Expected beats familiar
When Is an Email Attachment Safe to Open?
No attachment can be declared safe from appearance alone. Judge the sender, whether the file was expected, the file type, the request around it and whether you can verify the document another way.
A PDF icon, a known contact name or a normal-looking filename can lower your suspicion without lowering the actual risk. The better question is not 'does this file look safe?' but 'do I have enough independent reasons to expect this exact file from this exact sender right now?'
Attachment risk is a combination of context and file behavior
| Signal | Lower-risk interpretation | Higher-risk interpretation |
|---|---|---|
| Expectation | You asked for this exact document | The file arrived without any prior context |
| Sender | Known person using a channel you regularly use | New sender, unexpected address or compromised-looking conversation |
| Filename | Matches a document you expected | Urgent generic names such as invoice, payroll, scan or notice |
| File behavior | Opens as a passive document without requesting unusual actions | Asks to enable macros, scripts, editing, external content or software |
| Verification | You can confirm through another channel | The email itself is the only evidence the file is legitimate |
File extensions do not divide the world into safe and unsafe
Executable files can directly run code, which makes them an obvious concern, but attackers can also use archives, documents, HTML files and other formats as delivery mechanisms. Cloudflare points out that malicious scripts may be buried inside documents or archives and that even familiar-looking file types can carry risk.
That does not mean every ZIP, PDF or document is dangerous. It means the extension is one input. Context, source, expected workflow and the behavior requested after opening matter too.
A safer decision process
- 1
Ask whether the file was expected
If you did not request it and no real-world event explains it, do not let a familiar logo create urgency.
- 2
Verify the sender independently when the file matters
Contact the person through an existing chat, known phone number or separate thread rather than replying to the suspicious message.
- 3
Treat unusual enablement requests as escalation
Requests to enable macros, scripts, editing, external content or security exceptions are reasons to stop and verify.
- 4
Use your organization's security tooling where available
Managed environments may scan attachments, detonate files in sandboxes or block risky formats before delivery.
- 5
Prefer an independent portal for sensitive documents
If a bank, payroll provider or cloud service normally stores documents in its official app or site, navigate there directly instead of trusting an unexpected attachment.
A known sender is not a guarantee
Compromised accounts are valuable precisely because they inherit a real sender's identity and conversation history. If a colleague who never sends archives suddenly sends one with an urgent instruction, the account name should increase the value of independent verification rather than remove it.
The same principle applies to invoices and shared documents. A business relationship can be real while a particular message inside that relationship is malicious.
Open an attachment when the file, sender and real-world context agree—not because the filename looks ordinary. When the consequence is high, verify the document outside the email before opening it.
Put this threat in context
Sources and further reading
Need a separate inbox for a short-lived interaction?
Temporary email can reduce exposure of your durable address when future recovery is not important. It is one privacy layer, not a replacement for account security.
Create temporary email