Practical Guides

How to Share Your Resume as a Link (and What Each Method Leaks)

Six ways to send your resume as a URL instead of an attachment, what each one exposes about you, and the five questions to ask before you publish any resume link.

SP
Satish PophaleFounder of Infinite Resume
September 6, 202611 min read

A resume link is one URL that opens your resume in any browser, on any device, with no download and no attachment. It is the right format when you are talking to a human being: a recruiter on LinkedIn, a hiring manager in an email thread, a referral who asked what you have been working on. It is the wrong format when a job portal asks you to upload a file. That distinction decides almost everything else, and most guides skip it entirely. This is what each way of making that link actually exposes about you, what happens when you want to take it back, and the five questions worth asking before you publish one.

Use a link when a human will open it, and upload a file when software will read it. Applicant tracking systems parse the document you upload; most cannot follow an external URL at all, so a link pasted into an application form is often an empty submission. The same link is genuinely better in an email, a LinkedIn message, or an email signature, because it opens instantly on a phone, needs no download, and can be updated or withdrawn later. When you are unsure which situation you are in, attach the PDF and put the link in the message body underneath. That costs nothing and covers both.

Every method below produces a working URL. They differ on four things that matter after you press send: whether the recipient can actually open it, whether search engines can find it, whether you can revoke it, and how much of your contact detail travels with it.

Cloud storage (Google Drive, Dropbox, OneDrive)

The most common advice, and the one that fails most often. Drive files default to restricted access, so the link works perfectly for you and shows the recruiter a request-access wall. Your access request then lands in an inbox you are not watching while they move to the next candidate. If you use this method, set general access to anyone with the link with the viewer role, then open the URL in a private window where you are not signed in. If it opens there, it works. Two things it still does not solve: the file typically downloads rather than displays on some devices, and your Google account name sits next to the document.

PDF hosting services

Upload a PDF, get a URL. Fast, free at the entry tier, and genuinely convenient. The trade is that you have handed a document containing your phone number and home city to a service whose business model you have not read, on a URL you may not be able to revoke, and which may or may not be crawlable by search engines. Check two things before using one: whether the page carries a noindex directive, and whether deleting the file actually kills the link.

LinkedIn

LinkedIn can store resumes you have applied with and share them with recruiters, and your profile URL is itself a shareable career page. It is the lowest-friction option for people already in your network. It is also not your resume: it is LinkedIn's rendering of a profile, with LinkedIn's layout, LinkedIn's sections, and no control over what a hiring manager sees first. Use it alongside a resume link, not instead of one.

A personal website

The strongest option if you already have one, and a poor use of a weekend if you do not. A page you control can be styled, tracked, and taken down at will. It is also indexable by default, which is a feature for a portfolio and a problem for a document carrying your phone number. If you publish your resume on your own domain, add a noindex meta tag to that page specifically unless you actively want it in search results.

Most builders can publish the resume you already made to a URL. This is the only category where the link and the document stay in sync, because they come from the same source. Watch for three differences between products: whether the free tier includes the link at all, whether view tracking is a paid add-on, and whether the published page is a live mirror of your editor or a snapshot you control. Live mirrors mean an unfinished mid-edit resume can be visible to someone opening an old link.

Still correct in more situations than link-first advice admits. An attached PDF cannot 404, cannot be revoked out from under a recruiter mid-review, needs no permissions, and survives being forwarded internally, which is exactly what happens to a resume that interests someone. The reason to add a link is not that attachments are broken. It is that a link can be updated, measured, and withdrawn, and an attachment cannot.

Ask these of whichever service you pick, including ours. Each one has a factual answer you can verify in about a minute, and each maps to a specific way a resume link goes wrong months after you sent it.

1. Will this page end up in Google?

A resume is a document you send to named people, not a page you publish to the web. Once a page carrying your phone number is indexed, getting it out is a process: you request removal from the site, then separately ask Google to de-list the URL, and the delay between those steps is entirely outside your control. The fix is upstream and takes one directive: the page should carry noindex by default. Check by searching for a distinctive phrase from your resume in quotes a week after publishing.

2. What contact detail is actually in the file?

Your email address, phone number, and home city are the three items that make a resume useful to a data broker rather than a hiring manager. Consumer-protection guidance for job seekers has said the same thing for years: strip precise address detail, and treat a phone number on a public page as a phone number you will be called about by strangers. A resume you email to a named recruiter can carry everything. A resume on a URL you may forward twice should not.

3. Can you actually revoke it?

Revocation is where most sharing methods quietly fail. Deleting a file does not always kill a URL that a content delivery network has already cached, and a link that was cached as public can outlive the delete by hours or longer. Test it: revoke the link, then open it in a private window on a different network. If it still renders, revocation is a label rather than a control.

