A simple checklist for sending files securely (plus a quick comparison of the easiest options)

Two architects in a small open-plan creative studio organising project folders and drawings before sending a handoff link, in warm late-afternoon light.

You searched for a simple checklist for sending files securely because you have a real job to finish: get a folder of work to a client or collaborator without it bouncing, leaking, or turning into a version-control mess. Here is the checklist first (so you can ship today), then a side-by-side comparison of the most common ways to do it.

The simple checklist for sending files securely

1) Decide what “secure” means for this specific send

Security is not one switch. For client delivery, you usually want four things:

  • Only the right people can access it (password, limited recipients, or account access).
  • It does not live forever (expiry date you control).
  • It is not easy to forward indefinitely (download limits help for sensitive material).
  • You can prove what you sent (a stable link, clear file list, and ideally download activity).

If you are sending something truly sensitive (contracts, IDs, unreleased work), treat “secure” as: password + expiry + minimal sharing + separate channel for the password.

2) Package the files so nothing breaks on the other end

Most “security problems” start as workflow problems: you resend things, people use old versions, or they download the wrong file. Before you upload:

  • Use a clear folder name: ProjectName_Client_2026-08-30.
  • Include a short ReadMe.txt with what is inside, the “final” file name, and contact details.
  • Export a client-friendly format (PDF for layouts, JPG proofs, H.264/H.265 for review) and include source files only if needed.
  • Zip a folder when you need to preserve structure (fonts, linked assets, sessions). Do not zip just to “add a password” (more on that below).

Lived detail from the trenches: hotel Wi‑Fi dropping at 97% is not rare. A single huge zip can be painful to re-upload from scratch on flaky connections. If your tool supports resumable or multipart uploads, it will save your evening. If it does not, consider splitting into a few logical chunks (for example, Renders, Source, Deliverables).

3) Pick the right delivery method (transfer link vs cloud folder)

Use this rule of thumb:

  • Transfer link: best for handoffs, “here is the deliverable”, one-off sends, and anything that should expire automatically.
  • Cloud storage folder: best for ongoing collaboration where files change over time and both sides upload.

If you just need the client to download once, a transfer link is usually simpler and safer because it is designed to end.

4) Set expiry on purpose (and tell the recipient)

Set an expiry that matches the job:

  • 24 to 72 hours for review cuts and proofs.
  • 7 days for typical client delivery and “download when you can”.
  • 14 to 30 days when procurement or legal teams move slowly (or you are sending to a large org).

Then put the expiry in the message: “Link expires Friday”. It cuts down on “it says expired” emails later.

5) Use passwords correctly (and avoid the common fake-security trap)

The trap: “I put it in a zip with a password, so I’m done.” That helps only if the recipient handles it well, and it often causes support issues (mobile unzip failures, password typos, broken previews).

Better: use a tool that supports password-protected links, and send the password via a different channel (for example, link by email, password by text or chat). If you must use a zip password, use a modern format (AES) and test it on a phone before you send it.

6) Limit access and forwarding where it matters

If the content is sensitive (unreleased music, a commercial shoot, internal financials), consider:

  • A download limit (so the link cannot be used endlessly).
  • Single-recipient sharing (avoid posting the link into a big group chat).
  • Separate links per recipient when you need accountability.

Not every service offers download limits. If that feature matters, choose a service designed for controlled delivery rather than generic storage sharing.

7) Send a message that prevents back-and-forth

Copy/paste this and adjust:

  • What it is: “Final export + source folder”
  • What to download: “Download Project_Final_v3.mp4
  • Expiry: “Link expires in 7 days”
  • Password: “Password sent via SMS”
  • Fallback: “If the download fails, tell me what device you’re on and I’ll resend”

8) Know what happens after expiry (deletion vs “archived forever”)

This is the part most comparison posts skip. Two services can both say “expires”, while one quietly keeps your files in the background. If you care about confidentiality and cleanup, look for plain-language answers to:

  • Are expired transfers deleted or merely disabled?
  • How long are files kept if nobody downloads them?
  • Does the company sell or reuse file metadata or contact details?

