A dangerous attachment rarely looks threatening. It is called “Invoice”, “Quote” or “Delivery notice”, it comes with a polite message and it looks exactly like a file you might be expecting. The difference lies in a few details: what the file is really called, what kind of file it actually is, who sent it and what it asks you to do once it is open.
This post brings together the signs of a dangerous attachment: what they mean, where you can see them and what to do when you find one. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise). Here we use them at two moments: before you open a file, to decide not to, and after you have opened it, to notice in time that something has gone wrong.
It is the diagnostic deep dive on the recommendation about not opening unknown attachments: not opening what you were not expecting is the prevention; recognising the signs helps you tell when a file deserves a second thought, even when it comes from someone you know.
What the signs of a dangerous attachment are
A sign, or indicator, is an observable detail suggesting that a file may not be what it claims to be. The real risk is malware: harmful software that can steal data, spy on what you do or lock up your documents.
A sign is not proof. It is a reason to stop and check, through a different channel from the one the file arrived on: a phone call, or a message on another app. It may have a harmless explanation, or it may point to an attempt to infect your device.
The value of these signs lies in timing: spotting them before you open a file means there is nothing to fix; spotting them straight after means you can step in before the problem spreads.
Why they matter more when the attachment is unexpected
A file you asked for has a context: you know what to expect and you notice if something does not add up. An unexpected file only has the context of the message that comes with it, and that is exactly what the person who prepared it can make up.
What is more, attachments no longer arrive only by email: they also turn up in chats and in messages on social networks. And they come from people you know, when their account has been taken over and used to write to everyone in their contacts. It can happen to you too, as we explain in the recommendation on messages sent in your name.
Finally, an attachment you have downloaded is already on your device. That is why the signs you see before opening it are worth more than the ones you will see afterwards.
Technical indicators: before you open
These are the details you can see in the message and in the file itself, without opening it. First, four terms: the file extension is the last part of a file’s name, after the final full stop (“.pdf”, “.jpg”), and it tells the system which program to open it with; a macro is a small set of automatic instructions contained in some documents; a compressed archive is a file that holds other files, usually a “.zip”; the domain is the part of an email address after the @ sign.
| Indicator | What it means | Why it matters | Where you see it | What to do |
|---|---|---|---|---|
| Double extension | The name ends with two extensions, for example “invoice.pdf.exe” | Only the last one counts: what looks like a document is actually a program | In the file’s full name, with extensions made visible | Do not open it; ask the sender, on another channel, what they sent you |
| Unusual extension for a document | An “invoice” with extensions such as .exe, .scr, .js, .iso or .lnk | These formats run instructions or contain other files | In the list of attachments or in your downloads | Do not open it; a genuine document almost always comes in a common format |
| Password-protected archive, with the password in the message | The compressed file is locked with a password written in the same message | It protects nothing: its purpose is to stop email filters from inspecting the contents | In the body of the message, often “for confidentiality reasons” | Do not open it; it is one of the most reliable signs |
| A request to enable macros or “enable content” | You are told you will need to switch something on to see the document | Macros are a common way to launch harmful software from a document | In the email text or inside the document | Do not enable anything; ordinary documents can be read without switching anything on |
| Odd sender or domain | The address does not match the display name, or imitates a company’s | People sending malicious files often pose as a supplier, a courier or a public office | By tapping the sender’s name to see the full address | Check through a channel you already know |
| Unannounced attachment | A file nobody told you to expect, even from a contact you know | It is the sign that almost all malicious messages have in common | By asking yourself: did I ask for this? Am I expecting a parcel? | Ask for confirmation on another channel before opening it |
| Attachment that points to an online file | The document only contains a “View” button that opens a sign-in page | Its purpose is to collect your email or cloud storage password | In the file preview | Do not enter any credentials; sign in from your bookmark or the official app |
Signs you can observe yourself: after opening
If the file has already been opened, many signs show up in the first few seconds or over the following days, simply by using your computer or phone as normal.
| Signal | What it means | Why it matters | How you notice | What to do |
|---|---|---|---|---|
| A blank or blurred document asking you to “enable” something | The file shows nothing but a prompt to switch on content or editing | There is no “real” content: the request is the file’s only purpose | A white page and a bar with an “Enable” button | Close it without enabling anything and delete the file |
| Pop-ups that open and close straight away | A pop-up, often black, appears for a split second | The file may have started instructions in the background | A flash on the screen right after opening | Disconnect the device from the network and follow the recovery steps |
| The file “won’t open” or shows an error | A generic error appears, or nothing happens at all | Some malicious files fake an error while they get to work | “File damaged” on a document you were expecting | Do not try again; treat it as a file that has been opened |
| Sudden slowdowns | The device is sluggish, the fan runs even when it is idle | It may point to a hidden program at work | In everyday use, from the moment of opening | A weak clue: read it together with the others |
| A password request after opening | A page opens asking you to sign in to your email or another service | Its purpose is to steal your credentials | A sign-in page you did not go looking for | Do not enter anything; if you did, change the password from another device |
| Alerts from the system’s built-in protection | The system reports that it has blocked or quarantined a file | The automatic check has recognised something suspicious | Security notifications from the system | Take the alert seriously and do not restore the file |
| Files that change name or will not open any more | Documents and photos with strange extensions and a demand for payment | It is the sign of ransomware, malware that locks your files to demand a ransom | In your personal folders, often with an “instructions” file | Disconnect the device and get help before doing anything else |
| Contacts receiving strange messages from you | People ask you about emails or files you never sent | Your account may be spreading the same attachment | Someone points it out to you | Change the password from another device and let your contacts know |
On a phone the signs are partly different, and we cover them in the recommendation on spotting the signs of malware on your phone.
