Originally published: June 8, 2023 · Last updated: August 17, 2026
An attachment can appear to come from a colleague, customer or familiar company and still be malicious. Email accounts can be compromised, sender names can be imitated and phishing messages are deliberately designed to create enough urgency that the recipient opens the file before verifying the context.
No checklist can prove that an unknown file is harmless, but a few habits reduce unnecessary risk.
Was the attachment expected?
An unexpected invoice, résumé, shared document or “urgent” file deserves verification even when the sender name looks familiar. Microsoft recommends contacting the apparent sender through another method when an attachment is unexpected or suspicious.
Do not reply to the suspicious message itself as your only verification method. Use a known phone number, existing chat thread or independently obtained contact address.
Does the message create artificial urgency?
Phishing frequently relies on pressure: open the invoice now, avoid a penalty, review the document immediately or confirm an account. Urgency is not proof of fraud, but it is a reason to slow down rather than accelerate.
Check the actual file type
A filename can be misleading. Windows and security guidance recommend verifying that the file type matches what you expected. Be particularly cautious with executable files, scripts and archives that hide another file inside.
Do not assume that a familiar document icon proves the underlying file is a harmless document.
Scan downloaded files
Keep endpoint security and antivirus protection current and scan suspicious downloads before opening them. Microsoft specifically recommends scanning downloaded files and only unblocking files from trusted sources.
Security scanning reduces risk but does not make an unexpected attachment automatically trustworthy.
Use preview features where appropriate
For common document types, a mail provider’s protected preview can sometimes let you inspect content without opening a local file directly. This is one additional layer, not a substitute for sender verification.
Be cautious even with known senders
CISA has documented malware campaigns delivered through email attachments and recommends caution even when an attachment appears expected and the sender is known. A compromised mailbox can send convincing messages inside an existing relationship.
Do not enable macros or security bypasses casually
If a document tells you to disable security controls, enable macros or change protected-view settings simply to see the content, treat that as a major warning. Confirm the document independently before changing protections.
If you already opened something suspicious
On a work device, contact the organization’s IT or security team promptly. If you entered credentials after opening a suspicious attachment or link, treat the account as potentially compromised and follow the service’s account-recovery process. Do not hide the incident while waiting to see whether something happens.
Bottom line
The safest question is not “Does this attachment look legitimate?” but “Do I have an independent reason to expect and trust this file?” Verify unexpected attachments, inspect the file type, keep security tools active and avoid bypassing protections to satisfy an urgent email.
Sources: Microsoft: Protect yourself from phishing, Microsoft Attachment Manager guidance, CISA StopRansomware Guide.