It says delivered, but they never got the link

Delivered means their mail server accepted it, not that a human saw it. What each receipt actually proves, why file-sharing emails attract filters, and the fix that always works.

4 min read

You sent the link, the dashboard says it was delivered, and the recipient insists nothing arrived. Both of you are telling the truth: delivered means their mail server accepted it, not that a human saw it.

Here is what the receipts actually mean, why file-sharing emails are treated harshly by filters, and how to get the link in front of someone.

What each status means

  • Sent — handed to the mail provider. It has left, and nothing further is known yet.
  • Delivered — the recipient's mail server accepted it. This is the one people over-read: the message could be in the inbox, in spam, in quarantine, or filed by a rule. The server took it, that is all.
  • Opened — the message was rendered. Useful, and imperfect: many clients block the tracking pixel, so no open does not mean it was not read.
  • Bounced — refused. Usually a wrong address, sometimes a full mailbox, occasionally a server rejecting the whole message.
  • Nothing at all — silence is not failure. A row we have heard nothing about stays as it is rather than being marked failed, because not hearing is not evidence.

So "delivered but they cannot find it" is not a contradiction. It narrows the problem to the last few inches: their spam folder, a filter rule, or a quarantine they never look at.

Why these emails attract filters

A message whose entire content is "here is a link to a file" resembles, structurally, a great deal of phishing. Filters know it.

Several things stack up:

  • A short message with a prominent link is a classic pattern.
  • An unfamiliar sending domain to that recipient.
  • No prior correspondence between the two addresses.
  • Corporate link-scanners that rewrite or follow URLs, sometimes breaking them in the process.
  • The word "invoice", and its relatives, which sit in the most-abused category in email.

None of this means the message did anything wrong. It means the shape is suspicious and the filter is playing the odds.

What to check first

  1. Ask them to search rather than browse. Searching for the sending domain finds a message filed into a folder they never open, which is more common than spam.
  2. Check the spam folder explicitly. "I checked my email" usually means the inbox.
  3. Confirm the address, character by character. A single wrong letter delivers cleanly to a domain that accepts anything, and you get a delivered receipt for a mailbox nobody reads.
  4. Ask about quarantine. In many companies filtered mail never reaches the user at all; it sits in an admin console with a daily digest people ignore.

The reliable fix

Send the link yourself, in a normal message, from your own address.

It sounds like a retreat but it is the most dependable route, and for one recipient it takes seconds. A message from an address they already correspond with, with a sentence of context, passes filters that a transactional email from an unfamiliar domain will not. Copy the link and paste it into your usual mail client or chat.

If you are sending to many people, it is worth doing both: let the service mail the link for the receipts, and tell one or two key recipients directly.

Making the message less suspicious

When you do send it yourself:

  • Say what it is in your own words. Two sentences of context is the single biggest improvement, for filters and for humans.
  • Mention it in advance if you can — "sending the files over shortly" in a conversation you are already having.
  • Avoid a message that is only a URL. That is the most phishing-shaped thing you can send.
  • State the expiry as a date, so an unread message does not quietly become useless.
  • Do not use a link shortener. It raises suspicion, hides the destination, and on an encrypted transfer it can strip the key fragment and break the link entirely.

If it keeps happening to one organisation

Some corporate filters block file-sharing domains as a matter of policy, and no amount of rewording changes that. The tell is that every message to that company disappears while the same link works everywhere else.

At that point the answer is a conversation rather than a technique: ask your contact to have the domain allowed, or agree a route their systems accept. It is worth knowing early, before a deadline depends on it.

Related: a download link is not working for problems once they have clicked, and sharing files with clients for the message itself.