Learn
How to Share Large Files Securely

Most people first discover the limits of file sharing when an email bounces. You attach a video, a design file, or a dataset, hit send, and get an error telling you the attachment is too large. From that point on, you are improvising. You upload to whatever service comes to mind, paste a link, and hope the recipient can access it. Whether the file is encrypted, whether the link expires, whether anyone else could stumble onto it: these questions tend to come later, if they come at all.
This guide covers the main methods for sharing large files, the security trade-offs of each, and what to look for when you need something more reliable than a quick workaround.
Why email attachments have limits
Email was designed for text messages, not file delivery. Most providers cap attachments at around 25 MB, though some enterprise systems set the limit lower. The reasons are practical: large attachments strain mail servers, fill up recipients' inboxes, and slow down delivery. When you send a 20 MB attachment to ten people, you are creating ten copies of that file across different servers. It is an inefficient way to move data.
For documents, spreadsheets, and small images, email attachments work fine. For anything larger, including video clips, high-resolution photos, design source files, CAD drawings, or datasets, you need a different approach.
Common methods and their trade-offs
There is no single best way to share large files. Each method involves compromises between convenience, security, speed, and cost.
Cloud storage sharing (Google Drive, Dropbox, OneDrive) is the most common approach for most people. You upload a file to your cloud storage, generate a sharing link, and send it. The advantages are clear: most people already have an account, the recipient does not need to install anything, and files stay available until you remove them. The limitations are less obvious. Security depends entirely on the provider and your settings. A link set to "anyone with the link can view" is, in effect, a public URL. If that link gets forwarded, indexed, or leaked, the file is exposed. Provider-side encryption protects files from external breaches but does not prevent the provider itself from accessing your data. For sensitive materials, this matters. You can learn more about how end-to-end encryption works and why it differs from standard cloud encryption.
Dedicated file transfer services (WeTransfer, Hightail, SendAnywhere) are designed specifically for sending files. They are simple: upload, get a link, share it. WeTransfer in particular has become popular for creative work because it handles large files and requires no account from the recipient. The trade-offs are worth understanding, though. Free tiers typically offer no encryption, no password protection, and links that expire after a set period, often seven days. Files sit on the service's servers during that window, and you have limited visibility into who has accessed them. Paid tiers add password protection and longer expiry windows, but the files still pass through and reside on a third party's infrastructure. For a detailed look at how these services compare, see the best file sharing tools for creatives.
USB drives and external hard drives remain relevant, particularly for very large transfers (hundreds of gigabytes or more) or situations where internet bandwidth is limited. A courier with a hard drive can sometimes beat a fibre connection for raw throughput. The security profile is different from cloud methods: there is no transmission to intercept, but there is a physical object that can be lost, stolen, or damaged. If the drive is not encrypted, anyone who finds it can read the contents. For creative professionals working with large video or design files, physical media is sometimes the most practical option, though it introduces its own risks. Fabric's cloud drive offers an alternative for teams who want to avoid shipping hard drives while still working with large files.
FTP and SFTP are older protocols that are still used in some industries. FTP transfers files quickly and can handle very large uploads, but standard FTP sends data unencrypted, including your login credentials. SFTP (Secure File Transfer Protocol) encrypts the connection, making it suitable for sensitive transfers. The main drawback is complexity: setting up and managing an FTP server requires technical knowledge, and recipients need an FTP client. For organisations that already have the infrastructure, it works well. For everyone else, it is more effort than it is worth.
Peer-to-peer and direct transfer tools like Resilio Sync or Magic Wormhole send files directly between devices without storing them on a server. This avoids the question of third-party access entirely, since the file never sits on someone else's infrastructure. The limitations are that both parties typically need to be online simultaneously, and transfer speeds depend on both connections.
Security considerations worth understanding
When sharing files, security is not a single feature but a collection of decisions. Some matter more than others depending on what you are sharing and with whom.
Encryption in transit means the file is protected while moving between your device and the server, or between devices. Most modern services use TLS (Transport Layer Security) for this, which prevents interception during transfer. This is a baseline, not a differentiator. Nearly every reputable service offers it.
