US blog
Email

Is this email attachment safe?

Before opening a suspicious PDF, ZIP, invoice, or document attachment, check the sender, domain, context, file type, and request.

Suspicious email attachment preview with a warning checklist

If you were not expecting the attachment, do not open it first.

Check the sender, the domain, the file type, the timing, and what the email wants you to do. A fake invoice can look boring. That is part of the problem.

The attachment check

What to checkWhy it matters
Sender domainDisplay names are easy to fake
File typeZIP, executable, macro document, or strange link is riskier
ContextWere you expecting this invoice, contract, resume, or tax file?
Payment detailsDid bank details suddenly change?
Login requestDoes the file push you to a fake sign-in page?
UrgencyIs it trying to make you open before checking?

Common attachment traps

Fake invoice

The email says an invoice is attached. The sender name looks familiar. The risky part is the attachment, the payment details, or a link to "download" the invoice.

Fake tax document

The message mentions tax, refund, penalty, or account status. It may use your real name or business details.

Fake brand deal or contract

Creators and small businesses see this often. The sender asks you to download a "brief," "contract," or "media kit" from a strange domain.

Fake security notice

The attachment says your account, mailbox, or device is at risk. It usually wants a login or code.

If the attachment sent you to a login page, treat it like a link problem too: how to check a link without clicking it.

What to do instead

  1. Contact the sender through a known channel.
  2. Open the vendor portal yourself.
  3. Do not enable macros.
  4. Do not open ZIP files from unexpected emails.
  5. Do not log in through the attachment link.
  6. Ask IT or a trusted person if this is for work.

Sources