Which email attachments are actually dangerous
Not all file types carry the same risk. Here they are, roughly in order.
Updated 2026-09-26
"Never open attachments" is advice nobody can follow, because attachments are how work happens. Here is the more useful version: which ones can actually do something, and what to do when you are unsure.
Genuinely dangerous
Programs. .exe, .msi, .scr, .bat, .cmd, .com, .pif on Windows; .dmg, .pkg, .app on a Mac. These *are* software. If one arrives by email, from anyone, for any reason, do not run it.
Scripts. .js, .vbs, .ps1, .hta, .wsf. Small text files whose entire purpose is to execute instructions.
Shortcuts and disk images. .lnk and .iso are now common in real attacks, precisely because they look harmless and slip past filters.
Archives hiding any of the above. A .zip, .rar or .7z is only as safe as what is inside it. A password-protected archive with the password in the email body is a technique for defeating scanners, not a courtesy.
Depends entirely
Office documents. .docx, .xlsx, .pptx are fine as documents. The danger is macros, and modern Office blocks them by default in files from the internet. A document that opens and asks you to "Enable Content" or "Enable Editing to view" is the attack. There is no legitimate invoice that needs macros to be readable.
PDFs. Usually fine, occasionally not. The realistic PDF risk today is not malware, it is a PDF that contains a link or a QR code to a phishing page. Treat a link in a PDF like a link in an email.
HTML files. An .htm or .html attachment is a web page that opens locally, often a login page made to look like your webmail. Rare in normal correspondence and worth suspicion.
Usually harmless
Plain images (.jpg, .png, .gif), plain text (.txt, .csv) and most video and audio. Not impossible to abuse, but not where the risk lives.
The question that matters more than the file type
Were you expecting it? An invoice from a supplier you do not use, a CV for a job you did not advertise, a receipt for a purchase you did not make — the file type is secondary. The realistic goal of most of these is not to infect your machine at all; it is to get you to open an attachment, believe the story, and then follow an instruction later in it.
If you need to look
- Open it on your phone. Phones are far more locked down than laptops.
- Open it in the browser. Gmail, Outlook and the rest preview documents without running anything
on your machine.
- Check with the sender, on a number or address you already had. Not by replying — if the account
is compromised, you are asking the attacker.
If you already opened it
Disconnect from the network, run whatever anti-malware you have, and change your passwords from a different device. If it was a work machine, tell your IT team immediately. Nobody has ever been told off for reporting this quickly; plenty of people have been for reporting it on Monday.
Check a suspicious message Free, and it needs no account.