# Passwords and email access > Decide exactly who can open a link. Source: https://docs.wavdrop.link/protect-links By default, anyone with the link can listen. When that's too open, lock it. Both locks live in the project's **Secure** panel, and a link uses one or the other. | Lock | Who gets in | Plan | | --- | --- | --- | | Password | Anyone who has the link and the password | Plus, Pro | | Email access protection | Only the emails or domains you add | Pro | ## Password 1. Open the project and click **Secure**. 2. Choose **Add password**, type one (4 to 128 characters) and click **Set password**. 3. Send the password separately from the link. Your client sees a password screen before anything plays. Too many wrong tries and they have to wait a few minutes. **Hide details before password** keeps the project name and details hidden until the link is unlocked, including in the preview card that chat apps show for links. Previews already sent in chats keep what they showed. To change or remove the password, choose **Manage password**. > [!NOTE] > Moved to Free with a password already set? The link keeps it, and you can still remove it. Setting a new one needs Plus or Pro. ## Email access protection Only the people you add can listen. Nobody needs an account. 1. Open **Secure**, then **Email access protection**. 2. Add up to 10 entries. Each is an email address (ana@label.com) or a whole domain (*@label.com). 3. That's it. Adding emails doesn't send anything. What your client does: 1. They open the link and type their email. 2. If it's on the list, they get an email with an access link. It works once and expires in 15 minutes. 3. They click it, choose **Continue to listen**, and can listen for about an hour in that browser. After that, they confirm again. The page answers the same way whether or not an email is on the list, so nobody can use it to find out who you work with. Some entries aren't allowed: domains of public email providers (anyone can get a gmail.com address, so it would make the link public) and temporary or disposable addresses. > [!WARNING] > Turning on email access removes the link's password. Removing the last email, or turning email access off, makes the link open to anyone who has it again. WAVDROP asks before it does that. ## Which one should I use? - Sending to one artist who forwards links around? **Email access protection.** - Sending to a team where you don't know every address? **Password**, or email access with their domain. - Quick preview for a trusted contact? No lock, plus a short [expiry](https://docs.wavdrop.link/share-links).