Encryption at rest means the file is encrypted while stored on the provider's servers. This protects against breaches of the provider's infrastructure. However, if the provider holds the encryption keys, they can technically decrypt your files. End-to-end encryption, where only you and the recipient hold the keys, offers stronger protection but is less common in mainstream file sharing tools. Fabric uses end-to-end encryption as a default, which means files are encrypted before they leave your device.
Password protection adds a layer of access control to shared links. Instead of anyone with the URL being able to download the file, they also need a password. This is particularly useful when sharing links over channels you do not fully control, such as email or messaging apps.
Expiry links automatically disable access after a set time. This reduces the risk of old links being discovered and used later. For one-time deliveries, an expiry of a few days is usually sufficient. For ongoing collaboration, you need something more persistent.
Access controls let you specify who can view, download, or edit a shared file. The more granular the controls, the better you can manage access. Some services let you restrict access to specific email addresses, while others only offer broad settings like "anyone with the link."
Download tracking tells you who accessed your file and when. This is less about preventing access and more about awareness. For client deliveries, legal documents, or sensitive materials, knowing that the intended recipient downloaded the file, and that no one else did, provides a useful record. Fabric's link analytics track views and downloads on shared files, giving you visibility into how your links are being used.
What to look for in a secure file sharing solution
The right tool depends on what you are sharing, how often, and with whom. A freelance photographer sharing proofs with a client has different needs than an engineering team distributing CAD files across offices.
Start with the basics: does the service encrypt files in transit and at rest? Can you password-protect links? Can you set expiry dates? These features should be standard, not premium add-ons.
Look at file size limits. Some services cap uploads at 2 GB on free plans, which is fine for most documents but inadequate for video, 3D models, or large datasets. If you regularly work with files over 5 GB, check the limits carefully. Video editors and designers often need services that handle files in the tens or hundreds of gigabytes without throttling.
Consider the recipient's experience. If the person you are sharing with needs to create an account, install software, or navigate a complicated interface, you will end up fielding support questions instead of getting feedback on your work. The best sharing tools make the recipient's experience as simple as opening a link.
Think about where the file lives after sharing. Some services store a copy on their servers indefinitely. Others delete it after a set period. If you want the file to remain accessible, you need a service that doubles as storage, not just transfer. If you want it to disappear, you need reliable expiry. Fabric's publish feature lets you share files directly from your cloud storage, so the file is not duplicated onto a separate service. You control access from the same place you store the file.
Finally, check whether the service provides an audit trail. For professional use, knowing who accessed what and when can be important for compliance, client communication, or simply peace of mind.
Enterprise vs personal needs
Personal file sharing is mostly about convenience. You want to send a large video to a friend or share a folder of photos with family. Security matters, but the stakes are lower. A free tier of a cloud storage service usually covers this well enough.
Enterprise file sharing introduces additional requirements. Compliance with regulations like GDPR or HIPAA may dictate where files are stored and how they are encrypted. Centralised administration lets IT teams manage permissions across the organisation. Integration with existing tools, from project management software to communication platforms, reduces friction. Audit logs become essential rather than nice-to-have.
For teams that fall between personal and enterprise, such as agencies, small studios, and freelancers, the challenge is finding tools that offer professional-grade security without the complexity and cost of enterprise solutions. This middle ground is where many people end up cobbling together multiple services, one for storage, another for sharing, a third for collaboration, which introduces its own risks. Every additional service is another set of credentials, another privacy policy, and another potential point of failure. Consolidating your cloud storage into fewer tools can reduce this surface area.
Large file specifics
Different file types come with different sharing challenges.
Video files are often the largest files people need to share. A short 4K clip can easily exceed 1 GB, and project files with multiple tracks and effects can run to hundreds of gigabytes. Compressing video for sharing often degrades quality, which defeats the purpose. Services that support streaming previews, so the recipient can watch without downloading, save time and bandwidth. If you are a content creator or work in video production, your sharing tool needs to handle these sizes without choking.
Design files from tools like Figma, Sketch, Adobe Creative Suite, or Blender can be large, particularly when they include embedded assets, linked libraries, or version history. Sharing the source file is sometimes necessary for collaboration, but sharing a flattened export or preview is often sufficient for review. Knowing when to share which saves time and reduces unnecessary exposure of source materials.
