What you may not host on PDFLink

The content PDFLink refuses to host, how we find it, how to report a document, and how long we take. Written for the person filing a report as much as for the person uploading.

Last updated 22 September 2026

PDFLink gives anybody an address on the public internet in a few seconds. That is the product, and it is also why this page exists: a service that hands out URLs without asking who you are attracts people who want a URL precisely because nobody asked.

This page says what we will not host, what we do to find it, and how to tell us when we have missed something. If you are here because a PDFLink address was used against you or your brand, skip to Reporting a document — it is the shortest route to having it removed.

What we will not host

Phishing and credential theft. A document designed to lead someone to a page that collects passwords, card details, one-time codes or identity documents. This includes a document that is itself harmless but exists to carry the link — which is the most common abuse of a service like this one.

Malware. Files carrying malicious code, exploits or droppers, and documents that attempt to run a program when opened.

Impersonation. Documents presenting themselves as coming from a person, company, bank or public body they do not come from — invoices, notices, statements, letters of authority.

Fraud. Fake receipts, altered statements, forged certificates, qualifications or identity documents, and documents supporting an advance-fee or investment scam.

Illegal material. Anything unlawful where it is hosted or where it is read. Child sexual abuse material is reported to the authorities, not merely removed.

Abuse of a person. Harassment, threats, doxxing, non-consensual intimate images, and hate speech directed at people for who they are.

Infringement. Material published without the right to publish it, once a valid complaint is made by the rights holder or their agent.

Adult material. Sexually explicit content, paid or free. This is a business decision rather than a moral one: it changes what our domains are classified as, and that affects every other customer's links.

Resource abuse. Using the service as a content delivery network, a file drop for unrelated software, or a way to consume bandwidth at our expense.

Regulated and restricted trades. Unlicensed gambling, counterfeit goods, prescription medicines, weapons, and unlawful ticket resale.

Everything above applies to what a document links to as well as what it contains. A clean PDF pointing at a credential-harvesting page is a phishing document.

How we find it

Every upload is checked before it gets an address. The file must actually be a PDF — header, trailer, cross-reference table and objects — which stops a renamed executable or archive. A document that asks to launch a program is refused outright.

Every upload is scanned for malware with ClamAV and current signatures.

The links inside a document are checked against Google Safe Browsing. A PDF pointing at a page known for phishing or malware does not get an address, and its digest is refused from then on.

Readers can report a document from the viewer, with no account.

We do not read your documents to police their contents, and nobody at PDFLink browses what you upload. The checks above are automatic. Human review happens when a document is reported, or when an automated check flags one.

Reporting a document

Use the Report this document link in the viewer, or write to abuse@pdflink.co with the address. Tell us what is wrong with it; you do not need an account and you do not need to identify yourself.

What happens next:

A report never takes a document down by itself. If that were automatic, any competitor could delete anyone's proposal.

What removal means

A document we remove stops working for everybody holding the link, including whoever we removed it from. The address is never reissued to something else. The file's digest goes on a blocklist, so uploading the same file again will not bring it back — by anyone, on any account.

Repeated breaches end the account. We keep a record of what was removed and why, because we are asked for it by registrars, hosting providers and anti-abuse services, and we would rather answer them accurately.

If we got it wrong

Write to abuse@pdflink.co from the account's email address with the link and why the document does not breach this policy. We will look again. We would much rather reinstate a document than argue about it — but we act first and argue second where phishing and malware are concerned, and we are not sorry about that order.