Handle invalid verification or signature links
Respond to a 404 without disclosing alternative records or guessing tokens. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.
Where to goPublic verify/sign URL → 404
Before you start
- Use an authorised account and confirm the customer, external recipient, template, letter or configuration is the intended one.
- Follow the exact route shown above and verify the stored record, generated file and delivery evidence instead of relying on an alert alone.
What you’ll accomplish
Respond to a 404 without disclosing alternative records or guessing tokens. These instructions follow the inspected module’s live hook, route, controller, model, installer, PDF helper and view flow.
Follow these steps
- Check the complete URL was copied without punctuation or line wrapping.
- Ask the issuing organisation to resend the authorised link.
- Staff should locate the record by reference and use Verify or Resend Email.
- Do not enumerate codes or hashes.
Fields and options to review
Action scopeRespond to a 404 without disclosing alternative records or guessing tokens.
Module version1.0.0
Exact routePublic verify/sign URL → 404
EvidenceVerify the history row, PDF, email metadata, open evidence, signature, public page, client view or postal fields produced by this flow.
Rules the system enforces
- Unknown unique_code and hash values produce 404.
- The module provides no public lookup form by verification code.
How to confirm it worked
- The requested letter, template, setting, file or tracking detail is created or updated through the supported route.
- The history row, generated PDF, email/send metadata, public verification, signature evidence, client view or postal display agrees with the action.
- Any warning, missing file or failed send is investigated rather than bypassed.
Security, privacy and operational checks
- Apply least privilege and verify recipient identity before sending or exposing public links.
- Protect PDFs, enclosures, signatures, verification URLs, email-open metadata, IP addresses and customer data under organisational policy.
- Test configuration and deployment changes with controlled records before production-wide use.
- Interpret email opens and e-signatures according to their documented technical limitations.
Continue with related guidance
Was this guide useful?Your response is stored only in this browser.
