Inbox
Email security

Expected beats familiar

When Is an Email Attachment Safe to Open?

No attachment can be declared safe from appearance alone. Judge the sender, whether the file was expected, the file type, the request around it and whether you can verify the document another way.

9 min read

A PDF icon, a known contact name or a normal-looking filename can lower your suspicion without lowering the actual risk. The better question is not 'does this file look safe?' but 'do I have enough independent reasons to expect this exact file from this exact sender right now?'

Attachment risk is a combination of context and file behavior

SignalLower-risk interpretationHigher-risk interpretation
ExpectationYou asked for this exact documentThe file arrived without any prior context
SenderKnown person using a channel you regularly useNew sender, unexpected address or compromised-looking conversation
FilenameMatches a document you expectedUrgent generic names such as invoice, payroll, scan or notice
File behaviorOpens as a passive document without requesting unusual actionsAsks to enable macros, scripts, editing, external content or software
VerificationYou can confirm through another channelThe email itself is the only evidence the file is legitimate

File extensions do not divide the world into safe and unsafe

Executable files can directly run code, which makes them an obvious concern, but attackers can also use archives, documents, HTML files and other formats as delivery mechanisms. Cloudflare points out that malicious scripts may be buried inside documents or archives and that even familiar-looking file types can carry risk.

That does not mean every ZIP, PDF or document is dangerous. It means the extension is one input. Context, source, expected workflow and the behavior requested after opening matter too.

A safer decision process

  1. 1

    Ask whether the file was expected

    If you did not request it and no real-world event explains it, do not let a familiar logo create urgency.

  2. 2

    Verify the sender independently when the file matters

    Contact the person through an existing chat, known phone number or separate thread rather than replying to the suspicious message.

  3. 3

    Treat unusual enablement requests as escalation

    Requests to enable macros, scripts, editing, external content or security exceptions are reasons to stop and verify.

  4. 4

    Use your organization's security tooling where available

    Managed environments may scan attachments, detonate files in sandboxes or block risky formats before delivery.

  5. 5

    Prefer an independent portal for sensitive documents

    If a bank, payroll provider or cloud service normally stores documents in its official app or site, navigate there directly instead of trusting an unexpected attachment.

A known sender is not a guarantee

Compromised accounts are valuable precisely because they inherit a real sender's identity and conversation history. If a colleague who never sends archives suddenly sends one with an urgent instruction, the account name should increase the value of independent verification rather than remove it.

The same principle applies to invoices and shared documents. A business relationship can be real while a particular message inside that relationship is malicious.

Open an attachment when the file, sender and real-world context agree—not because the filename looks ordinary. When the consequence is high, verify the document outside the email before opening it.

Put this threat in context

Sources and further reading

Need a separate inbox for a short-lived interaction?

Temporary email can reduce exposure of your durable address when future recovery is not important. It is one privacy layer, not a replacement for account security.

Create temporary email

Related security guides