How to See Who Downloaded Your PDF
Oleh Tsyupa · Founder, PDFTrackr
8 min readWhat the download record actually names
A download is one event with two halves, and only one half is ever in doubt. The click is recorded reliably: somebody asked for a copy of a document you were hosting, at a known moment, from a known link. The person is another matter — a link that anyone can open produces an anonymous session, and an anonymous session cannot be made retrospectively named.
So the real question behind “who downloaded my PDF” is narrower than it looks: did the link ask for an identity on the way in? We can put a number on how much that one setting decides, because it is measurable in our own production data.
62% of recorded downloads came with a name — and every one of them was on a link where viewer identification was switched on. Across the 147 sessions on links without it, the number of named downloads was zero.
This is not a statistical finding, and that is what makes it useful: it is structural. A link that never asks for an address has nowhere to record one, so the identity is not weak or partial — it does not exist. The sessions on identified links behaved the same way in reverse: 109 of 111 carried an address. The setting, not the tooling, is what decides.
Based on 258 validated reading sessions across 215 distinct visits, 49 share links and 43 documents, 21 Jul – 4 Aug 2026, extracted 7 Aug 2026 — measured from 17:30 on 21 Jul, the moment download counting went live, so no session that could not have been recorded sits in the denominator. One visit is excluded: a single visitor on a single link produced 210 sessions and 180 download clicks on 29 Jul 2026, a pre-deploy test burst rather than a reader; that day's other 44 sessions stay in. Validated means at least one page rendered and the session was not classified as automated. A named session is one carrying a viewer email address — typed by the viewer, not verified.
One consistency note, since a sibling page publishes a download rate from a narrower cut of the same data. On this wider window 19.4% of validated sessions ended in a download click, against 19.7% measured over 132 sessions in the shorter window published at tracking downloads and views for a shared PDF. The two agree to within a third of a percentage point, which is the reason this page treats the rate as settled and spends its space on the identity question instead.
Method 1 — a tracked link with viewer identification on
This is the method that produces a name, and the reason is unglamorous: it asks. You host the PDF, share it as a link, and turn on the email gate, which requests an address before the document opens. From that point the session is named, and any download click inside it is recorded against that name along with the pages read before it.
Be straight about what the address is worth. A gate records what the viewer typed, and a viewer can type anything — so treat a gated name as a claim rather than proof, and expect some recipients to abandon the gate rather than fill it in. On PDFTrackr there is a second step for the cases where the claim is not good enough: a per-link verification option emails a six-digit code to the address and requires it before the document opens, so the name on the download is one the reader demonstrably receives mail at. The gate, the download count and the per-session name are all on the free plan; the verification step is on Pro. If you want to try the gate on a document you already have, create a free account — it takes about a minute, and the section at the end walks through the settings.
Two smaller things worth knowing before trusting any count, ours included. Some recorded opens are not people at all — corporate mail security fetches links before delivery — and in our own unfiltered data roughly one recorded view in seven had no page engagement at all. PDFTrackr classifies those automated opens, excludes them from your counts, and shows you what it filtered and why — all on the free plan. What no classifier can do is tell you what a real reader did with a copy once they had taken it.
Method 2 — one link per recipient, and no gate at all
When you already know the names, asking for them is friction with no payoff. Send each person their own link instead: the link identifies the recipient, so a download on it is attributable without anybody filling in a form. This is the better method whenever the list is short and enumerable — five clients, twelve investors, a named procurement contact — and it is why the gate is the fallback rather than the default.
Its limit is arithmetic. One link per person is fine by hand at five and tedious at fifty, which is the point where PDFTrackr's Pro plan starts paying for itself: bulk personalised links generate the whole set at once, and per-viewer CSV export gets the resulting list out to wherever you track deals. Free covers the whole job for one document at a time and keeps 50 active links, which is more than most senders ever need; Pro is what you buy once you are sending to enough named people that doing it one link at a time costs you more than the subscription does. You can see what the reporting looks like on the live demo dashboard before signing up for anything.
All six methods, compared on what each one names
Comparisons in this category usually rank by price or feature count. For this question the axis that decides everything is narrower: when a copy is taken, what does the record name — a person, a device, an account, or nothing?
| Method | Names the person? | Records the download click? | Works on an unknown audience? | Set up before sending? |
|---|---|---|---|---|
| Tracked link, identification on (PDFTrackr) | Yes — the address the viewer entered | Yes, tied to the reading session | Yes | Yes — the gate cannot be applied later |
| One tracked link per recipient (PDFTrackr) | Yes — the link is the identity | Yes, tied to the reading session | No — you must know the names | Yes |
| Cloud storage link (Drive) | Not for a PDF — the activity dashboard covers Docs, Sheets and Slides | Sometimes, for signed-in org accounts | No | Yes |
| Google Analytics 4 (file_download) | No | The click only, with no session behind it | Yes | Yes |
| PDF DRM | The licensed viewer, not the person holding it | Yes, and opens afterwards | No — every reader needs a licence | Yes |
| Plain email attachment | No | No | No | Nothing to set up |
Methods 3 to 6, and what each one leaves out
Method 3 — a cloud storage link. This is the method people expect to work, and for a PDF it is weaker than its reputation. Google's activity dashboard — the feature that names who opened a file — is documented for Docs, Sheets and Slides; PDFs are not covered, so a PDF sitting in Drive has no viewer list to read. Where a cloud platform does attribute a view, it attributes it to an account already signed in to your organisation, which is the wrong shape of answer for the case most people are asking about: a document sent to somebody outside the company.
