The most important of the Dropbox link limitations is simple to state and easy to miss: a Dropbox link cannot un-open a document. You can delete the link, change permissions, or move the file, but by the time you do that, anyone who has already opened it may have read it, screenshotted it, or saved a copy to their own machine. A shared link is a convenient way to hand over a file, and for casual sharing it is fine. What it does not give you is genuine, one-click recall of access to sensitive material after the fact, with proof of what happened. This guide explains that gap in plain English, why it matters when the document is a contract, a financial model or a board pack, and how a purpose-built data room closes it. It is general information, not legal advice.
Plenty of teams reach for Dropbox because it is already installed and everyone knows how it works. That is a reasonable instinct for holiday photos and internal drafts. The problem starts the moment the file is confidential and the recipient is outside your organisation, which is exactly when you most want the ability to pull access back. For a fuller side-by-side, see our 99 Data Rooms versus Dropbox comparison. Dropbox publishes its own link and permission controls, and you should check the current feature set on its official site (see Sources).
What a Dropbox link actually controls
A Dropbox shared link points to a file or folder held in Dropbox. Depending on your plan and settings, you can make it view-only or allow editing, set a password, add an expiry date, and disable downloads on some tiers. Those are real controls and they matter. Within the Dropbox environment, they do a decent job of deciding who can reach the file and what they can do while it sits on Dropbox servers.
The limits show up at the edges. First, controls like "disable download" only bind behaviour inside the viewer; they do not stop a determined person taking a screenshot or a photo of the screen. Second, and more fundamentally, a link controls access to the copy on Dropbox, not to copies that have already left it. Once someone downloads a file, or even just opens and reads it, that information is out. Revoking the link afterwards stops future access to the stored copy but does nothing about what the person has already seen or saved. Third, standard link sharing gives you limited, if any, page-level insight into who read what: you may see that a link was opened, but not how long a specific verified person spent on page nine of a twelve-page agreement.
None of this is a criticism of Dropbox as file storage. It is a mismatch between what a sync-and-share tool is built to do and what confidential document sharing actually requires. The same mismatch is why a general shared drive struggles with sensitive material, which we unpack in data room versus shared drive.
Why "revoke" means two different things
When people say they want to revoke a link, they usually mean one of two things, and the difference is the whole point of this article.
The weak version is "stop new people from opening it": you delete or expire the link so the next click fails. Dropbox and almost every sharing tool can do this. It is useful when a document is simply out of date, or when a deadline has passed.
The strong version is "cut off a specific person who already has access, right now, including mid-read, and know it worked". This is what you need when a deal falls through, when the wrong recipient was added, when an NED steps down, or when a document turns out to contain an error you do not want acted on. Here the requirements are stricter: access has to be tied to a verified identity rather than a shareable URL that forwards freely, revocation has to be instant and per-recipient rather than all-or-nothing, and you want a record showing exactly when access was granted and withdrawn. A plain link struggles with all three, because a URL is inherently forwardable and a stored file, once downloaded, is beyond recall. Our explainer on how to un-send a document you already shared walks through what is and is not actually possible here, because honesty matters: no tool can delete a copy already saved to someone else's laptop. What a good tool can do is make sure most viewing happens through a controlled, revocable channel, so that pulling access genuinely stops the ordinary case, and leaves a trail for the rest.
The gap that actually bites: proof and identity
Two capabilities sit underneath real revocation, and a shared link tends to lack both.
Identity is the first. A Dropbox link, unless carefully locked down, is a credential anyone can use: forward it, and the recipient's friend can open the file too. If you cannot tie an open to a named, verified person, "revoking their access" is meaningless, because there is no "their" to revoke. Access control that starts with a verified email and a one-time code changes the unit of sharing from "whoever has the URL" to "this specific person".
Proof is the second. If a confidential document leaks, or a counterparty later disputes what they were shown, you want records: who opened it, when, from where, and what they viewed. A raw link open tells you very little, and it certainly does not distinguish a genuine verified viewer from a bot, a link-preview crawler, or an accidental forward. The difference between a bare "visit" and a "verified" view is more important than it sounds, and we cover it in visits versus verified: what document analytics really show.
How 99 Data Rooms closes the gap
99 Data Rooms is built around the exact thing a Dropbox link cannot do. Instead of a forwardable URL to a stored file, you share a tracked, revocable link that is tied to access control. Before anyone sees the document, you can require a verified email and a one-time code, and on the Business tier you can require an NDA to be accepted first, so the person opening your material is the person you sent it to, not whoever the link was forwarded to. You can read more on our one-click revocation feature page.
While the document is open, page-by-page analytics show you whether it was actually opened, how long was spent where, and crucially whether the viewer was a verified recipient or just a raw visit. If circumstances change, one click revokes access, even for someone mid-scroll: the next time they try to load a page, it is gone. Because sensitive documents are viewed through this controlled channel rather than downloaded and forgotten, revoking genuinely cuts off the ordinary case, and the 24-month audit trail records what happened for the rest. On the Business tier, dynamic watermarking stamps each view with the viewer's identity, which raises the cost of a screenshot leak even where prevention is impossible; the distinction between deterring and preventing a leak is one we take seriously, and we set it out in deterrence versus prevention in document security. All of this lives inside proper virtual data rooms rather than a general file store; see our virtual data rooms feature page.
The honest framing, which matches how we describe every security feature: revocation and analytics are about deterrence and control, not magic. We cannot reach into a laptop and delete a file someone already downloaded. What we can do is make the controlled channel the easy default, so that in the common case, pulling access actually works and you have proof either way. The wider platform is in beta and improving fast, but this loop already runs today.
Do the one thing a Dropbox link can't
If the ability to pull access back matters, you want a tracked, revocable link rather than a forwardable URL. You can try it on the 99 Data Rooms free tier, which is a real tier and not a trial: three rooms, twenty-five active links, forever, no card required. Start for free, share your first document through a controlled link, and revoke it with one click to see the difference for yourself.
Sources
- Dropbox shared link controls, passwords, expiry and permissions (competitor feature reference, check current plan): Dropbox, official site, https://www.dropbox.com/features/share
Can you revoke a Dropbox link after someone has opened it?
You can delete or expire the link so it stops working for future clicks, and you can change permissions. What you cannot do is recall what a person has already read or downloaded: any copy that has left Dropbox is beyond the link's control. That is the core of the Dropbox link limitations covered here. Check Dropbox's current controls on its official site (see Sources).
Does disabling downloads stop a document leaking?
It raises the bar but does not close the door. Disabling downloads keeps the file inside the viewer, yet a determined person can still screenshot or photograph the screen. This is the difference between deterrence and prevention, which we explore in our security guides. Watermarking a view with the viewer's identity is a stronger deterrent than relying on a download toggle alone.
What is the difference between expiring a link and revoking access?
Expiring a link stops new opens after a set time; it is scheduled and impersonal. Revoking access cuts off a specific recipient now, including mid-read, and works best when access is tied to a verified identity rather than a forwardable URL. See how to un-send a document you already shared for what is genuinely possible.
Is Dropbox secure enough for a contract or board pack?
Dropbox is solid file storage with real access controls, and for many internal uses it is fine. For confidential documents shared outside your organisation, the gaps are identity, page-level analytics, and true per-recipient revocation. A purpose-built data room is designed around those needs; a general shared drive is not, as we cover in data room versus shared drive.
Can I see exactly who read my document?
With a plain shared link, usually not in any reliable way. With verified access plus page-by-page analytics, you can tell a genuine verified viewer from a raw visit and see how long they spent on each page. That distinction is explained in visits versus verified.