Sending unreleased music is a normal part of the job and a genuinely risky one. The awkward truth is that once someone can hear a track, they can record it, and no technology changes that. Everything worth doing is about reducing how easily a file spreads and improving your ability to tell where it went, not about making leaking impossible.
That framing matters, because a lot of advice in this area sells certainty that does not exist. What follows tries to separate the protections that do real work from the ones that mainly make you feel better.
What actually happens to a file you send
An attachment or a download link becomes a copy the moment it arrives. That copy has your original filename, sits in a downloads folder, gets synced to a backup, and is forwarded when your contact wants a second opinion. None of this is malicious and all of it is normal. Within a week, a track you sent to one person may exist in five places you cannot see.
The other thing that happens is that the copy stops matching. You revise the mix, the person you sent it to keeps listening to the old one, and eventually somebody gives you notes on a version you abandoned a fortnight ago.
Stream rather than send, where you can
The single most useful change is sending a link that plays rather than a file that downloads. A stream is not uncopyable, and anyone determined can capture the audio. What it does do is remove the accidental copy, which is how the overwhelming majority of unreleased music actually escapes.
It also keeps one version of the truth. If the link points at the current mix, then everyone is hearing the current mix, and the stale-notes problem disappears without anyone having to manage it.
The protections that do real work
- Download off by default. Turn it on deliberately, for the people who genuinely need the file, rather than leaving it on for everyone.
- An expiry date. Most pitches are live for weeks, not forever. A link that stops working is a copy that never got made.
- The ability to revoke. Things change: a deal falls through, a relationship sours. Being able to kill a link afterwards is worth more than any setting you chose beforehand.
- Knowing who opened it. Not surveillance, just knowing whether the person you pitched to actually listened, and being able to notice when a link is being opened by more people than you sent it to.
- One link per recipient. This is the one people skip, and it is the one that makes the others useful.
Why one link per person matters so much
A single link sent to thirty people tells you nothing when it turns up somewhere it should not be. Thirty separate links tell you exactly which one travelled. It costs almost nothing to do and it is the difference between knowing and guessing.
It also lets you revoke precisely. If one contact leaks, you close their access without disrupting the twenty-nine people who did nothing wrong.
Passwords, watermarks and the theatre problem
Passwords are worth using for genuinely sensitive material and are frequently pointless in practice, because most people send the password in the same email as the link. If you use one, send it separately, or accept that it is mainly a deterrent against casual forwarding.
Audio watermarking, meaning an inaudible marker unique to each recipient, is the real version of this and it is genuinely effective at answering the question of who leaked. It is also more involved than most people need for a demo, and it does nothing to prevent a leak, only to attribute one after the fact. Worth it for a pre-release master going to press. Overkill for a work in progress going to a co-writer.
What is close to pure theatre: disabling right-click, relying on obscure link addresses alone, and anything that assumes the recipient cannot use their phone to record their speakers.
Match the protection to the stage
The mistake most people make is applying one level of caution to everything, which means either irritating collaborators with friction they do not need, or sending a finished master with the same casualness as a rough idea.
- Work in progress to a co-writer or your own team: streaming link, downloads on, no expiry. These people need the file and the friction costs you more than the risk.
- Demos to A and R, sync or publishers: individual streaming links, downloads off, expiry set, opens tracked. This is the everyday case and it is where the habit pays.
- Pre-release masters to press, radio or a wider list: everything above, plus per-recipient watermarking, and a list of exactly who received what.
Before any wide send, ask yourself one question: if this appeared online tomorrow, could I tell who it came from. If the answer is no, you have sent one link to too many people.
The part people forget: taking access back
Access granted is almost never reviewed. Old links stay live for years, pointing at music that has since been released, re-recorded, or shelved for reasons you would rather not advertise. It costs very little to look through your active shares a couple of times a year and close the ones that have done their job.
This is also the moment to check what those links actually contain now. A link created against a song two years ago may be serving a version you have completely moved on from, which is its own kind of problem.
The honest summary
You cannot make unreleased music unleakable, and anyone claiming otherwise is selling something. What you can do is make accidental spread unlikely, make deliberate spread traceable, and make sure the person listening is hearing the version you meant. Those three things are achievable with settings that already exist in most decent sharing tools, including the one we build, and they cover the overwhelming majority of what actually goes wrong.