Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

For a playful hidden note, write the readable plaintext, choose a cipher or codebook, agree on its key, transform the message consistently, and have the recipient reverse the process. A Caesar shift is the easiest starting point; keyed substitution, transposition and Vigenère add puzzle difficulty. None of these handwritten systems should protect genuinely sensitive information.

A code replaces whole words or ideas. A cipher applies a repeatable rule to letters or their order. Encoding systems such as Morse and Braille change representation but do not automatically provide secrecy. Khan Academy’s cryptography overview and the NSA’s Codes and Ciphers explain these distinctions.

Before you start: agree on the rules

Most failed secret notes are not “cracked”; they are encoded with different assumptions. Decide these points with the recipient or puzzle instructions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Use the 26-letter A–Z alphabet, or specify another alphabet. Decide whether I and J are separate.
  • Choose whether spaces, apostrophes, accents, numbers and punctuation are kept, removed or converted.
  • State whether a key repeats after spaces or only after letters.
  • Choose uppercase handwriting and group long ciphertext in blocks of five for accurate copying.
  • Keep the plaintext in a separate draft and test a short phrase before sending the real message.

The basic flow is:

Plaintext + method + key → ciphertext
Ciphertext + method + key → plaintext

Plaintext is the original readable message; ciphertext is its transformed form; encryption (or enciphering) creates ciphertext; decryption (or deciphering) recovers plaintext; and a key is the setting or secret information controlling the transformation. Cryptanalysis means trying to recover a message or key without authorization.

Code, cipher, encoding and steganography

Codes use a codebook

A code substitutes a whole word, phrase, person, place or idea. For example:

Meaning Code word
Meet at home Bluebird
Danger Storm
Bring the map Lantern

Both parties need the same codebook. A message can combine methods—for example, replace “meet at home” with Bluebird, then apply a cipher to the remaining text.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ciphers follow a rule

A cipher shifts letters, substitutes them using a table, or rearranges their order. The same procedure can be applied repeatedly and reversed by someone who knows the method and key. Patterns such as repeated letters and word lengths often survive; ciphertext is not necessarily random.

Steganography hides the message’s existence

Steganography places a message inside an apparently ordinary carrier, rather than merely scrambling visible text. Taking the first letter of each sentence, using the second word of every line, or embedding text in a shopping list are simple examples. A cipher can be applied first and the resulting ciphertext hidden afterward. The carrier must still look natural; awkward wording can reveal it.

The easiest cipher: a Caesar shift

A Caesar cipher moves every letter by the same number. The method is named for Julius Caesar because historical accounts associate him with its use, although earlier substitution methods existed (PBS NOVA).

Encode step by step

  1. Choose a shift from 1 to 25. Use 3 for this example.
  2. Write the paired alphabets:
    Plain: ABCDEFGHIJKLMNOPQRSTUVWXYZ
    Cipher: DEFGHIJKLMNOPQRSTUVWXYZABC
  3. Replace each plaintext letter with the letter beneath it. Decide in advance what to do with spaces and punctuation.

Plaintext: COME AT SIX
Ciphertext: FRPH DW VLA

To decode, shift every letter three places backward. The alphabet wraps around, so Z shifted forward by three becomes C.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Useful conventions and limits

Keeping spaces makes a note easier to read but reveals word lengths; removing them looks more puzzle-like but increases copying errors. Uppercase letters reduce handwriting ambiguity. A message number or length can help a puzzle solver detect a missing character, but it does not strengthen the cipher.

There are only 26 possible shifts, including the unchanged alphabet, so trying every possibility is easy. The Office of the Privacy Commissioner of Canada describes this weakness and the persistence of language patterns ().

Atbash: a fixed reversed alphabet

Atbash pairs the first letter with the last, the second with the second-last, and so on:

Plain: ABCDEFGHIJKLMNOPQRSTUVWXYZ
Cipher: ZYXWVUTSRQPONMLKJIHGFEDCBA

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A becomes Z, B becomes Y and H becomes S, so HELLO becomes SVOOL. Atbash needs no exchanged key and is easy to perform by hand, making it useful for an introductory exercise or short visual puzzle. Its fixed, recognizable rule means it is not serious secrecy.