A concrete example
Sarah has been waiting for a parcel for a few days. One morning she gets an email: “Missed delivery notice. The document with collection instructions is attached. For confidentiality reasons, the archive password is 2468.” Attached is a compressed file.
Sarah opens it. Inside is a file with a document icon; she opens that too, and the page is almost blank, with a line of text inviting her to enable content to read it. Sarah taps “Enable”. For a moment a black box flashes up, then nothing. She assumes the file is faulty and closes everything.
By the afternoon her laptop is slower than usual and the fan keeps running even when it is idle.
Reading the email again, the signs were all there: an unannounced attachment, an archive with the password written in the message, a document asking her to enable something. Each one, on its own, could have had an explanation; all three together were enough to stop. Sarah realises in time: she disconnects the laptop from the network and follows the steps, in order, without panicking.
What to check right away
Before opening an attachment
- the sender’s full address, not just the display name;
- whether the file was expected, and from whom;
- the file’s full name, extension included;
- whether it is a password-protected archive, and where the password is.
If you have already opened a doubtful attachment
- whether the document asked you to enable macros or content, and whether you did;
- whether pop-ups or sign-in pages opened that you did not go looking for;
- whether you entered a password after opening it;
- notifications from the system’s built-in protection.
Over the following days
- the device’s speed and any unusual behaviour;
- messages sent from your account that you do not recognise;
- recent sign-ins to your main email account.
If you find a suspicious indicator
- Do not open the file, and if you already have, do not enable anything.
- Check with the sender on another channel: a phone call or a different app, never a reply to the same email.
- Report and delete the message using your email service’s reporting feature: it helps other users too.
- If you opened it and something seems off, disconnect the device from the network and do not type passwords on it until you have checked.
- Change your important passwords from another device, starting with your main email, if you entered any credentials.
The full sequence, with the steps in the right order, is in the post on what to do after opening a suspicious attachment. If you would rather understand the mechanisms that produce these signs, we explain them in the post on malware in email attachments.
What is not an indicator
Telling the difference helps you avoid two opposite mistakes: trusting details that guarantee nothing, and being suspicious of every file that arrives.
| Situation | Why it is usually not a signal |
|---|---|
| A PDF or a photo from someone who told you it was coming | A common format and an expected context are exactly what make an attachment normal |
| An archive from a colleague, with the password given in person or on another channel | Keeping file and password apart is good practice |
| A “protected” or “read-only” bar at the top of a downloaded document | The program opens files from the internet in read-only mode: it is a safeguard |
| A slowdown after opening a large document | It only counts if it carries on or comes with other signs |
| A full-screen warning saying “your device is infected, call this number” | It is not a symptom of infection: it is often another scam, designed to frighten you |
There are also false signs of safety: a familiar contact’s name as the sender, a polished logo, a line such as “attachment scanned”. None of these, on its own, proves that a file is safe.
The rule of thumb: an unexpected attachment deserves a check; an unexpected attachment with even one technical indicator deserves to stay unopened.
When to run these checks
You do not need a demanding routine. You just need the habit to kick in at the right moments.
| Moment | What to check |
|---|---|
| Whenever an unexpected attachment arrives | Sender, the file’s full name and extension, before you double-click |
| When a document asks you to enable something | Stop and close the file |
| When a password-protected archive arrives | Where the password is: in the same message, it is a strong sign |
| In the days after opening a doubtful file | The device’s speed, sent messages, sign-ins to your email |
| Once, today | Make file extensions visible and check that updates are switched on |
Visible extensions are the simplest check in this whole post: once they are switched on, a “document.pdf.exe” can no longer hide. An up-to-date system also reduces the effect of many malicious attachments, as we explain in the recommendation on keeping your software up to date; and you can find out which checks your email service and your system already run for you in the post on how attachment scanning works.
Two important warnings
An indicator is not proof. A colleague may use an unusual format, a supplier may write from a new address, a computer may slow down for a hundred reasons. You do not need to be certain that a file is dangerous: it is enough not to open it until you have checked.
No indicators is not a guarantee. The most carefully made malicious files have a believable name, a common format and come from a contact you know. That is why protection rests on the habit described in the recommendation: what you were not expecting stays closed until you know who sent it and why. The signs help you stop; the habit means you do not have to guess. If the file comes with a request for personal details or a payment, the signs of a fake bank email apply as well.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing how to read a file’s full name and extension and recognise the formats that run instructions |
| Awareness | Understanding that an attachment can look like any ordinary document and still come from a familiar contact |
| Secure Behaviour | Checking on another channel before opening, and never enabling content in an unexpected file |
Reference level: FL2 — Beginner. This is the level at which you recognise the most common signs of a deceptive file and stop before opening it, even without knowing the technical details of how it was put together.
Conclusion
Spotting a dangerous attachment does not take specialist skills. It takes shifting your attention from how the message looks to three simple questions: was I expecting this, what kind of file is it really, and what is it asking me to do?
What to do right now. Open the folder settings on your computer and switch on file extensions. Then look at the last few attachments you downloaded: you will know what a normal file looks like, and it will be easier to notice one that is not. To see where you stand on the other aspects of your digital security too, you can take the digital resilience self-assessment.
Related resources
Short deep dives from the Resources section, for anyone who wants to focus on a single aspect:
- How to recognise phishing when it is built to be convincing
- Scareware: the warning that is itself the attack
Related content
- Not opening unknown attachments — the recommendation this belongs to
- Malware in email attachments — the mechanisms behind these signs
- What to do after opening a suspicious attachment — what to do, in the right order
- Impact of infected attachments — what gets hit when a sign is confirmed
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



