Skip to content
HexaTransfer
Back to blog
File Transfer

Broken Download Link Fix: Troubleshoot File Sharing URLs

Download link not working? Troubleshoot broken file sharing URLs with common fixes for expired links, permission errors, and access restrictions.

A broken download link falls into one of six buckets: expired link (server deleted the file), truncated URL (email client cut it at a hyphen or pasted only part), password required (recipient wasn't given the password), geo or IP blocked (corporate firewall, country restriction), service outage, or link mistyped/regenerated. The browser error tells you which: "404 Not Found" is usually deletion or mistype, "403 Forbidden" is permissions, "410 Gone" is explicit expiry, and a plain timeout is often a network or firewall issue on the recipient's end.

Start with the exact error

Open the link, note the status code or error message verbatim. If the browser shows a service's branded "link expired" page, the file is gone server-side and no troubleshooting will recover it. If the browser shows a generic "can't reach this site" or DNS_PROBE_FINISHED_NXDOMAIN, the issue is the recipient's network, not the link itself.

Ask the recipient to screenshot the error page. That one screenshot eliminates 80 percent of the back-and-forth guessing.

Check for URL truncation

Email clients, especially older Outlook and some corporate Gmail setups, sometimes truncate long URLs when they wrap at certain characters (underscores, hyphens, equals signs). The link looks right in preview but pastes incomplete.

Send the link three ways: as a hyperlink in the email body, as plain text wrapped in < > brackets (RFC 3986 style, which most email clients recognise), and as a copy-pasteable code block. If the recipient clicks the hyperlink and it fails but the text-pasted version works, the culprit was the email client's link parser.

WhatsApp, Signal, iMessage, and Slack handle URLs more reliably than email for long tokenised links. A quick Signal message with the link is often the fastest fix.

Password and access control issues

If the link is password-protected and the recipient doesn't have the password, they'll see a password entry screen, not a broken link page. Confirm they received it. Share the password through a second channel (SMS, Signal, or voice call) separate from the email that carried the link, both for security and to avoid the same inbox filtering both.

If the service supports per-recipient access control (Google Drive, OneDrive with "specific people"), verify the recipient's email matches what you granted access to. A typo or an alias (hotmail.com vs outlook.com) will block access silently.

403 Forbidden and IP restrictions

Some transfer services geo-block or IP-restrict by default on certain plans. Dropbox Business and Google Workspace can be configured to restrict sharing outside the organisation's domain. If the recipient is on a corporate VPN that routes through a different country, geo-restriction may trigger.

Ask the recipient to try from a different network (their phone on cellular, for instance). If it works off-VPN but fails on-VPN, the corporate network is the block.

Service outages

Check the service's status page before diving into other fixes. WeTransfer, Dropbox, Google, and Microsoft all publish status pages. A major outage can make every link on that service unreachable for hours.

Downdetector.com aggregates user reports if the service doesn't publish status publicly. If you see a surge of reports in the last 30 minutes, wait 30 more minutes and retry rather than regenerating everything.

Expired links: the file is probably gone

If the service explicitly says "expired" or "link no longer active," the file has been deleted server-side on most consumer transfer tools. Recovery from the service isn't an option because they've already purged the object from their storage to comply with GDPR's data minimisation principle (Article 5(1)(e)).

Re-upload from your source. If you don't have the source, check backups (Time Machine, Backblaze, Carbonite, your NAS). Don't waste time asking support to "recover" an expired transfer on free tiers; the answer is always no because they literally cannot.

Mistyped or regenerated links

Transfer URLs typically contain a 20 to 40 character random token. Misspellings don't return "did you mean?" pages, they return 404. Make sure the recipient is using the exact URL you sent, not a hand-typed version from a screenshot.

If you regenerated the link (some services offer "new link" for the same file), old links stop working immediately. Confirm the recipient is using the latest URL.

Antivirus and proxy blocking

Some corporate antivirus tools (Symantec Endpoint, McAfee, Sophos) classify file transfer domains as "file sharing / uncategorised" and block them by policy. The recipient sees "this site is blocked by your security policy" or a browser timeout.

Ask IT to allowlist the specific service. If that's not possible, the recipient can try from a personal device or home network, or you can re-send through a service their organisation does allow (often Box or Dropbox Business if they use it internally).

Browser cache and cookie issues

Rare, but sometimes a stale cookie from a previous session interferes. Have the recipient try incognito/private mode first. If the link works in incognito but fails in their normal browser, have them clear cookies for the transfer service's domain.

Safari's "Prevent cross-site tracking" can also interfere with some services that rely on third-party cookies for download session tracking.

Try an incognito window, different browser, different device

The three-step recipient check: (1) same browser, incognito mode; (2) different browser (if Chrome, try Firefox or Safari); (3) different device (phone on cellular). If any of those three work, the issue is browser-specific or network-specific and you now know where to dig.

If none of them work, the link is genuinely broken server-side and you need to re-upload.

Re-upload to a service with clearer status

If this keeps happening, consider a service whose download page clearly tells the recipient what's wrong (password required vs expired vs service error) rather than a generic 404. HexaTransfer's download UI shows explicit states for password-protected, expired, and deleted links so your recipient can self-diagnose without pinging you, and the 10 GB per-transfer ceiling with AES-256-GCM encryption covers most confidential sends.

Try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file