Pigpen and other symbol alphabets

Pigpen assigns each letter to a position in grids; a dot distinguishes the second set of letters. A conventional chart can be represented as follows (the shape is the grid position; a dot marks the second letter in that position):

Grid position Letter 1 Letter 2
Top-left corner ┌ A J •
Top edge ┬ B K •
Top-right corner ┐ C L •
Left edge ├ D M •
Center ┼ E N •
Right edge ┤ F O •
Bottom-left corner └ G P •
Bottom edge ┴ H Q •
Bottom-right corner ┘ I R •
X-grid upper-left angle ⋖ S W •
X-grid upper-right angle ⋗ T X •
X-grid lower-left angle ⋘ U Y •
X-grid lower-right angle ⋙ V Z •

Draw and share the complete chart, encode one short word, and have the recipient decode it. Similar-looking marks, reversed shapes and missing dots are common failure points. Pigpen hides meaning from a casual observer but is easy to read once its alphabet is known.

Morse, Braille, binary and symbol writing

These are usually encodings or representations, not encryption:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Morse code represents letters and numbers with dots and dashes for writing, sound, light or tapping.
  • Braille represents characters through raised-dot patterns.
  • Binary or numerical alphabets represent letters as numbers or bit patterns.
  • Symbol alphabets replace ordinary letters with visual marks.

Someone who learns the mapping can read the message. Any secrecy comes from obscurity or an undisclosed mapping, not modern cryptographic strength.

Keyed substitution: a scrambled alphabet

A monoalphabetic substitution cipher gives every plaintext letter one permanent substitute. To build one with the keyword SECRET:

  1. Remove repeated keyword letters: SECRET → SECRT.
  2. Append every unused alphabet letter once, producing a full 26-letter cipher alphabet.
  3. Write it beneath ABCDEFGHIJKLMNOPQRSTUVWXYZ and substitute each letter.

Check that every alphabet letter appears exactly once. Agree on I/J treatment, spaces, punctuation and numbers, and never change the table midway. The same plaintext letter always produces the same ciphertext letter, so repeated words and letter frequencies can be analyzed. This is harder than Caesar but remains a puzzle system, not protection for confidential data (Kennesaw State University cryptography exercises).

Transposition: rearrange, do not replace

Transposition keeps the letters but changes their order (NSA, Codes and Ciphers).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Two-rail route (rail-fence)

Write MEETMEATNOON in a zigzag on two rows, then read across rows:

M   E   M   A   N   O
  E   T   E   T   O   N

The resulting ciphertext is the first row followed by the second. To decode, recreate the zigzag positions and read alternately from the two rows. Use one agreed layout; different rail counts produce different results.

Columnar transposition

  1. Choose a keyword and number its letters in alphabetical order, resolving repeated letters by their left-to-right order.
  2. Write the message beneath the keyword in rows.
  3. Add an agreed padding character if the final row is incomplete.
  4. Read columns in number order. Reverse these steps to decode.

An omitted or extra character can shift every later character. Grouping in fives, recording the message length and testing the reverse process reduce this risk.

Vigenère: changing shifts with a keyword

Vigenère is a polyalphabetic substitution cipher: a repeating keyword supplies a different Caesar shift at each position. The Library of Congress provides a historical teaching example (Library of Congress).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Choose a keyword, such as LEMON.
  2. Remove spaces and punctuation, or define how they count, then repeat the keyword to the message length.
  3. Convert letters to numbers with A=0 through Z=25.
  4. Add plaintext and key values modulo 26 and convert back to letters.

Plaintext: ATTACKATDAWN
Key: LEMONLEMONLE
Ciphertext:LXFOPVEFRNHR

For decryption, subtract the key values. The same plaintext letter can encrypt differently at different positions, but repeating a short key creates analyzable patterns. Vigenère is historically important and useful for a classroom exercise, not modern confidentiality. A one-time pad is a different system: its key must be truly random, at least as long as the message, secret and never reused (Office of the Privacy Commissioner of Canada).

