When Is It Safe to Open an Unexpected Email Attachment?

An unexpected email attachment is safe to open only after you verify the real sender outside the message, confirm that the file type fits the situation, see no warning from your mail provider or device, and refuse any request to scan a QR code, enable macros, or bypass protection.

Published on
Last updated on
14 min read
Oliver Jackson

Email Marketing Specialist

Michael Bodekaer

Founder, Board Member

Jose Lopez

Head of Growth Engineering

Authored By Oliver Jackson Email Marketing Specialist

Oliver is an accomplished email marketing specialist with more than a decade's worth of experience. His strategic and creative approach to email campaigns has driven significant growth and engagement for businesses across diverse industries. A thought leader in his field, Oliver is known for his insightful webinars and guest posts, where he shares his expert knowledge. His unique blend of skill, creativity, and understanding of audience dynamics make him a standout in the realm of email marketing.

Reviewed By Michael Bodekaer Founder, Board Member

Michael Bodekaer is a recognized authority in email management and productivity solutions, with over a decade of experience in simplifying communication workflows for individuals and businesses. As the co-founder of Mailbird and a TED speaker, Michael has been at the forefront of developing tools that revolutionize how users manage multiple email accounts. His insights have been featured in leading publications like TechRadar, and he is passionate about helping professionals adopt innovative solutions like unified inboxes, app integrations, and productivity-enhancing features to optimize their daily routines.

Tested By Jose Lopez Head of Growth Engineering

José López is a Web Consultant & Developer with over 25 years of experience in the field. He is a full-stack developer who specializes in leading teams, managing operations, and developing complex cloud architectures. With expertise in areas such as Project Management, HTML, CSS, JS, PHP, and SQL, José enjoys mentoring fellow engineers and teaching them how to build and scale web applications.

When Is It Safe to Open an Unexpected Email Attachment?
When Is It Safe to Open an Unexpected Email Attachment?

An unexpected email attachment is safe to open only after you verify the real sender outside the message, confirm that the file type fits the situation, see no warning from your mail provider or device, and refuse any request to scan a QR code, enable macros, or bypass protection. [1] [2] [5] [8] [11]

You can usually make that call quickly with the tools already built into your email account, Windows PC, or Mac. The safe default is still “not yet,” not “probably fine.”

What’s new

On , the FBI warned that Kimsuky phishing campaigns were using QR images in email attachments or embedded graphics to bypass traditional email security controls. In other words, even a file that looks like a harmless image can be the first step in an account-takeover attempt. [1]

TL;DR

  • Verify the real sender outside the email.
  • Confirm the file type makes sense.
  • Check for provider or device warnings.
  • Refuse QR, macro, or bypass prompts.
  • Save first. Scan on Windows or check the file type on Mac.
  • If still unsure, report it, delete it, and move on.

What can change: blocked file lists, warning banners, and download screens change over time. If your Gmail, Outlook, Windows, or Mac warning looks different from the examples below, trust the warning and check the latest help page before you open anything. [5] [6] [10] [11] [12]

Table of contents

Before you open anything

  • What you need: the email message, a way to contact the sender outside that message, and your device’s built-in security tools.
  • Works with: Mailbird, Gmail, Outlook, webmail, mobile mail apps, Windows, and Mac.
  • Time: usually just a quick check.
  • Cost: usually none if you use the tools already on your device.
  • Fallback option: if you cannot scan the file yourself, verify the sender first and ask them to resend it as plain text, a standard PDF, or a cloud share from their usual account.
  • Safety note: do not double-click the file, scan any QR code in the message, or type a password the email gives you until the sender and file are verified.

If this is a work account, your company’s rule wins. Use the steps below as the default when no stricter rule exists. [1] [2] [5] [8] [11]

How to check an unexpected email attachment safely

How to check an unexpected email attachment safely

  1. Freeze the file where it is

    Do not double-click the attachment, tap “Open,” scan a QR code inside the message, or enter a password supplied in the email. If the file starts opening automatically, close the app before you click anything inside the document. [1] [3]

  2. Ask the three context questions

    Ask yourself: was I expecting a file from this person, was I expecting it now, and does this file type make sense for the reason they emailed me? If any answer is “no,” treat the attachment as untrusted until you verify it. [2] [3] [11]

  3. Inspect the full sender address and the thread context

    Expand the sender name so you can see the full address and reply-to, then compare it with an older legitimate message or the organization’s real website. If you use Mailbird, Attachment Search can take you back to the conversation the file came with, which makes it much easier to spot a message that is out of context. [2] [3] [13]

  4. Check the same message in your provider’s webmail view if anything feels off

    If you normally read mail in Mailbird or another desktop app and the message looks even slightly odd, open the same email once in your provider’s webmail view. Gmail warns about unverified scripts and encrypted attachments. Outlook.com can show safety bars and trusted-sender indicators. Treat any warning or blocked download as a hard stop. [5] [7] [12]

