Why Email Formatting and Attachments Matter for Security
The way you format an email and the files you attach can either protect you or expose you to hackers. Plain text emails are harder to exploit than formatted emails with embedded links and images, because they cannot run hidden code. Attachments are where most malware enters a computer — a file that looks like a document or photo can actually contain instructions that steal your passwords or lock your files for ransom.
You do not need to stop using email entirely, but understanding which formats are safer and which attachments carry real risk lets you make deliberate choices instead of accidental ones. The goal is to send what you need to send while closing the doors hackers use most often.
Key Takeaways
- Plain text emails cannot run hidden code or execute commands, making them safer than formatted emails with embedded images and links.
- Attachments are the most common way malware enters a computer, so only open files from people you know and trust, and only when you expected them.
- File extensions like .exe, .zip, .scr, and .bat are dangerous because they can run programs; .doc, .xls, and .pdf files can also contain malicious code if they come from untrusted sources.
- Compressed files (.zip) hide what is inside them, so never unzip an attachment unless you know exactly what the sender intended to send.
- Sending attachments through cloud storage links instead of email attachments reduces the risk that malware will reach the recipient's computer.
Plain Text Versus Formatted Email
Plain text is email with no formatting — no bold, italics, colors, images, or embedded links. It looks like a straightforward letter typed on a typewriter. Plain text cannot run code or execute commands, which means a hacker cannot use formatting tricks to steal information or install malware. This is the safest way to send email.
Formatted email (also called HTML or rich text) allows you to make text bold, add colors, insert images, and embed clickable links. The problem is that the code behind those features can be manipulated. A link that appears to go to your bank's website can actually go to a fake site designed to steal your login. An image can contain hidden instructions. A hacker can also use formatting to hide malicious code inside what looks like a normal message.
Most email programs default to formatted email because it looks nicer. If you are sending sensitive information — passwords, account numbers, financial details — switch to plain text first. In Gmail, Outlook, and Apple Mail, you can usually find this option in the compose window under "Format" or "More options." The message will look plainer, but it will be much harder to exploit.
Which Attachments Are Dangerous
Not all attachments are equally risky. Files that can run programs are the most dangerous because they can execute malware directly on your computer. These include .exe (Windows programs), .bat (batch files that run commands), .scr (screensavers), .msi (installers), .com, and .pif files. If someone sends you one of these, do not open it unless you initiated the read and you trust the sender completely.
Document files like .doc, .docx, .xls, and .xlsx are safer than executable files, but they are not safe from malware. These files can contain macros — small programs embedded inside the document that run when you open it. Microsoft Office disables macros by default in most cases, but if you see a message asking whether you want to enable macros, the answer is almost always no. A legitimate document from a trusted source will work without macros.
PDF files are generally safer than Office documents because they are harder to weaponize, but malicious PDFs do exist. Image files like .jpg and .png are very unlikely to contain malware on their own, though a hacker could use an image as a decoy to trick you into opening something else. Compressed files (.zip, .rar, .7z) hide what is inside them, so you cannot see what you are actually extracting until after you open them — never unzip an attachment unless you know exactly what the sender intended to send.
How to Decide Whether to Open an Attachment
Before you open any attachment, ask yourself three questions: Did I expect this file? Do I know and trust the sender? Does the file type make sense for what the sender said they were sending?
If the answer to any of these is no, do not open it. A common scam is to send an attachment that looks like an invoice, delivery notice, or package tracking update from a company you use. The sender's name might look official, but if you did not request that file, it is dangerous. Even if you recognize the sender's name, their email account might have been hacked — in that case, the attachment is still malware.
If you are unsure, contact the sender through a different method. Call them on the phone or send them a separate email asking whether they sent the file. Do not reply to the email with the attachment, because that email address might be compromised. A few minutes of caution is worth far more than the risk of opening something that could lock your files or steal your information.