If you want a deeper buyer checklist for this, see what happens to your files after you send them online.

Comparison: the easiest ways to send files securely (expiry, passwords, and what they are best at)

The options below are the ones creatives actually use when email attachments are a non-starter. Exact limits and pricing change, so treat competitor numbers as “check before you commit”. For LetsSend details, the limits below are accurate as of August 2026.

Secure file sending options compared (links vs storage)
OptionBest forFree allowance (typical)Max per send (typical)Expiry controlsPassword protectionPrice tier (typical)
LetsSendSimple transfer links for client deliveryUp to 5GB per transfer, 5GB daily allowance (Free, as of Aug 2026)200GB per transfer (Pro, as of Aug 2026)Auto-expiry, 7 days (Free) and up to 30 days (Pro, as of Aug 2026)Yes, link passwordFree and Pro ($12/month, as of Aug 2026)
WeTransferQuick one-off transfers, common client expectationFree tier available with limits (check current)Paid plans allow larger sends (check current)Expiry varies by plan (check current)Often plan-dependent (check current)Free and paid plans (check current)
Dropbox (shared link)Ongoing collaboration and shared foldersFree plan with storage cap (check current)Limited by storage and sharing rulesAdvanced expiry often plan-dependentOften plan-dependentFree and paid plans (check current)
Google Drive (share link)Teams already in Google WorkspaceFree storage cap (check current)Limited by storageExpiry controls typically in paid/Workspace contextsVia Google account permissions, link settings varyFree and paid plans (check current)
OneDrive (share link)Microsoft 365-heavy teamsFree storage cap (check current)Limited by storageExpiry controls often tied to plan/admin settingsOften available depending on plan/settingsFree and paid plans (check current)
Tresorit (encrypted sharing)High-sensitivity documents and compliance-heavy workMay have a trial or limited free option (check current)Varies by planStrong link controls (check current)Yes (check current)Paid-focused (check current)

Verdicts: which option fits your workflow?

If you are delivering a one-off client handoff (most creatives)

Use a transfer link tool that gives you expiry and a link password without fuss. You will spend less time explaining “request access” screens and more time finishing the next job.

If you want something private and straightforward, LetsSend is built for this. Transfers upload straight from your browser to encrypted object storage (not relayed through a middle server), links expire automatically, and you can password-protect links. Free allows up to 5GB per transfer with a 7-day expiry (as of August 2026). Pro goes up to 200GB per transfer and up to 30 days expiry, and Pro links can carry a download limit (as of August 2026). Sign-in is passwordless (short code via email), so there is no password to leak.

If you and the client will keep adding files for weeks

Use cloud storage (Dropbox, Google Drive, OneDrive) and treat it like a shared workspace, not a one-time delivery. Do the boring setup that saves you later: one shared folder, clear permissions, and a “Final” subfolder so drafts do not get mistaken for deliverables.

Trade-off: cloud folders are often “sticky”. They can linger indefinitely unless someone cleans them up, and link controls like expiry and passwords may depend on plan or admin settings.

If the files are extremely sensitive (legal, HR, regulated)

Consider a security-first provider designed around encrypted collaboration and policy control (for example Tresorit). You will usually pay more, and the recipient experience can be less frictionless, but the controls may be worth it.

A practical “secure send” setup you can reuse (the 2-minute version)

  1. Create one deliverables folder with a date-based name.
  2. Add a ReadMe.txt listing what is final, what is optional, and the deadline.
  3. Upload using a transfer link tool for one-off delivery.
  4. Set expiry (7 days is a sane default for most handoffs).
  5. Turn on a link password, send password in a separate channel.
  6. Keep your original folder until the client confirms download.

