Skip to content

Guide

Password, email verification or allowlist: which fits your recipient?

A shared document link can be open to anyone, locked with a password, gated behind an email check, or limited to a list of addresses. The right choice depends on three things: how many people you are sending to, how much you trust them, and how much friction they will put up with before they give up and ask you for a PDF instead.

The four modes

  • Public (anyone with the link): no gate. Right for anything you would post on your website.
  • Password protected: the recipient types a password you gave them. Stops strangers, stops search engines, does not tell you who opened it.
  • Email verification: the recipient enters their email and confirms it before the document opens. You learn who opened it. A forward still works, but the forwarder's colleague has to identify themselves.
  • Allowlist (specific emails): only the addresses you listed can pass the email check. A forward to anyone else fails.

Choose by recipient, not by document

The same document can deserve different modes for different people. A one-page overview going to a hundred conference contacts is a public link. The same overview going to three named buyers is an email-verified link. The full pricing proposal going to one buyer's finance team is an allowlist with an expiry.

A simple rule: if you would be embarrassed by a forward, use an allowlist. If you would merely like to know about a forward, use email verification. If you only want to keep strangers out, use a password. If you want reach, go public.

The friction trade

Every gate costs you some opens. A password means the recipient has to find the message you sent the password in. An email check means typing an address and clicking a confirmation. For a warm recipient who asked for the document, that friction is nothing. For a cold prospect, it can be the reason they never open it. When in doubt on a cold send, start lighter and tighten on the second link.

How this maps to scrolly

On scrolly each link has exactly one access mode, chosen when you create it: Public (anyone with the link), Password protected, Email verification, or Allowlist (specific emails). Passwords are 4 to 256 characters. An allowlist takes up to 500 addresses, one per line or comma-separated. Public and password recipients never need an account. Email and allowlist recipients confirm their address, and from then on the analytics show that person by email rather than as an anonymous visitor.

Two habits that make any mode work better

  1. Create one link per recipient when it matters who opened it. Links are cheap; ambiguity is not.
  2. Put an expiry on anything with a price in it. A link that dies on its own is a link you never have to remember to revoke.

FAQ

Frequently asked questions

Which mode should I use for an investor?
Email verification or an allowlist. Both tell you exactly who opened the deck, and an allowlist stops a forward from working at all. Add an expiry so the link dies after the round.
Is a password enough?
A password stops casual access and keeps the link unusable to search engines and strangers. It does not tell you who opened it, and anyone who is told the password can open it. Use it when you trust the group but not the internet.
Can I change the mode after sending?
Each scrolly link keeps its own mode. The usual move is to create a new link with the stricter mode and revoke the old one, so people who already have the old link stop getting in.