CAD and BIM files used in architecture and engineering can be enormous, especially for complex assemblies. These files also tend to have dependencies, linked files, textures, and libraries, that need to travel with the main file. Sharing a single file without its dependencies produces errors on the receiving end. For creative teams and technical professionals, this means the sharing solution needs to handle folders or packages, not just individual files.
Datasets, whether CSV files, database exports, or research data, can range from megabytes to terabytes. The sensitivity of the data matters as much as the size. Anonymisation, access controls, and encryption are all more important when the file contains personal information or proprietary data. Understanding who owns your data when it sits on a third party's servers is worth considering before uploading.
A practical approach
For most people, the best strategy combines a reliable cloud storage service with good sharing features. Store your files in one place, share from that place, and manage access from that place. This avoids the fragmentation that comes from using separate tools for storage and sharing.
When choosing a service, prioritise security features that match your actual risk profile. If you are sharing holiday photos, convenience matters more than end-to-end encryption. If you are sharing client contracts, unreleased creative work, or sensitive business data, encryption and access controls should be non-negotiable.
Review your sharing links periodically. Old links to files you no longer need to share are unnecessary exposure. Disable or delete them. Use expiry dates where possible so this happens automatically.
And think about the recipient. The most secure sharing method in the world is useless if the person on the other end cannot figure out how to access the file. Balance security with usability, and you will find something that works.
Frequently asked questions
What is the maximum file size for email attachments?
Most email providers set a limit of 25 MB per message, though some enterprise systems use lower limits. Gmail, Outlook, and Yahoo all enforce the 25 MB cap. Files larger than this need to be shared through a cloud storage link, file transfer service, or other method.
Is WeTransfer secure enough for sensitive files?
WeTransfer's free tier does not offer end-to-end encryption or password protection, so it is not suitable for sensitive or confidential files. The paid Pro plan adds password protection and link expiry, which improves security, but files still reside on WeTransfer's servers during the transfer window. For sensitive materials, a service with end-to-end encryption is a better choice.
How can I share a file larger than 5 GB?
Many cloud storage services (Google Drive, Dropbox, OneDrive) support files up to 5 GB or more on paid plans. Dedicated transfer services like Masv or Aspera handle very large files efficiently. For extremely large transfers (hundreds of gigabytes), a physical drive may be more practical than an internet transfer, depending on your upload speed.
What does end-to-end encryption mean for file sharing?
End-to-end encryption means the file is encrypted on your device before it is uploaded and can only be decrypted by the intended recipient. The service provider cannot read the file, even if their servers are breached. This differs from standard encryption at rest, where the provider holds the keys and could, in theory, access the data.
Should I use a VPN when sharing files?
A VPN encrypts your internet connection, which adds a layer of protection when using public Wi-Fi or untrusted networks. It does not, however, encrypt the file itself or protect it once it reaches the sharing service's servers. A VPN is a useful supplement to, not a replacement for, a secure file sharing method.
How do I know if someone has downloaded my shared file?
Some services offer download tracking or read receipts for shared links. This feature is more common on paid plans. Fabric's link analytics, for example, show who viewed and downloaded a shared file. If tracking is important to you, check whether your sharing tool supports it before sending.
What is the safest way to share files with a client?
Use a service that offers password-protected links, expiry dates, and encryption. Share the link through one channel (email) and the password through another (text message or phone call). This way, intercepting one communication does not give access to the file. Restricting access to specific email addresses, where the service supports it, adds another layer.
Can I share large files from my phone?
Yes. Most cloud storage apps (Google Drive, Dropbox, iCloud, Fabric) support uploading and sharing files from mobile devices. The main constraint is upload speed on mobile data connections, which can make large uploads slow. Using Wi-Fi and a service with a mobile app that supports background uploads helps.
How long should a shared link remain active?
It depends on the purpose. For one-time deliveries, a few days to a week is usually sufficient. For ongoing reference materials, a longer or indefinite link may be appropriate, provided you review and revoke access periodically. Using expiry dates as a default, and extending them when needed, is safer than leaving links open indefinitely.
What is the difference between sharing a file and sharing a folder?
Sharing a file gives access to a single item. Sharing a folder gives access to everything inside it, including files added after the folder is shared. Folder sharing is useful for ongoing collaboration but requires more careful management, since anything placed in the folder becomes accessible to everyone with the link. For project-based work, organising files thoughtfully before sharing a folder prevents accidental exposure.