miinideckmiinideck
PricingUse casesBlog
Sign in
Controls & plans

Does sharing a link put your page on Google? (2026)

Two things people say about unlisted links are both half right. Whether a page gets indexed has almost nothing to do with how secret the address is — it comes down to two questions you can check yourself in about a minute.

By miinideck·August 20, 2026·7 min read
TL;DR
  • Two beliefs are both half right: "unlisted links don't get indexed" and "sharing a link puts it on Google". Neither describes what actually happens.
  • Indexing needs two things: a crawler that can reach the address, and a response that doesn't tell it not to index. Randomness in the URL only affects the first, and only against guessing — not against a crawler following a link somebody posted.
  • The instruction that decides it is noindex, in a meta tag or an X-Robots-Tag header. You can check any page for both in about a minute.
  • robots.txt is not that instruction. It blocks crawling, which can leave a URL listed and prevent your noindex from ever being read.
  • miinideck.com sends noindex on every document by default, in both places, and lets you flip a single page to searchable when that page's job is to be found.

Someone posts a version of this question every week, and it reliably gets two confident answers that contradict each other.

The first: unlisted links are fine, Google can't index what it doesn't know about. The second: anything you publish gets crawled eventually, assume it's public.

Both are describing something real. Neither is a working model, and the gap between them is where people get surprised — usually by finding something in a search result that they thought was quietly sitting at an address only three people knew.

Here is the mechanism, which is less mysterious than either answer suggests.

Indexing needs two separate things to go right

For a page to appear in a search result, two conditions both have to hold.

One: a crawler has to reach the address. Crawlers do not brute-force URLs. A long random address is genuinely not something anything arrives at by guessing — that is what the randomness buys, and it works. What crawlers do instead is follow links from pages they already have. So the address becomes known the moment it appears somewhere crawlable: a forum reply, a public issue tracker, a comment, a Discord that mirrors to the web, a page that lists "resources", a sitemap.

Two: the response has to not say no. When the crawler arrives, the page and its headers can carry a directive. If that directive is present, the page stays out of the index even though it was found, fetched, and read.

Notice what falls out of this. Secrecy of the address only ever affects condition one, and only against guessing. It offers nothing at all against condition one being satisfied the ordinary way — by somebody pasting the link somewhere public. And it never touches condition two.

Which is why the honest version is: an unguessable URL is not an indexing control. It is a reachability control, it works well at that, and it is doing a different job.

What the actual instruction looks like

Two forms, both standard, both honoured by the major search engines.

In the page's head:

<meta name="robots" content="noindex,nofollow">

Or in the HTTP response headers:

X-Robots-Tag: noindex

The header version matters more than it looks. It applies to responses that are not HTML at all — a PDF, an image, a downloadable file — where there is no head to put a meta tag in. It is also harder to lose: a meta tag lives inside content that gets edited, and one careless replacement of a document's markup can drop it. A header is set by the host, on every response, regardless of what the file contains.

The strong setup is both. That is not belt-and-braces paranoia; they cover different cases.

The trap: robots.txt is not this

This is the single most common way people get the outcome they were trying to avoid.

robots.txt says do not fetch these URLs. It is a crawling instruction. And a URL that is never fetched can still end up listed — search engines can index a URL they were asked not to crawl, on the strength of links pointing to it, displaying it with no description because they never saw the page.

Then the second-order problem: because the crawler was never allowed to fetch the page, it never read your noindex tag. You put up the sign and then blocked the road to it.

So the two mechanisms are close to opposites in effect:

You wantUseNot
Page not to appear in resultsnoindex (meta and/or header), page left crawlablerobots.txt block
Crawler not to spend time on a sectionrobots.txt block—
Page not to be readable by peoplepassword, expiry, or don't publisheither of the above

That last row is the one that costs the most when it is missed. Which brings us to a real example.

The July 2026 episode, read properly

In late July 2026, TechCrunch reported that shared Claude conversations and artifacts were turning up in Google, findable with a site: search. Within a couple of days the results were gone.

