Search the Dropbox Watchdog archive
A real dropbox.com share link is a legitimate file host, not a scam by itself. But that legitimacy is exactly what phishers exploit: this archive documents years of criminals hosting credential-harvesting pages on Dropbox's own domain, and building convincing fake Dropbox login pages, so the link — or the email carrying it — looks completely genuine.
Dropbox does give link owners real controls. Its help documentation describes password-protecting a shared link ("Customers on Dropbox Professional, Essentials, Standard, Advanced, Business, Business Plus, and Enterprise can add a password to a shared link on dropbox.com or on the Dropbox mobile app. When someone opens the link, they'll need the password to see its contents"), and setting an expiration date ("People can access the shared link only until the expiration date. After the expiration date, the link is disabled"). Owners can also restrict who a link works for, choosing between "Anyone with link" and "Team members" from the link's "Who has access" setting.
One caveat worth knowing: these settings only bind people who reach a file through the link itself. As Dropbox's own help page puts it, "Link settings, including passwords and other restrictions, apply only to people who access a file or folder through the shared link. Anyone added directly, or who already has access, keeps their existing permissions and isn't affected by link settings."
None of that protects you from a link that was never legitimate to begin with. This archive's entry on the 2024 'BEC 3.0' wave documents Check Point recording thousands of attacks in which criminals hosted credential-harvesting documents on Dropbox itself, so the phishing email genuinely came from [email protected] and sailed past filters that trust the Dropbox domain. Separately, recurring campaigns across 2022–2026 have built convincing fake Dropbox login pages reached via PDF lures and redirect chains, and a 2026 wave used fake OAuth-consent and DocSend-style lures to the same end. And in 2014, researchers found that Dropbox's own shared links to supposedly private documents could leak to third parties through browser referer headers and, in some cases, surface in Google search results.
Practical checks that hold up regardless of who owns the underlying domain: confirm the sender is who you actually expect before opening a shared-link email, hover the link (or long-press on mobile) to see where it really goes before clicking through, and never enter your Microsoft, Google, or Dropbox password on a page you were routed to after clicking a shared-file link — a genuine Dropbox share never requires you to re-authenticate with a different provider's credentials to view the file.
This answer is informational, not legal or security advice. Dropbox Watchdog is independent and not affiliated with Dropbox, Inc.