Method 4 — Google Analytics. GA4's enhanced measurement fires a file_download event, in Google's own words,
“when a user clicks a link leading to a file (with a common file extension)”— Google, Analytics Help: enhanced measurement events
That is a click on your website by a visitor Google is measuring anonymously. It is genuinely useful for a PDF you published openly — it tells you which page drove the download — and it is the wrong instrument entirely for a document you emailed to a named person.
Method 5 — PDF DRM. DRM binds a copy to a licensed viewer, so the sender keeps seeing activity after the file has been taken, which none of the other five methods manage. The price is that every reader has to install and licence that viewer, and what the record names is the licence rather than the human using it. If your requirement is control rather than insight, that trade is worth making; if you just want to know whether a proposal landed, it is a heavy tool for a light question.
Method 6 — a plain email attachment. There is nothing to see and no product that changes it. An attachment leaves no hosted copy, so there is no download to record and no session to attach a name to. This is the one case where the answer to “how do I find out who downloaded it” is that the decision was made when you pressed send.
What none of the six methods can do
The honest limits are more useful here than the capabilities, because this is a question where the marketing tends to overreach.
- Follow the copy after it is taken. Nothing reports back from an ordinary downloaded file — a property of a copy on someone else's disk, not a gap in any one product. DRM is a different category rather than a better tracker: it does not follow the copy either, it makes the copy check in with a licence server, and every reader must install that viewer first.
- Name someone who was never asked. Identity is captured at the door or not at all. There is no report that reconstructs it for sessions already recorded.
- Prove the person who typed the address is the person reading. A gate records a claim. Verification raises it to “this reader can receive mail at this address”, which is stronger and is still not identity.
- Tell you a download meant interest. A copy taken and never opened looks identical to a copy taken and read twice. What the reader did before the click — which pages, how long — is the part that carries information, and knowing who opened your PDF covers how to read it.
Setting it up on a document you are about to send
- Upload the PDF and create a share link. The file is unchanged; you are giving it a hosted home so the download click has somewhere to be recorded.
- Decide who needs a name attached, before you send. Turn the email gate on for a list you cannot enumerate, or give each named recipient their own link. Both decisions have to be made before sending; neither can be applied afterwards.
- Leave downloading on only where you want the click counted. Switching downloading off keeps the document inside the viewer, so there is no copy to lose track of and nothing to count.
- Read the download against the reading session it came from. A download on its own says a copy was taken. The pages read before the click are what say whether the person had any use for it — the mechanics of which are covered in how to know who opened your PDF.
All four steps are on the free plan — 500MB, 50 files, 50 active share links, viewer identification, download control and 12 months of history, with no card.
See who took a copy — and what they read first
Share your PDF as a tracked link with viewer identification on, and every download is recorded against a named reading session with page-by-page timing. Free — 500MB, 50 files, 50 links, no credit card.
Start tracking freeFrequently asked questions
How do I see who downloaded my PDF?
Share it as a tracked link with viewer identification switched on before you send it, and each download click is recorded against the address the viewer entered, alongside the pages they read first. If you already know the recipients, give each one their own link instead — the link identifies them with no form to fill in. Neither can be applied to a link you have already sent.
Can you tell who downloaded a PDF after it was downloaded?
For an ordinary PDF, no — the download click is the last thing anybody can see, and that is a property of the copy sitting on someone else's disk rather than a gap in any one product. DRM is the exception on this page: it does not follow the copy either, but it can require the copy to check in with a licence server before it opens, so the sender keeps seeing opens. The cost is that every reader must install and licence that viewer first, which is why it is a different category rather than a better tracker.
Does Google Analytics show who downloaded a PDF?
No. GA4's enhanced measurement records a file_download event when someone clicks a link leading to a file, which is an anonymous click on your website. It can tell you which page drove the download; it cannot tell you which person took the copy, and it sees nothing at all for a PDF you emailed rather than published.
How often does a recorded download actually come with a name?
In our own production data, 62% of recorded downloads carried a name, and all of them were on links where viewer identification was switched on — across the sessions on links without it, the count was zero. The setting decides it, not the tool. (258 validated reading sessions, 21 Jul – 4 Aug 2026.)
Is the email address a viewer enters actually verified?
By default it is a claim, not proof — a viewer can type any address. PDFTrackr has a per-link verification option on Pro that emails a six-digit code to the address and requires it before the document opens, which raises the claim to 'this reader can receive mail here'. That is stronger than an unverified gate and is still not proof of identity.
Can I stop people downloading instead of tracking it?
Yes, and it is often the better answer. Downloading is a per-link permission you can switch off, which keeps the document inside the viewer so the whole reading session stays observable and there is no copy to lose track of. It is on the free plan. What it cannot stop is a screenshot or a photograph of the screen.
Does a download mean the person read the document?
It does not, in either direction. A copy taken and never opened is indistinguishable from a copy taken and read repeatedly. The reading data recorded before the click — which pages were opened and for how long — is the part that carries information about whether the document landed.
Sources
- Google — Analytics Help: enhanced measurement events (file_download definition) (accessed 2026-07-20)
- Google — Activity dashboard help (Docs, Sheets & Slides only; PDFs not covered) (accessed 2026-07-14)
- Microsoft — Safe Links in Microsoft Defender for Office 365 (accessed 2026-07-14)
Keep reading: how free PDF tracking works and why one in seven PDF views is not a real reader.
Oleh Tsyupa
Founder, PDFTrackr
Has analysed over 3,000 tracked document-viewing sessions on PDFTrackr.