  5. Reveal the real file type before you open the attachment

    Make sure you can see the file extension. Reject mismatches such as invoice.pdf.exe or photo.jpg.js . Program, script, disk-image, and password-protected archive types are higher risk. Gmail blocks many of them, including .exe , .js , .iso , and documents with malicious macros. [6]

  6. Save first, then check the file on your device

    Download the file without opening it from the message. On Windows, right-click the saved file and choose Scan with Microsoft Defender . On Mac, select the file in Finder and open Get Info , then confirm the Kind matches the document you expected—not an Application, Script, or another executable type. If the type is wrong, delete it. [9] [10] [11]

  7. Verify the sender on a different channel

    Call, text, or start a brand-new message using contact details you already know are real. Ask a specific question, such as “Did you send me a PDF named invoice-4831 today?” Do not use the phone number, link, or reply address inside the suspicious email. [2] [3] [14]

  8. Ask for a safer version if the file still feels odd

    If the sender is real but the file still looks unusual, ask them to resend it as plain text in the email body, a normal PDF, or a file share from their usual account. Be extra cautious with password-protected attachments, because encrypted or archived content may not be scanned by your email provider. [5] [6]

  9. Open it once, carefully, and never bypass a warning

    If the sender verified it and the file type matches, open it after the scan or device check. If Word, Excel, or PowerPoint asks you to Enable Content or Enable Macros , close the file. If a PDF or image asks you to click a link, sign in, or scan a QR code, stop and go to the real website yourself instead. [1] [8] [11]

  10. If you already opened it, contain the damage fast

    If the file launched something, asked for credentials, or anything about the device suddenly feels wrong, disconnect the device from the network, update your security software, and run a full scan. On Windows, a full scan or Microsoft Defender Offline is intended for times when you think the device may have been exposed to malware. Change any compromised passwords from a clean device, then alert your IT team if this is a work account. [4] [14] [15]

  11. Report it and clean up

    Mark the message as phishing or spam in your mail service, forward phishing emails to reportphishing@apwg.org , report the attempt to the FTC, and then delete the message. If the file turns out to be legitimate, save it in your normal folder and keep the verified thread for reference. [3] [4] [5]

Why this email attachment check works

Most attachment attacks still need one of three things from you: trust in the wrong sender, permission to run active content, or a login after you open the file. This checklist checks those three points in order, using the same warning systems built into major mail providers, Windows, Mac, and Microsoft 365. That turns a vague “looks okay” decision into a short set of hard stops. [1] [8] [14]

Troubleshooting suspicious attachment warnings

Common suspicious attachment problems and what to do
Symptom Likely cause Fix
The sender “confirms” by email, but the address still looks different Spoofed address or a compromised mailbox Call or text a saved number and ask them to resend the file from the address you already know. [2] [14]
The attachment is a ZIP or RAR file and wants a password Encrypted contents may not be scanned Ask for a secure portal, a cloud share from the sender’s usual account, or a normal PDF instead. [5] [6]
Office asks for “Enable Content” or “Enable Macros” The file contains active content Close it and ask for a PDF, screenshot, or pasted text. Do not enable macros. [8] [11]
Windows says the file came from another computer and might be blocked Windows marked the download as potentially unsafe Verify the source, scan the file, and only unblock it if you trust it. [11]
Finder shows the file as an Application or Script on a Mac A program is pretending to be a document Delete it and ask the sender to resend the real document format. [10]
Gmail or Outlook shows a warning bar or blocks the download The provider sees risk or cannot fully scan the file Do not force it. Verify the sender and ask for a safer delivery method. [5] [7] [12]
You opened it and something odd happened right away Possible malware execution or credential theft attempt Disconnect from the network, run a full or offline scan, change passwords from a clean device, and contact IT if it is a work account. [14] [15]

Common suspicious attachment problems and what to do

The sender “confirms” by email, but the address still looks different

Likely cause: Spoofed address or a compromised mailbox

Fix: Call or text a saved number and ask them to resend the file from the address you already know. [2] [14]

The attachment is a ZIP or RAR file and wants a password

Likely cause: Encrypted contents may not be scanned

Fix: Ask for a secure portal, a cloud share from the sender’s usual account, or a normal PDF instead. [5] [6]

Office asks for “Enable Content” or “Enable Macros”

Likely cause: The file contains active content

Fix: Close it and ask for a PDF, screenshot, or pasted text. Do not enable macros. [8] [11]

Windows says the file came from another computer and might be blocked

Likely cause: Windows marked the download as potentially unsafe

Fix: Verify the source, scan the file, and only unblock it if you trust it. [11]

Finder shows the file as an Application or Script on a Mac

Likely cause: A program is pretending to be a document

Fix: Delete it and ask the sender to resend the real document format. [10]

Gmail or Outlook shows a warning bar or blocks the download

Likely cause: The provider sees risk or cannot fully scan the file

Fix: Do not force it. Verify the sender and ask for a safer delivery method. [5] [7] [12]

You opened it and something odd happened right away

Likely cause: Possible malware execution or credential theft attempt

Fix: Disconnect from the network, run a full or offline scan, change passwords from a clean device, and contact IT if it is a work account. [14] [15]