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A reliable workflow for sending a handwritten secret

  1. Identify the purpose. Use Caesar or Pigpen for a playful note, several methods for a lesson, and a clue-solvable method for a puzzle.
  2. Choose the alphabet and conventions. Set I/J, spaces, punctuation, numbers, padding and key-reset rules.
  3. Exchange the method and key. Use a shift number, keyword, codebook or symbol chart. Keep it separate from a puzzle’s obvious ciphertext.
  4. Encode a test phrase. The recipient should decode it before relying on the system.
  5. Encode the message. Check every character against the original plaintext.
  6. Group and label carefully. Use uppercase blocks of five and, where helpful, a non-secret length or message number.
  7. Decode independently. Start from the ciphertext and key rather than memory, then compare with the plaintext draft.
  8. Secure or destroy the key. This is optional for a game, but a disclosed key removes the intended secrecy.

Can these handwritten ciphers keep a message secret?

They can stop a passer-by from immediately understanding a note, but they are not modern security tools. Caesar has a tiny key space; substitution exposes frequency patterns; transposition preserves the original letters; and repeated-key Vigenère can be analyzed. Short messages may be guessed from likely phrases, while long messages reveal more language structure. Combining weak methods can make a puzzle harder for a casual solver while adding transcription errors and false confidence.

For genuinely private communication, use trustworthy, modern security software with sound key management rather than an invented hand cipher. The U.S. Naval Academy’s steganography lecture also distinguishes hiding a message from encrypting it.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which method should you choose?

Method Best for Main advantage Main weakness Difficulty
Caesar shift First lesson, quick note Very easy by hand Only 26 shifts Very low
Atbash Short visual puzzle No table required Fixed and obvious once recognized Very low
Pigpen Secret-looking handwriting Distinctive symbols Ambiguous marks; chart reveals all Low
Morse Sound, light or tapping Works beyond ordinary writing Encoding, not secrecy Low
Simple substitution Longer puzzle messages More varied than Caesar Frequency analysis Medium
Rail fence Showing rearrangement Clearly demonstrates transposition Easy to attack; errors propagate Low
Columnar transposition Puzzle design Keyed rearrangement Difficult to hand-check Medium
Vigenère Advanced classroom exercise Changing shifts Repeated keys remain vulnerable Medium
One-time pad Theory discussion Strong only under strict conditions Impractical key generation and distribution High
Modern authenticated encryption Actual confidentiality Designed for contemporary threats Requires trustworthy software; not handwritten Not a hand method

Common failure cases

  • Ambiguous alphabet: A=0 versus A=1, merged I/J, accented letters and number rules must match.
  • Mistyped ciphertext: use uppercase, blocks of five, a short test and a plaintext backup; do not edit ciphertext casually.
  • Key disclosure: putting “key: BLUE” beside the message is suitable for a demonstration, not an independently solvable puzzle.
  • Multiple languages or scripts: A–Z tables do not automatically cover diacritics, other alphabets, emojis or mixed text; adapt the alphabet explicitly.
  • Invisible ink: prefer harmless paper-based steganography; avoid toxic, corrosive or flammable substances.

Frequently asked questions

What is the easiest secret code to write?

For a reversible letter-by-letter method, use a Caesar shift. For a visual note, Pigpen is similarly approachable once both people have the chart.

Is Morse code a cipher?

Ordinary Morse is an encoding for letters and signals, not encryption. Learning the dot-and-dash mapping reveals the text.

Is Pigpen secure?

No. It obscures the message from casual readers, but anyone with the symbol alphabet can decode it.

Can I create my own cipher?

Yes, for games and learning. Document the alphabet, key, spacing and decoding steps, and test the reverse process. Do not assume originality makes it secure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do I send the key safely?

Give the recipient the method and key through a separate channel or in advance. For a puzzle, provide clues rather than placing the key beside the ciphertext.

What should I use for genuinely private messages?

Use reviewed modern encryption in reputable software, not Caesar, substitution, transposition or ordinary Vigenère.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.