The interesting part is Anthropic's explanation, because it is correct and it is not a defence. Their position was that the links are "not guessable or discoverable unless people choose to share them themselves", and that they show up in search only when posted somewhere crawlers can see — a forum, a social post.

Both halves of that are true. The addresses were not guessed. People had shared them, in public places, exactly as described. Condition one was satisfied the completely ordinary way.

What that leaves is condition two. Pages that had been legitimately found were then indexed, because nothing in the response asked search engines not to. The unguessable half of the design held perfectly; it was simply never the half that governs indexing.

That is the whole lesson, and it applies to every tool in this category, ours included. Not someone made a mistake — rather, two protections that sound like the same protection are not, and a product that has only the first one will look fine right up until a user pastes their link somewhere public.

On miinideck every document is served with noindex by default — the meta tag and the X-Robots-Tag header — so a link that gets pasted somewhere public stays out of results anyway. When a page's job is to be found, you flip that one document to searchable on purpose.

See how it's set

Check any page in about a minute

You do not have to take a tool's word for this, including ours. Two checks:

The meta tag. Open the page, view source, search for robots. You are looking for a <meta name="robots"> whose content includes noindex.

The header. From a terminal:

curl -sI https://example.com/your-page | grep -i x-robots-tag

Output means the host is sending the directive. No output means it is not — which is fine if the page is meant to be found, and worth knowing if it is not.

If neither is present on a page you assumed was private, nothing has necessarily gone wrong yet. It means the page's status is currently unlisted but indexable, and the only thing standing between it and a search result is that nobody has posted the link anywhere a crawler goes.

Where this leaves the two original answers

"Unlisted links don't get indexed" — true only while nobody publishes the link, which is not a property of the link. It is a bet on human behaviour, and it is the bet that failed in the episode above.

"Assume anything you publish is public" — good instinct, wrong mechanism. It is not inevitable crawling that makes a page public; it is the absence of an instruction. A page that says noindex and is never linked from anywhere crawlable is genuinely not going to show up.

The useful mental model sits in between: reachability is about who shares the link, indexing is about what the host says, and privacy from actual humans is a third thing entirely — a password, an expiry, or not publishing it at all.

Three separate dials. Most of the confusion in this topic comes from tools, and articles, that present them as one.

More in Controls & plans

Which of your Claude shares are public — and what unsharing actually undoes (2026)

Sharing a chat creates a snapshot anyone with the link can open. Unsharing disables that link. Neither of those is the same as 'not indexable', and the difference caught a lot of careful people in July 2026. Here's the mechanism, where to check your own shares, and when you need noindex to be a property of the link itself.

July 30, 2026·8 min read

How to Make a Shared Link Self-Destruct on a Schedule (2026)

A scheduled self-destruct retires a shared link on a date you set at upload — no reminder, no manual deletion. Here's why scheduling beats deleting by hand, how to pick the date, and what the viewer sees when the link retires.

September 6, 2026·6 min read

"A secret URL isn't real security" — what that objection gets right, and where it stops

Ask an AI assistant how to share a page privately and it will usually warn you that an unguessable URL is not real privacy. Half of that warning is correct. This is the half that isn't, the threats a random link genuinely does not cover, and the point where you should stop and put a login in front of it instead.

August 23, 2026·9 min read

Send your own private link.

miinideck turns a single HTML file into an unguessable link with optional password and expiry. Default-private, never indexed.

See pricingTry it free →
miinideck

HTML files, finally as links — for AI builders, agencies, and consultants. Default-noindex, default-private, default-yours.

Product

  • Pricing
  • Use cases
  • Try it free

Resources

  • Blog
  • Free tools
  • Featured on
  • Report abuse

Legal

  • Privacy
  • Terms
Listed onmiinideck listed on Product Huntmiinideck listed on Faziermiinideck listed on TheSaaSDirmiinideck listed on AIToolHuntmiinideck listed on LaunchNest
© 2026 miinideckMade for people who don't want their work indexed.