Judge the action the file requires
An attachment may ask you to open a document, enable macros, run an installer or enter credentials into a linked page. Those are different actions with different consequences. A familiar file icon or sender name does not establish that the requested action is legitimate.
The safest initial review does not execute the file. Do not disable antivirus, enable a blocked macro or extract a password-protected archive just because the message says it is required for delivery.
Verify before opening
- Check whether the attachment was expected in an existing business workflow. Confirm unusual requests through a known separate contact, especially when the message pressures you to act immediately.
- Inspect the actual filename and extension using the application's or operating system's supported view. A double extension or misleading icon deserves attention, but a normal extension is not proof of safety.
- Use the email provider's or organisation's approved reporting feature for a suspicious message. Preserve the original without forwarding potentially harmful files to a group of colleagues.
- If the attachment is legitimate and necessary, open it using the approved updated application and normal protection settings. Treat an unexpected request to enable active content or launch another program as a new decision requiring verification.
Verify a safe alternative
Ask the verified sender whether the document can be accessed through an existing trusted portal or provided in a simpler form that meets the business need. Do not upload confidential attachments to a public scanning website merely to obtain reassurance.
If the file was already opened
Record exactly what happened: previewing, opening, enabling macros, entering credentials or running a program. Tell the responsible administrator which action occurred and approximately when. If code may have run, follow the incident process and use a separate trusted device for account changes as appropriate.
Keep evidence useful
Retain the message reference, sender details and reported action in a private incident note. Avoid repeatedly opening the attachment to reproduce a problem on a production computer. Security-tool results should be interpreted with context: a clean scan is helpful evidence, but it does not guarantee that a new or tailored file is harmless.
Make reporting easy
Staff should know a single approved reporting route and receive guidance on the next action. The aim is to stop an unsafe workflow early, not to require every recipient to become a malware analyst before asking for help.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.