Common situations

If it came from a coworker or vendor you know

Do not rely on the same thread. Call the number already in your contacts or a prior signed document, and verify the exact filename and why they sent it now. [2] [14]

If it claims to be from your bank, payroll service, or a delivery company

Skip the attachment first. Open the official site or app you normally use and look for the alert there instead of entering through the email. [3]

If the file is “just” a picture or PDF with a QR code

Treat it like a link, not a picture. Do not scan it until the sender and purpose are verified outside the message. [1]

If you manage several accounts in Mailbird

Use Mailbird’s Attachment Search to jump back to the original conversation the file came from, and exclude spam attachments while you sort through files. [13]

If you are stuck on a phone

Do not treat the phone as a safety shortcut. Flag the message, then check it later on desktop or in your provider’s webmail view where you can inspect the full address and the real file type more easily. [1] [5] [12]

Set it up once: habits that make unexpected attachments less risky

For your own inbox

  • Keep automatic updates on so your operating system, browser, and security software.
  • Keep file extensions visible so fake names are easier to spot.
  • Save real phone numbers for your bank, payroll provider, top vendors, and frequent contacts.
  • After a file is verified, move it out of Downloads into your normal folder structure.
  • Keep a backup that is not always connected to your computer.

Updates and separated backups make one bad attachment much less costly. [14] [15]

For a team

  • Set one simple rule: nobody opens unexpected attachments until sender verification happens outside email.
  • Create one shared path for reporting suspicious messages.
  • Ask vendors to use consistent sending addresses and predictable file formats.
  • Tell people to report the message even if they are only “pretty sure” it is fake.

A simple team rule catches a large share of ordinary phishing attempts before anyone clicks. [2] [14]

Frequently Asked Questions about unexpected email attachments

How can I tell if an unexpected email attachment is safe?

It is safe only after you verify the real sender outside the email, the file type makes sense, the file is not flagged by your provider or device, and the document does not ask you to turn off protections or enable macros.

Sources: [2] [5] [8] [11]

Is it safer to open the email but not the attachment?

Usually, yes. But stop at reading only enough to inspect the sender and context. Do not click links, buttons, images, or the attachment itself.

Sources: [3] [5]

Are PDF email attachments safe?

Safer than obvious program files, usually, but not automatically safe. A PDF can still try to push you to a bad link, a fake login, or a QR-code scam.

Sources: [1] [10]

What if the sender is someone I know?

That helps, but it does not prove the message is real. People get spoofed, and real inboxes get compromised. Verify the file through a different channel first.

Sources: [2] [3]

What if the attachment is password-protected?

Treat it as higher risk until verified. Encrypted or archived content may not be fully scanned by your mail provider.

Sources: [5] [6]

Should I open it on my phone instead of my computer?

No. A phone is not a safety shortcut. Some phishing attacks are specifically designed to move you onto a mobile device with a QR code.

Sources: [1]

What should I do if I already opened it?

Disconnect if anything started running, update your security software, run a scan, change affected passwords from a clean device, and report it if this is a work or sensitive account.

Sources: [4] [14] [15]

Can antivirus alone tell me an email attachment is safe?

No. Filters and antivirus help a lot, but they do not replace sender verification, file-type checking, and warning prompts from your device or email provider.

Sources: [5] [7] [11]

Quick email attachment safety checklist

  • Stop. Do not open the file, scan a QR code, or type a password from the email.
  • Ask: was I expecting this sender, this file, and this timing?
  • Expand the full sender address and reply-to.
  • If anything feels off, check the same message in your provider’s webmail view for warning bars.
  • Reveal the file extension. Reject program or script files and any macro prompt.
  • Save first. Scan on Windows or check the file type on Mac.
  • Verify on a known phone number, text thread, or new email—not by replying to the suspicious message.
  • If still unsure, report it, delete it, and move on.
  • If you already opened it, disconnect, scan, change passwords from a clean device, and tell IT if it is work mail.

These are the fastest checks worth memorizing. [2] [3] [5] [8] [11]

Mailbird brings this into one desktop inbox for Windows and Mac, so you can set it up in minutes.

Sources

  1. FBI — North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities (Jan. 8, 2026)
  2. Microsoft Support — Protect yourself from online scams and attacks
  3. FTC Consumer Alert — Protect yourself from phishing scams
  4. FTC Consumer Advice — How To Recognize and Avoid Phishing Scams
  5. Gmail Help — Open & download attachments in Gmail
  6. Gmail Help — File types blocked in Gmail
  7. Gmail Help — Anti-virus scanning attachments
  8. Microsoft Support — Enable or disable macros in Microsoft 365 files
  9. Microsoft Support — Scan an item with Windows Security
  10. Apple Support — Safety tips for handling email attachments and content downloaded from the Internet
  11. Microsoft Support — Information about the Attachment Manager in Microsoft Windows
  12. Microsoft Support — Help protect your Outlook.com email account
  13. Mailbird Help Center — Attachment Search
  14. FTC — Phishing (Cybersecurity for Small Business)
  15. Microsoft Support — Virus and Threat Protection in the Windows Security App