How to recognise and safely handle a suspicious email attachment before opening it
Summary
This guide helps you troubleshoot and resolve: How to recognise and safely handle a suspicious email attachment before opening it. Follow the steps below to fix the issue.
Common Causes
Email attachments are one of the most common ways cyber criminals try to deliver malware, ransomware, or credential-stealing tools to Australian businesses. The good news is that most malicious attachments show clear warning signs before you ever click them. This guide walks you through how to spot a suspicious attachment, how to inspect it safely, and what to do if you think you've received something dangerous.
Quick Warning Signs to Look For
Before opening any attachment, scan the email for these red flags:
- Unexpected sender or unusual address — The display name says "ATO" or "Australia Post" but the actual email address is a random Gmail or foreign domain.
- Urgent or threatening language — Phrases like "final notice", "account will be suspended", or "immediate action required".
- Generic greeting — "Dear Customer" instead of your actual name.
- Mismatched branding — Spelling errors, low-quality logos, or odd formatting.
- Unexpected attachments — You didn't request it, don't know the sender, or weren't expecting an invoice from that supplier.
- Suspicious file types — Executables (
.exe,.bat,.cmd,.scr), script files (.js,.vbs,.ps1), or password-protected archives (.zip,.rar) you weren't told the password for.
.exe, .bat, .cmd, .com, .scr, .js, .vbs, .ps1, .jar, .iso, .lnk. Legitimate organisations virtually never send these by email.Safe Inspection Steps Before Opening
- Verify the sender independently. Don't reply to the email or use any contact details in the message. Instead, find the organisation's official contact details from their website and call them directly to confirm the attachment is genuine.
- Hover over the sender's name in your mail client to reveal the full email address. In Outlook, hover over the name; in Gmail, click the three-dot menu next to the message and choose Show original.
- Hover over the attachment link without clicking. The real filename and extension should appear. Watch for double extensions like
invoice.pdf.exe— Windows often hides the second extension. - Check file extensions are visible. In Windows File Explorer, choose View > Show > File name extensions. On macOS, open Finder > Settings > Advanced and tick Show all filename extensions.
- Scan the file before opening. Right-click the downloaded file and choose Scan with Microsoft Defender (Windows). On macOS, drag the file into your third-party antivirus application or use your endpoint protection tool. You can also submit the file to VirusTotal for a multi-engine check, but only do this with files you suspect — never with documents containing sensitive personal data.
- Open documents in protected view. Microsoft Word, Excel, and PowerPoint open files from the internet in Protected View by default. Don't click Enable Editing unless you're confident the file is safe.
How to Report a Suspicious Email
If you receive a suspicious email at your work address, report it to 220 Internet Services rather than deleting it. We can block the sender across your organisation and investigate any impact.
- In Outlook, select the suspicious message without opening any attachments.
- Click Home > Report > Report Message > Phishing (or Junk > Report as Phishing in older versions).
- In Gmail, open the message, click the three-dot menu, and choose Report phishing.
- Open a ticket through the 220 support portal and attach a screenshot of the email headers (in Outlook: File > Properties > Internet headers).
You can also report scams to the Australian Cyber Security Centre via ReportCyber, and forward scam emails to [email protected].
If You've Already Opened a Suspicious Attachment
Don't panic, but act quickly:
- Disconnect from the network. Unplug the Ethernet cable or turn off Wi-Fi to prevent malware from spreading.
- Don't enter any passwords on the affected computer.
- Run a full antivirus scan. Open Windows Security > Virus & threat protection > Scan options > Full scan, or on macOS use your endpoint protection tool.
- Change passwords from a different, clean device — especially email, banking, and any work accounts.
- Contact 220 immediately. Open a ticket and tell us what was opened and when. Our security team can isolate the device, check for signs of compromise, and begin remediation.
Preventing Future Incidents
- Keep Windows Update or macOS Software Update turned on so security patches install automatically.
- Enable Multi-Factor Authentication on your email account — see our guide to password reset (Windows login) for related credential hygiene tips.
- Use an email filtering service that scans attachments before they reach your inbox.
- Back up important business data to an offline or cloud location that isn't permanently mapped to your computer, so ransomware can't reach it.
- Train your team to treat unexpected attachments with the same caution as an unexpected visitor at the office door.
Still Having Issues?
💻 Open a Ticket