---
id: KB-TL-021
url: https://app.codecontract.io/help/trackline/i-got-a-link-is-it-genuine
idioma: en
categoria: trackline
audiencia: usuario
nivel: basico
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-TL-003, KB-CO-005, KB-TL-026]
citadoPor: [KB-PS-021, KB-PR-027, KB-PR-031]
---

# I got a link — is it genuine?

_Yes, if you were expecting it from that company. And three ten-second checks confirm it without calling anyone._

**Responde a:** i got an email asking for documents is it safe · is the link they sent me fake · how do i know if a document request is phishing · asked to upload papers to a website

**Short answer: if you were expecting that company to ask you for paperwork, it is genuine.** A Code Contract email always exists because a specific someone —a client, a contractor, an accountant— started a request addressed to you. It never sends itself.

## The three checks, in ten seconds

1. **Does it say which company is asking, and what for?** — A legitimate request names the sender and the document. A scam tends to be vague and urgent.
2. **Does the link go to codecontract.io?** — Check before tapping — hover on a computer, long-press on a phone.
3. **Is it asking for documents, or for something else?** — Here you upload and sign documents. Passwords, card details and transfers are never requested.

> [!IMPORTANT]
> **What this system will NEVER ask you for: your email password, card details, a payment, or to install anything.** If a message claiming to be ours asks for any of those four, it is not ours. There are no exceptions and no special cases, so you do not need to weigh up whether this is one.

## If you are still unsure

**En corto**

- Do not reply to the email: call your usual contact at that company, on the number you already had.
- Not the number in the message — that is exactly what a scam would put there.
- And if nobody at that company knows what you are talking about, delete it and tell them: someone may be impersonating them.

> [!WARNING]
> The rare but real case: **a genuine link you were not expecting**. It usually means whoever started it is someone at that company you do not normally deal with —purchasing rather than your usual account manager— or that the request was meant for a colleague and reached you. One phone call settles it, and it is worth making before uploading anything.

**Do I have to create an account?**

Not to answer a request. You go in through the link.

**What if the link has expired?**

Ask whoever sent it for a new one. It is not your mistake.

**Can I forward it to a colleague?**

Yes, but tell the requester: there will be a record of who uploaded what.

## Ejemplos

**You receive a document request from a client you do work with, but from someone you have never dealt with.**

- Checks the link goes to codecontract.io
- Calls their usual contact to confirm who started it

→ The paperwork goes up with the doubt settled and without having replied to the email.

**A similar message arrives asking for your email password «to verify your identity».**

- Discards it without tapping anything and warns the impersonated company

→ The scam is stopped and the impersonated company finds out in time to warn others.

**A link arrives and nothing was expected from that company.**

- Phones the usual contact before opening it

→ The check happens through a different channel.

**The link asks for data nobody usually requests.**

- Stops and checks before entering anything

→ No data is given to somebody who should not have asked.

**The sender address is similar but not identical.**

- Compares with earlier emails from that company

→ The difference is obvious.

**The request was expected and everything fits.**

- Goes in and uploads what is asked

→ The delivery is resolved the same day.
