← Back to all posts

Is This Email Attachment Safe? What to Check Before Opening It

To decide whether an email attachment is safe to open, check both the file and the request that delivered it. Confirm that you expected the document, verify unusual instructions independently, and scan the attachment without running it. A familiar sender or a clean malware result does not make every request legitimate.

Blue Lantern Security supports both parts of this review. The Email Analyzer examines the message, while the Static Malware Analyzer provides deeper checks on submitted file contents and structure. The two reports answer different questions.

First, check why the attachment arrived

An invoice you expected from a supplier is different from an invoice demanding an urgent payment to a new account. Even if both files contain no detectable malware, the second request needs independent verification.

Before opening the attachment, ask:

  • Were you expecting this document from this person?
  • Does the actual sender address fit the organization, rather than just the display name?
  • Is the request consistent with the work you are doing together?
  • Are you being asked to change payment details, sign in through the document, or bypass a warning?

Confirm important changes using a phone number or contact method you already have. Replying to the same email is weak verification if that mailbox has been compromised.

Then check the attachment without running it

If you are on a work device, follow your organization's reporting process first. Your security team may want the original message rather than a separately uploaded file.

If you are permitted to handle it yourself:

  1. Keep it closed. Do not run an installer, enable document content, or follow a link to see what happens.
  2. Check the full filename and expected type. A document name ending in .exe or a script extension deserves an explanation. The file's icon is not proof of its format.
  3. Scan with your device's security software. Follow its response guidance if it finds a threat.
  4. Use an approved file-analysis service if needed. Review what it found and what it could inspect before deciding what to do next.

The download-checking guide covers local scans and file identification in more detail.

What should I look for in different attachment types?

Attachment What deserves attention Why the file scan is only part of the answer
PDF invoice or shared document A request to sign in, scan a QR code, or use new payment details The risk may be the action requested, even without an executable payload
Word or Excel document Instructions to enable macros or turn off a protection The sender is asking you to change how the document is allowed to behave
ZIP or another archive An unexpected password, nested files, or an executable presented as a document An archive result does not prove that every item inside was inspected
Executable, script, or shortcut A file you did not request or instructions to run it to view a document Running it can invoke code or commands rather than display an ordinary document
HTML attachment A page asking for credentials or directing you to an unfamiliar service A page can be part of a credential-theft attempt without looking like a conventional virus

These are investigation cues, not a list of formats that are always malicious. Legitimate businesses send PDFs and ZIPs every day. The concern is whether the file and its instructions fit a verified purpose.

Can a PDF attachment be dangerous without containing a virus?

Yes. It can direct you to a phishing page or present fraudulent instructions. Microsoft has documented campaigns using QR codes inside PDF attachments to reach credential-stealing pages.

Consider an invoice that looks ordinary and produces no malware findings, but tells you that a supplier's bank account has changed. A file scan cannot tell you whether those new payment details belong to the supplier. Confirm them through your established process.

Similarly, navigate to a known service independently when a document tells you to sign in. Do not assume that a scanned PDF makes the link or QR code inside it trustworthy.

Should I enable macros to read a document?

Do not enable macros because an unexpected attachment tells you to. Microsoft describes how attackers use internet-delivered Office files to persuade users to enable active content in its guidance on blocking internet macros.

If a business process really needs macros, verify the file and the requirement with the responsible person or administrator. A warning should be resolved through that process, not bypassed to make an unknown document display correctly.

How does Blue Lantern Security check the email and file?

Start with the original email saved as an .eml file if you need message analysis. This preserves information that a screenshot or copied body text cannot provide. The Email Analyzer examines headers, content, links, domains, and attachment types.

The email report's attachment-type check is not a full malware examination of the attachment. For a particular saved attachment, use the Static Malware Analyzer to inspect that file directly, if your organization's policy allows it.

The Email Analyzer also offers an option to submit the same .eml for static malware analysis, creating a separate job. Do not assume that scanning an email container proves every embedded file was extracted and fully inspected. The Email Analyzer documentation explains the submission paths.

For a standalone file, the Static Malware Analyzer accepts uploads up to 4.5 MB. Select the checks, submit the file, and read the report in the Monitoring Hub. It can expose mismatched file types, matched malware rules, suspicious strings, and unusual file regions without executing the upload. The scan-results guide explains how to interpret those findings.

Personal accounts include 30 free daily runs shared across file, email, and URL analysis. Uploaded files and emails are retained for no more than one day, and reports last one week. Metadata about each run is retained indefinitely. Check the privacy policy before uploading confidential correspondence.

What about a password-protected ZIP?

A password is not a sign that the archive is trustworthy. It also changes what an analyzer can inspect. Blue Lantern Security's file-upload form does not accept an archive password, so a report on the encrypted container should not be read as clearance of the contents.

Ask for a verified alternative or have your security team handle it. Do not disable your antivirus or extract an unexpected archive just to make a scanner accept it.

What if I already opened the attachment?

Tell your security contact what happened: whether you only downloaded it, opened it, enabled content, ran a program, followed a link, or entered a password. Those actions call for different investigation steps. Keep the original message available through your approved reporting process.

Follow your endpoint protection's guidance if it reports a threat. If you entered credentials, use a trusted device to reach the real service and secure the account. A clean scan of the attachment afterward does not mean the device or account escaped harm.

Check a suspicious attachment with Blue Lantern Security