airline, booking reference, passengers, segments, cabin and fare brand, the total paid. Those fields go into your account, and the original is kept as you sent it, because when a reading looks wrong it is the only way to check. Access is limited to your own account and to the people who verify a candidate drop on your behalf — a person checks every one before anything is filed, as how Dipback works sets out.

We never ask for an airline login; there is nowhere in the product to give us one. Card details go to Stripe and are never stored by us. The vendors, what we collect, and how long we keep it are in our privacy policy, worth reading before you forward rather than after.

If you would rather not forward anything

You can type the booking in by hand instead: airline, reference, flights, what you paid. Nothing leaves your inbox and the monitoring is identical. Or watch the fare yourself — genuinely doable, and the method is in how to track your airfare after you book. The catch is a chore with no end date, on a schedule the fare sets rather than you.

If you would rather start smaller than either, open the signup flow and stop at the email step. That step is why forwarding works at all: once we know which address to expect from you, mail from it is matched to your account, and mail from an address we do not recognize does nothing. Nobody is asking you to forward anything today — read what we would ask for, and close the tab there if the answer is still no.

Frequently asked questions

What can someone do with my flight confirmation number?

A confirmation number, also called a record locator or PNR, is a lookup handle rather than a password. Paired with the surname on the booking, it is generally what retrieves a trip in an airline's manage-booking area. What is visible or changeable from there differs by carrier and can change without notice, so treat the code as something you give out deliberately rather than post publicly. It is not a credential: on its own it will not sign anyone into your airline account, your email, or anything holding your card.

Is it safe to forward my airline confirmation email to a third party?

Forwarding sends a copy of fixed information: names, flights and dates, a booking reference, ticket numbers, the total paid, and usually only the last four digits of a card. It grants no ongoing access and cannot be used to sign in anywhere, so the exposure is bounded by whatever that message contained on the day you sent it. The harder question is the recipient. Whether you approached them or they approached you, whether they publish what they collect and how long they keep it, and whether they ever ask for credentials are the things worth checking first.

Should I ever give a fare-tracking service my airline login?

Treat that as a hard no. Nothing about watching a fare requires your airline password, and a company asking for one is moving a risk onto you that it should be carrying itself. The same caution applies to anything that behaves like a credential: a verification code read out over the phone, a password reset link, or the answer to a security question. If a request like that follows an unprompted message about a specific trip, stop and reach the company through a route you found yourself before replying.

What happens if I forward a confirmation from an email address you do not have on file?

Nothing happens, and that is deliberate. Forwards are matched against the addresses on an account, so a message from an address we do not recognize lands in an unmatched queue: no booking is created, no monitoring begins, and no account is touched. It is also why the email step during signup carries more weight than it appears to, since it tells us which address to expect from you. If you have already sent something from an address we do not have, add that address to your account and forward the message again.

Can I add a booking without forwarding an email at all?

Yes. You can type the booking in by hand, giving the airline, the booking reference, the flights and dates, and what you paid, and monitoring works the same way from there because the fields matter rather than how they arrived. Manual entry keeps the original message in your inbox, which some people prefer for a first booking while they decide whether a service has earned more than that. Tracking the fare yourself with a search you re-run is a third option; the trade is that it never stops needing you.

Browse by topic

Have a booking sitting unwatched?

Forward the confirmation and we start watching the fare today.

Add my first trip