Overview
If you're sending content that contains personal or sensitive information, you don't always want it landing straight in someone's inbox. Statements, tax documents, payment summaries, anything with personally identifiable information (PII) — these are the sends where a bit of extra verification goes a long way.
That's what the Require authentication to view attachments setting is for. Tick it on, and any linked attachment in your email becomes gated behind an authenticated landing page. The recipient clicks the link, lands on the verification page, enters the details you've asked for, and only then does the file open.
It's a simple way to give sensitive sends an extra layer of protection without changing how the email itself looks or reads.
Heads up — this only works with linked attachments
Authentication kicks in when attachments are linked rather than attached. If Attach attachments is ticked, the file goes out with the email and there's nothing to log in to. You'll need to untick that setting first.
Find the Email Composition Settings
To get to these settings:
- In the secondary navigation menu, click Applications to view a list of all available Applications.
- Open the Application you want to work in, then click the Details tab.
- Scroll to the Email Composition Settings section near the bottom.
Turn authentication on
- Untick Attach attachments if it's currently ticked. With this off, files are linked from the email body rather than delivered alongside it.
- Tick Require authentication to view attachments.
- Scroll to the bottom of the page and click Save.
That's it — any linked attachment sent from this Application will now sit behind a verification step. Recipients won't see the file in their inbox, just a link, and they'll need to log in before it opens.
What recipients see — the landing page
When a recipient clicks the attachment link in your email, they're taken to an authenticated landing page. This is where they enter the verification details you've asked for, and where the file is delivered once they've checked out. You've got two options for how that page looks.
Learn how to configure a custom landing page
For information on how to add a custom authentication page at an application level, you can learn more in the Configure Landing Page Settings guide.
Set the authentication factors
The setting in Email Composition Settings decides whether authentication is required. What recipients actually need to enter — surname, date of birth, account number, or some combination — is configured in the Security / data retention section of the same Application.
It's worth checking that section before your first send, so you know exactly what your recipients will be asked for when they hit the landing page.
What's next
Once authentication is switched on, send yourself or a colleague a test email and walk through it end to end. You'll see how the email reads, how the landing page presents, and how the file opens once verification clears — all from the recipient's perspective, before anything goes out for real.