Practical guide
Unexpected Attachment? Ask What Job It Serves
Check the reason for a file before opening something that claims to be an account notice or private preview.
Start with whether a file was expected
A file named Account details or Private preview can create curiosity without explaining why you need it. Ask whether you requested an attachment, whether the sender is known through a reliable channel, and what task the file is supposed to complete. In a hypothetical exchange, you ask a question about a profile and receive an unrelated archive. That mismatch is a good reason to pause. You do not owe a sender an immediate download simply because they say the material is important.
Keep the conversation outside the attachment
If clarification is needed, use a contact route you already trust rather than instructions embedded in the file. Ask what format you should expect and whether the same information is available through the service's normal account page. The FTC identifies harmful attachments as a common phishing tactic. This does not mean every unexpected document is malicious; it means the document should not be the place where you first try to establish the sender's identity or the purpose of the request.
Respect a warning instead of chasing the content
If your browser or security software flags a download, treat the warning as a stop point for this task. Do not follow a sender's instructions to disable protection or rename the file until it opens. Mozilla documents protection against dangerous and potentially unwanted downloads. A person offering ordinary account help should not need you to defeat those protections to read their explanation. Leave the file unopened while you clarify the situation, and use official device guidance if you already ran something suspicious.
Choose the smallest useful next step
Sometimes the safest completion is a plain-text answer instead of a file. For example, a support team can often confirm a ticket number or explain a setting without sending an executable attachment. Ask for the information you actually need, not for a second version of the same unexplained download. If the sender cannot provide a credible reason for the file, stop the exchange. The takeaway is to make purpose and provenance clear before curiosity turns a message into software running on your device.
Sources checked
Linked reference pages checked on 2026-09-09. Product details can change. No paid-membership test or sponsorship is implied.
FTC: phishing attachments ↗Mozilla: phishing and malware download protection ↗