4. Is the recipient seeing what you meant to send?

A live link that mirrors your editor updates itself while you work. That sounds like a feature until a recruiter opens a link from three weeks ago in the middle of a rewrite. A snapshot is the safer default: what you published is what they see, and updating is a deliberate act. Whichever model your tool uses, know which one it is before you send the link, because the failure only shows up when someone is reading.

5. What does the tracking actually measure?

View tracking is the feature most often sold as a paid tier, and it is worth understanding what a view means before you read anything into the number. Bots, link previews and prefetches inflate raw counts: a single message in a group chat can generate several automated fetches before a person sees it. Unique visitor counts are usually windowed, meaning the same person opening the link on two days counts twice. Treat the numbers as a signal that a link is circulating, not as attendance.

We built our share link around the five questions above, and the answers are deliberately specific rather than reassuring. Publishing is free on every plan. Each resume has its own link, so a link you sent to one company can be revoked without touching any other. How many links you can keep live at once is the one thing the plan decides: the free plan keeps one live at a time, which is the right shape for one active application, and revoking it immediately frees the slot for a different resume. The paid passes publish a link for every resume, which is what you want when you are running several conversations at once.

Noindex by default, and not negotiable

Every published resume page carries index:false, follow:false, noarchive and noimageindex, and no resume URL is ever submitted in our sitemap. The page stays crawlable so that search engines can read the noindex directive, which is the part people get wrong when they reach for robots.txt instead. The link is unguessable rather than secret: a twelve-character random identifier, never your name, so the URL leaks nothing about you if it appears in a browser history or a referrer header.

Contact redaction that is verified, not promised

Redaction is on by default. When it is on, your email address and phone number are masked before the resume is rendered, and mailto and tel links are stripped, so the published file never contains them in any form a scraper can read. The important part is the enforcement: our server does not trust the file it receives. It rebuilds the document from scratch and then checks that your contact strings are genuinely absent from the result before the link goes live. If they are present, the publish is rejected rather than served. A visitor who needs to reach you can pass a bot challenge to reveal your details, which raises the cost of bulk collection without blocking a real person.

A snapshot you control, with a republish prompt

The link shows the version you published, not your work in progress. When you edit the resume afterwards, the share panel tells you the published copy is out of date and offers a republish action, and the public page shows the recipient the date of the snapshot they are reading. You also control whether the PDF download is available at all, and can set the link to expire after 7, 30 or 90 days, or never.

Revocation that revokes

Revoking rotates the internal token, deletes the stored file, and marks the link dead, and every single request for the document re-checks that state on our server rather than being served from a shared cache. That last detail is the one that makes the difference: it is why a revoked link stops working immediately instead of when a cache somewhere decides to expire.

View analytics on a paid pass

Total views, 24-hour unique visitors and the sites your link is being opened from are part of Infinite Pro and Career Season. The link itself stays free on every plan. Tracking works without cookies and without storing your visitors' IP addresses: each view is reduced to a salted one-way hash that rotates every 24 hours, known bots and link-preview fetchers are filtered out, your own visits to your own link are excluded, and every record is deleted after 90 days.

The whole flow runs from the preview screen, and takes about a minute the first time. You can build and download a resume with no account at all; publishing a link needs one, because the link has to belong to somebody who can revoke it.

Step by step

First, finish the resume and open the preview. Second, open the share panel and decide three settings: keep contact redaction on unless the recipient specifically needs to dial you from the page, choose whether the PDF can be downloaded, and pick an expiry that matches the conversation. Third, publish, and copy the link. Fourth, before you send it to anybody, open it once in a private browser window. That single check catches every permission and visibility mistake in this article, whichever tool you used to make the link.

A bare URL in a message reads like a newsletter and gets treated like one. Name the role, say what the link is, and keep the attachment where an ATS or a forward can reach it. One pattern that works: a sentence on the role you are writing about, a sentence on the single most relevant piece of evidence, then the link labelled as your resume with a note that the PDF is attached as well. If you have set an expiry, say so, because a link that quietly stops working looks like carelessness rather than a privacy setting.


Conclusion

The format question is easy: link for people, file for systems, and both when you cannot tell. The harder question is what happens to that link in three months, when the conversation is over, the role is filled, and the URL is still sitting in somebody's inbox. That is what noindex, redaction, expiry and real revocation are for, and it is worth thirty seconds of checking before you send rather than a removal request afterwards. Publish the link, open it in a private window, and know which of your details travelled with it.

Shareable Resume LinkResume LinkResume PrivacyJob SearchRecruitersResume SharingOnline Resume

Ready to Build Your Resume?

Put these insights into action — 100% free, no credit card required.