By Ryan Richardson · Published 8 October 2026
A paid digital product shows signs of being accessed far more often than the purchase count explains, or a delivery link is found circulating somewhere it shouldn't be.
A download link with no expiry works exactly once as intended, for the buyer who received it, and then works indefinitely for anyone who receives a copy of it from that point on. The link itself carries no record of who's allowed to use it or for how long. Nothing has to be stolen or hacked for this to happen; a forwarded email is enough, and the link has no way of telling the difference between the original buyer and the fifth person down the chain.
Gate the file behind a signed link that expires after a few days, long enough that a buyer who opens it on a phone and comes back to finish it on a laptop later is never mistakenly locked out. Reissue the link on request without asking why; the point is to close the long-term forwarding gap, not to interrogate genuine buyers who lost track of an email.
Check whether your own delivery links expire at all. If a link generated at the point of purchase still works months later with no verification step, that's the open gap this failure mode describes, whether or not you've seen evidence of it being shared yet.
| Claim | Value | Source |
|---|---|---|
| Why a permanent delivery link fails and the fix | a permanent link gets forwarded until a paid product is free with extra steps; gate it behind a signed link expiring after a few days, long enough that a phone-then-laptop buyer is never flagged, and reissue on request without asking why | Measured in Real Money, Field Manual |
| Expiry window long enough to not lock out a genuine buyer | a few days, long enough that a buyer who opens on a phone and finishes on a laptop later is never mistakenly locked out | Measured in Real Money, Field Manual |