Skip to content

What the link in the email proves, and what it doesn't

The signing link is the credential: 192 bits, minted per recipient, sent to one address. It proves whoever signed had that message. It does not prove identity, and a forwarded link carries its access with it. What the record establishes, and what it cannot.

Proof and audit8 min read
A brass chain lying diagonally across a blank cream envelope with its final link left open and unhooked, beside a plain brass key resting on a blue ribbon.

Arriving with a signing link opens the document immediately — no password, no account, no second code. The link is the credential. It is 192 bits of randomness, minted for one recipient and sent to one address, and what it establishes is precisely this: whoever signed had access to the message we sent to that address. It does not establish who they were.

That is a smaller claim than most signing products make, and we would rather state it plainly than let a green tick imply something broader.

How it works

Each recipient on an envelope gets their own token. It is generated from a cryptographically secure source, it is long enough that guessing is not a strategy anybody would attempt, and it appears in exactly one place: the email addressed to that recipient. Opening it starts a session bound to that recipient and that envelope. Nothing else on the account is reachable from it.

The design decision underneath is that a document sent to you should open when you click it. Every additional step between the email and the signature is a place where an agreement stalls, and stalled agreements are the actual problem in this category. Fraud is the rarer one.

What it does establish

  1. Delivery to a specific address. The token existed only inside a message sent to one mailbox.
  2. Possession at the moment of signing. Whoever completed the envelope had that message, or its contents, in hand.
  3. A time-ordered record around it. When the envelope was sent, when it was first opened, from which IP address, with which browser, and when each field was completed.

Taken together that is a chain running from an address you chose to a signature you can point at. In the ordinary case — the counterparty you have been emailing for three weeks opens the link and signs — it is entirely sufficient.

What it does not establish

Written out, because this is the part vendors leave off the page:

  • Identity. Nobody checked a passport. The link proves control of a mailbox, and a mailbox is not a person.
  • That the link stayed with the recipient. A forwarded link carries its access with it. If your counterparty forwards the email to an assistant, the assistant can sign, and the record will look exactly like the counterparty signing.
  • That the mailbox is personal. Shared inboxes are ordinary — accounts@, legal@, a family address — and anyone reading that inbox holds the credential.
  • That the account was not compromised. If somebody else is reading their email, somebody else can sign.
  • Authority to bind an organisation. Whether a person can sign on behalf of a company is a question about their role, and no signing platform has any view on it.
Every one of those limits applies just as squarely to a signature page printed, signed and returned as a phone photograph, which is what the link is competing with. It is a comparison, not an excuse.

Why we record everything anyway

Because attribution is decided on evidence rather than on a single fact. UETA § 9(a) provides that an electronic record or electronic signature is attributable to a person “if it was the act of the person”, and that the act may be shown “in any manner”, including a showing of the efficacy of any security procedure applied.

In any manner is doing real work in that sentence. The statute is not asking for one dispositive proof. It is asking what the whole picture supports. So the audit trail carries the send, the first view, the IP address and user agent on each event, every field completion, the decline if there was one, and the SHA-256 of the finished document. Not one of those is identity. Together they are a story that is difficult to tell any other way.

What happens when somebody actually denies signing is its own question, and has its own piece elsewhere on this site.

When you should want more

The link model is the right default and the wrong choice in a few specific situations:

  • The counterparty is a stranger and the amount is large.
  • The relationship is already adversarial and you expect the signature to be contested.
  • A regulator, a lender or an internal policy specifies verified identity.
  • You are signing in the EU under a rule that calls for a qualified electronic signature, where identity is verified in advance by a qualified trust service provider.

In those cases the honest answer is that you want identity verification we do not perform. The audit trail is not a substitute for it, and we would rather point you elsewhere than sell you a record you would have to over-argue later.

The step we built and turned off

There is a six-digit email code in our codebase. It works. We ran it as the default and then removed it, because it demanded a second email in order to open the first, and the cost — recipients who never received the code, codes landing in spam, envelopes abandoned at the door — was much larger than the single gap it closed. That gap is the forwarded link, and a code sent to the same mailbox does not close it anyway.

It stays in the product as a step-up rather than a default, which is where a control like that belongs.

Try it on a real document

Everything described here is what closeit.fast does on every envelope, including on the free tier. Send one and read the trail it produces.

Start signing free

Your first envelope is three minutes away.

Upload a PDF, place the fields, send the links — and get back a sealed document with a certificate of completion attached to the end of it.

One free envelope every monthNo card, no sales call, no per-signature fee