Common failure points (and how to avoid the “can you resend?” loop)

Upload failed at the end

This is usually unstable Wi‑Fi or a laptop sleeping mid-upload. Fixes that help in practice:

  • Use wired or stable Wi‑Fi where possible, and disable sleep until it finishes.
  • Upload in fewer, larger batches (but not one giant zip if you cannot resume uploads).
  • Leave a buffer before your deadline so you can retry.

Client says the link is blocked by IT

Some corporate networks block consumer file-sharing domains. Your options:

  • Ask what is allowed (often Google Drive, OneDrive, or an approved vendor list).
  • Send from a domain they already use (for example their Microsoft/Google environment) if that is the only way through.
  • Offer an alternate format (smaller proxy, PDF, or split archives) if the block is size-related.

They opened it on a phone and now everything is “missing”

Mobile downloads can hide files in strange places, and zip extraction is inconsistent across devices. If the recipient is likely to be on mobile, prefer single deliverable files (one PDF, one MP4) rather than a complex folder tree. If you must send a folder, warn them it is best downloaded on desktop.

Where LetsSend fits (disclosure)

We build LetsSend, so treat this as advice from a team that runs a file transfer service, not a neutral directory. That said, you should pick the tool that matches the job. If you need ongoing collaboration, cloud storage is often the better fit. If you need a clean handoff with automatic expiry, a transfer link tool is usually best.

If you want to send something right now, you can send a file free. To understand the controls (expiry, passwords, download limits), you can see all features and compare Free and Pro (limits and pricing accurate as of August 2026).

Trust and data handling: what to check before you use any service

Before you trust any platform with client work, you should be able to answer: who runs it, how to reach them, and what happens to data after expiry. You can see the team behind LetsSend, contact us, and read how we handle your data. For LetsSend specifically: we do not sell files or contact details, and expired transfers are deleted rather than quietly archived.

One last sanity check before you hit send

  • Open the link yourself in a private/incognito window.
  • Download one file to confirm it is the correct version.
  • Confirm the expiry date matches the recipient’s timeline.
  • Send the password separately (if used).

Do that, and you will avoid 80% of the messy “security” problems that are really just delivery problems in disguise.

Frequently asked questions

What is the safest way to send a file to a client with a password?

Use a transfer link that supports password protection, set an expiry date, and send the password in a separate channel (for example, link by email and password by text). Test the link in an incognito window first so you know the recipient will see the password prompt and the correct files.

Is a password-protected ZIP enough for secure file sharing?

Sometimes, but it is easy to get wrong. ZIP passwords can cause mobile extraction issues, and people often reuse weak passwords. A password-protected link with expiry is usually smoother for clients. If you must use a ZIP, choose strong encryption (AES), use a unique password, and test on the recipient’s likely device.

What should I include in a secure file handoff message?

Include what the files are, which file is the “final” deliverable, when the link expires, and where the password will arrive (sent separately). Add a one-line fallback like “If download fails, tell me your device and I’ll resend.” This prevents the most common back-and-forth.

How long should an expiring download link stay active?

Set expiry to match the job. For proofs and review cuts, 24 to 72 hours is often enough. For typical client delivery, 7 days is a good default. If the recipient is a larger organisation or needs internal approval, consider 14 to 30 days so you do not have to reissue links.

What’s the difference between a file transfer link and a cloud storage share link?

A file transfer link is designed for one-off delivery and usually expires automatically, which reduces lingering access. A cloud storage share link is better for ongoing collaboration where files change, but it can be easier to overshare or leave access open indefinitely unless you manage permissions and cleanup carefully.

When a transfer link expires, are the files deleted?

Not always. Some services only disable the link but keep the files in the background. If deletion matters, check the provider’s data handling and retention policy. For LetsSend, expired transfers are deleted rather than quietly archived, and we do not sell files or contact details.

sending files securely password protected file sharing expiring links client delivery large file transfer

Your files are waiting.

Drop something in and watch it fly. It takes about ten seconds.

Send something