When a customer needs a document, attaching it may seem like the obvious option. It can be convenient, but it also creates a copy that remains outside your application. A link keeps the download under your application's control, while introducing another step for the reader.
Consider whether the document changes
A receipt that should remain a fixed snapshot can suit an attachment. A report that is updated regularly may be clearer as a link to the current version. Explain which version the reader is receiving instead of letting the delivery method decide that implicitly.
Think about the user's environment as well. An attachment can be saved for offline use. A link depends on the destination being available and, if needed, on the user being able to authenticate.
Check size before encoding
Sendar's documented single-email API supports up to five attachments with a combined decoded size of 1.3 MiB. Check the original bytes rather than comparing only the length of the encoded string. Encoding adds overhead, and a document that looks small in a preview can exceed the sending limit.
Validate the generated file before including it. Use a meaningful filename and appropriate content type. Ensure the document belongs to the intended recipient and that a failed generation does not attach an empty or unrelated file.
Keep link access intentional
For a private document, use your application's access controls. Do not assume an obscure URL is equivalent to authentication. If you use an expiring link, decide how the user can obtain a fresh one after it expires and communicate that behaviour clearly.
Avoid putting access credentials or unnecessary personal information into the URL. Email scanners and intermediaries may inspect links, so do not make a simple fetch perform an irreversible action.
Test the final combination
Inspect the actual email and document together with a controlled recipient. Verify the attachment opens or the link reaches the intended resource. Test the wrong-account case for protected downloads. The success of the email request alone does not establish that the reader can access the correct document.