Guide

How to stop your documents being forwarded

Start with the uncomfortable part: you cannot technically prevent someone from forwarding a document they can see.

If a person can read it, they can screenshot it. If they can download it, they can send it. Any vendor promising to make a file un-forwardable is selling you something that doesn’t exist, and you should treat the rest of their claims accordingly.

What you can do is change the economics. Make forwarding traceable, make it consequential, and make the useful version of the document something only you control access to. In practice that stops almost all of it — not through technical prevention, but because the people who might forward it now know you’d find out.

Four things that work, roughly in order of effectiveness.

1. Watermark with the viewer’s identity

The single most effective deterrent, and it’s not close.

Every copy carries the name and email of the person who opened it, stamped into the document itself. Nothing prevents the forward — but the recipient’s name is on every page of the leaked copy, and they know it.

This changes behaviour before it happens. A person who’d casually forward an anonymous PDF thinks twice when their own name is printed across it. And if it does leak, you know exactly whose copy it was — which matters enormously in a competitive process where your underwriting turning up at a rival broker’s desk is a real risk with a real cost.

Automatic per-viewer watermarking is now standard in serious deal platforms. If you’re doing it manually in Acrobat, you’re spending hours on something that should be a setting.

2. Gate access behind an agreement

Require an NDA or confidentiality waiver before anything opens.

The legal value is real but secondary. The behavioural value is bigger: someone who has just actively agreed not to share a document, by name, minutes ago, is markedly less likely to forward it than someone who received an attachment with no ceremony at all.

It also creates a record. If you ever need to enforce, you have a timestamped agreement tied to a named individual and a specific document set — rather than an argument about whether an email footer counts.

3. Share access, not files

The structural fix underneath the other two.

When you email an attachment, you’ve made a permanent copy that exists forever, outside your control, in a place you cannot reach. When you share access to a hosted space, the document stays in one place — and you can change what that place contains, who can reach it, and whether it exists at all.

Practically this means you can:

  • Revoke access the moment a deal dies or a party drops out
  • Update a document without chasing down five stale versions
  • Restrict download, so casual viewers read in-browser rather than acquiring a copy
  • Expire access on a date that suits the transaction

The forwarded link is useless to an unauthorised person if access is per-identity. That is the real mechanism — not stopping the forward, making the forward worthless.

4. Keep an access log

Know who opened what, when, from where, and how many times.

Most of the time this is deal intelligence rather than security. But when something goes wrong it’s the only evidence you have, and the difference between “I think it came from the buyer’s side” and a timestamped record is the difference between a suspicion and a conversation.

What doesn’t work

  • Password-protecting the PDF. The password gets forwarded with the file. It stops nothing.
  • “Confidential — do not distribute” in the footer. A polite request, not a control. Worth including; don't mistake it for protection.
  • Full DRM. Genuine document rights management — locking files to devices, remote-wiping copies — exists, and it's viable if you're a pharmaceutical company. For real estate it's expensive, it makes documents painful to open, and buyers who can't easily read your package simply don't. The friction costs you more deals than the leaks do.
  • Trusting NDAs alone. An NDA is enforcement after the fact. Enforcement is slow, expensive, and requires you to have noticed. Deterrence beats litigation.

What good actually looks like

The realistic target isn’t zero leaks. It’s this:

  • Every copy is traceable to a named person
  • Anyone with access has actively agreed to terms
  • Access can be withdrawn instantly
  • You can see who opened what
  • The friction is low enough that legitimate buyers don't complain

Get those five right and you’ve addressed the practical risk. Chasing technical un-forwardability past that point costs you deals in exchange for a guarantee nobody can honestly give you.

Where this leaves you

If you’re sending a marketing flyer, none of this matters. Send it as widely as you can.

If you’re sending underwriting, rent rolls, tenant details or anything a competitor could use, you want traceability and revocability at minimum. Not because a leak is likely, but because when it happens you want to know whose copy it was.

Shrubs does all four: per-viewer watermarking on PDFs and images — switch it on once and it applies to everything you upload from then on — NDA and waiver gating before access, section-level permissions with instant revocation, and a full access log. Free plan includes 2.5 GB (USD pricing).

See how it works