Home › Knowledgebase › KB-459

How to recognise and safely handle a suspicious email attachment before opening it

Summary

This guide helps you troubleshoot and resolve: How to recognise and safely handle a suspicious email attachment before opening it. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Email attachments are one of the most common ways cyber criminals try to deliver malware, ransomware, or credential-stealing tools to Australian businesses. The good news is that most malicious attachments show clear warning signs before you ever click them. This guide walks you through how to spot a suspicious attachment, how to inspect it safely, and what to do if you think you've received something dangerous.

Quick Warning Signs to Look For

Before opening any attachment, scan the email for these red flags:

Never open these file types from an unverified sender: .exe, .bat, .cmd, .com, .scr, .js, .vbs, .ps1, .jar, .iso, .lnk. Legitimate organisations virtually never send these by email.

Safe Inspection Steps Before Opening

  1. Verify the sender independently. Don't reply to the email or use any contact details in the message. Instead, find the organisation's official contact details from their website and call them directly to confirm the attachment is genuine.
  2. Hover over the sender's name in your mail client to reveal the full email address. In Outlook, hover over the name; in Gmail, click the three-dot menu next to the message and choose Show original.
  3. Hover over the attachment link without clicking. The real filename and extension should appear. Watch for double extensions like invoice.pdf.exe — Windows often hides the second extension.
  4. Check file extensions are visible. In Windows File Explorer, choose View > Show > File name extensions. On macOS, open Finder > Settings > Advanced and tick Show all filename extensions.
  5. Scan the file before opening. Right-click the downloaded file and choose Scan with Microsoft Defender (Windows). On macOS, drag the file into your third-party antivirus application or use your endpoint protection tool. You can also submit the file to VirusTotal for a multi-engine check, but only do this with files you suspect — never with documents containing sensitive personal data.
  6. Open documents in protected view. Microsoft Word, Excel, and PowerPoint open files from the internet in Protected View by default. Don't click Enable Editing unless you're confident the file is safe.
Tip: If a sender asks you to "enable macros" or "enable content" to view a document, treat it as suspicious. Macros are a common delivery method for ransomware.

How to Report a Suspicious Email

If you receive a suspicious email at your work address, report it to 220 Internet Services rather than deleting it. We can block the sender across your organisation and investigate any impact.

  1. In Outlook, select the suspicious message without opening any attachments.
  2. Click Home > Report > Report Message > Phishing (or Junk > Report as Phishing in older versions).
  3. In Gmail, open the message, click the three-dot menu, and choose Report phishing.
  4. Open a ticket through the 220 support portal and attach a screenshot of the email headers (in Outlook: File > Properties > Internet headers).

You can also report scams to the Australian Cyber Security Centre via ReportCyber, and forward scam emails to [email protected].

If You've Already Opened a Suspicious Attachment

Don't panic, but act quickly:

  1. Disconnect from the network. Unplug the Ethernet cable or turn off Wi-Fi to prevent malware from spreading.
  2. Don't enter any passwords on the affected computer.
  3. Run a full antivirus scan. Open Windows Security > Virus & threat protection > Scan options > Full scan, or on macOS use your endpoint protection tool.
  4. Change passwords from a different, clean device — especially email, banking, and any work accounts.
  5. Contact 220 immediately. Open a ticket and tell us what was opened and when. Our security team can isolate the device, check for signs of compromise, and begin remediation.
Time matters. The faster we know about a potential infection, the more we can do to contain it. Even if you're not sure whether the attachment was malicious, report it.

Preventing Future Incidents

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket