Better Safe Than Sorry

Scams, recalls, safety. Sorted.

Digital hygiene

Safe Email Attachment Habits

Launch library · evergreen read

Photo: Umbrella Revolution Umbrella in Causeway Bay 20141011 by Doctor Ho (CC BY-SA 2.0), via Openverse

Unexpected attachments, even from a familiar name, deserve a genuine second look before opening, since a compromised contact's account is sometimes used to send malware to their own trusted circle of contacts entirely without their knowledge. Even a familiar name is not proof that the message is genuine.

Checking whether the file type genuinely makes sense for the context, such as an unexpected executable file attached to what claims to be an invoice, helps identify a mismatch that is often a clear warning sign. A mismatched file type is often the clearest signal something is wrong.

Contacting the sender through a separate channel, such as a text message or phone call, to confirm they genuinely sent an unexpected attachment adds a simple, effective layer of verification before opening anything at all. This quick call costs little and prevents a potentially costly mistake.

Keeping security software genuinely updated, and being especially cautious of attachments urging you to "enable content" or macros in a document, addresses one of the more common ways malware actually spreads through email. Treating this instruction as suspicious by default is almost always the right call.

Back to the library

Share

Sharing opens the network in a new tab. No tracking scripts are loaded on this page.

Printed from Better Safe Than Sorry. Sources for this article are listed at the end of the page.