Is this email attachment safe?
If you were not expecting the attachment, do not open it first.
Check the sender, the domain, the file type, the timing, and what the email wants you to do. A fake invoice can look boring. That is part of the problem.
The attachment check
| What to check | Why it matters |
|---|---|
| Sender domain | Display names are easy to fake |
| File type | ZIP, executable, macro document, or strange link is riskier |
| Context | Were you expecting this invoice, contract, resume, or tax file? |
| Payment details | Did bank details suddenly change? |
| Login request | Does the file push you to a fake sign-in page? |
| Urgency | Is it trying to make you open before checking? |
Common attachment traps
Fake invoice
The email says an invoice is attached. The sender name looks familiar. The risky part is the attachment, the payment details, or a link to "download" the invoice.
Fake tax document
The message mentions tax, refund, penalty, or account status. It may use your real name or business details.
Fake brand deal or contract
Creators and small businesses see this often. The sender asks you to download a "brief," "contract," or "media kit" from a strange domain.
Fake security notice
The attachment says your account, mailbox, or device is at risk. It usually wants a login or code.
If the attachment sent you to a login page, treat it like a link problem too: how to check a link without clicking it.
What to do instead
- Contact the sender through a known channel.
- Open the vendor portal yourself.
- Do not enable macros.
- Do not open ZIP files from unexpected emails.
- Do not log in through the attachment link.
- Ask IT or a trusted person if this is for work.
Sources
- CISA, avoiding social engineering and phishing attacks: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
- Phishing Codebook research: https://arxiv.org/abs/2408.08967
- FTC, what to do if you were scammed: https://consumer.ftc.gov/articles/what-do-if-you-were-scammed