Safe Ways to Send Files to Others
If you need to send a file to someone, consider using cloud storage instead of email attachments. Services like Google Drive, Dropbox, OneDrive, and iCloud let you upload a file and send the recipient a link instead of attaching the file directly. The recipient downloads the file only when they click the link, and you can control who has access and when access expires.
This approach has two advantages: it reduces the chance that malware will be caught by email filters before reaching the recipient, and it lets you revoke access if you change your mind. If you must send an attachment through email, use a password-protected compressed file (.zip) so that only the intended recipient can open it. Make sure the recipient knows the password through a separate message — never send the password in the same email as the file.
For very sensitive files, consider encrypting them before you send them. Many email programs have built-in encryption, and services like ProtonMail encrypt messages automatically. Encryption scrambles the file so that only someone with the correct password or key can read it, even if a hacker intercepts it.
Recognizing Suspicious Formatting and Links
Hackers use formatting tricks to hide where links actually go. A link might say "Click here to update your account" but actually point to a fake website designed to steal your password. In most email programs, you can hover your mouse over a link without clicking it to see the real address it points to. If the address does not match what the link text says, do not click it.
Be suspicious of emails that use urgent language, bright colors, or large fonts to pressure you into acting quickly. Legitimate companies rarely use these tactics. They also rarely ask you to click a link to verify your password or account information — if you need to access your account, go directly to the company's website by typing the address yourself instead of clicking an email link.
Formatted emails that contain many images, especially images with text overlaid on them, are often phishing attempts. Real companies usually send plain, straightforward emails. If an email looks like it was designed to look flashy or urgent, treat it with extra caution.
Email Settings That Reduce Risk
Most email programs let you control how attachments and formatted content are displayed. In Outlook, you can set the reading pane to plain text only, which strips out formatting and makes hidden code visible. In Gmail, you can disable image loading by default, which prevents some tracking and reduces the risk of image-based exploits. In Apple Mail, you can turn off HTML rendering for specific senders or for all mail.
These settings make email less visually appealing, but they close several doors that hackers use. If you receive a lot of email from untrusted sources — mailing lists, newsletters, automated notifications — these settings are worth enabling. You can always switch back to formatted view for email from people you trust.
Another useful setting is to disable automatic downloading of images and attachments. Most modern email programs do this by default, but it is worth checking. If images and files do not read until you explicitly allow them, you have a moment to decide whether you trust the sender before anything runs on your computer.
Frequently Asked Questions
Can a hacker send me malware through a photo attachment?
A standard photo file (.jpg, .png) cannot run malware on its own. However, a hacker could send a file that looks like a photo but is actually an executable program with a fake extension. Always check the real file type by right-clicking the file and looking at properties, not just the name it displays. If someone sends you a photo you did not ask for, do not open it.
What should I do if I accidentally opened a suspicious attachment?
Do not panic, but act quickly. Disconnect your computer from the internet when ready. Run a full antivirus scan using a program like Windows Defender, Malwarebytes, or Avast. If the scan finds anything, follow the program's instructions to remove it. If you are not comfortable doing this yourself, take your computer to a repair shop. Change your passwords from a different device while your computer is offline.
Is it safe to open a .pdf attachment?
PDF files are generally safer than Office documents or executable files, but malicious PDFs do exist. Only open PDFs from senders you trust. If a PDF came unexpectedly, contact the sender first. Some email programs let you preview PDFs without fully opening them, which adds a layer of safety.
Why do some emails ask me to enable macros?
Macros are small programs embedded in Office documents. Legitimate documents sometimes use macros for formatting or calculations, but hackers also use macros to install malware. Microsoft disables macros by default to protect you. If you see a message asking you to enable macros, the answer is almost always no — the document will work without them.
Can I get malware from a .zip file?
A .zip file itself cannot run malware, but it hides what is inside. When you unzip it, the files inside might be dangerous. Never unzip an attachment unless you know exactly what the sender intended to send and you trust them completely. If you are unsure what is in a .zip file, ask the sender before opening it.
