How to check whether a file is safe before you open it
A file is generally safe to open if it came from a source you trust, matches what you expected to receive, and your antivirus software does not flag it. The biggest risk is files that arrive unexpectedly in email or messages — especially those asking you to enable macros, download something else, or act quickly. Before opening any file you are unsure about, check where it came from, look at the file name and extension, scan it with your antivirus tool, and consider whether you actually need to open it at all.
Most files on your computer are safe by default. The danger comes from files designed to spread malware, steal information, or lock your files for ransom. These usually arrive as email attachments, downloads from unfamiliar websites, or files shared through messaging apps. Knowing what to look for takes only a few minutes and can prevent serious problems.
Key Takeaways
- Files from unexpected sources — especially email attachments that ask you to enable macros or click links — should be treated as suspicious until you verify where they came from.
- Check the file extension (the letters after the dot) to see what type of file it is; executable files like .exe, .bat, and .msi are higher risk than documents like .pdf or .txt.
- Run any suspicious file through your antivirus software or upload it to VirusTotal (a free scanning service) before opening it.
- If a file came from email, contact the sender through a different method — by phone or a known email address — to confirm they actually sent it before opening it.
Where the file came from matters most
The source of a file is your first clue to whether it is safe. Files from people you know, websites you use regularly, and official software publishers are generally trustworthy. Files from unknown senders, suspicious links in emails or messages, or websites that seem off are much riskier.
Email attachments are the most common way malware spreads. If someone you know sends you a file, that does not automatically mean it is safe — their email account could be compromised, or the file could have been intercepted. If you were not expecting the file, or if the message seems out of character, contact the sender through a different method (a phone call, a text message, or a known email address) and ask if they actually sent it.
Downloads from the official website of a software company are safe. Downloads from third-party sites that claim to host the same software are often not. If you need a program, go directly to the publisher's website rather than searching for a download link.
What the file name and extension tell you
The file extension — the letters after the final dot in the file name — shows what type of file it is. Some extensions are much riskier than others. Executable files like .exe (Windows programs), .msi (Windows installers), .bat (batch files), and .com (command files) can run code directly on your computer and are high risk if they come from an unknown source.
Document files like .pdf, .txt, .docx (Word), and .xlsx (Excel) are lower risk on their own, but they can still contain malware if they are designed to. A Word document that asks you to "enable macros" or "enable content" is asking permission to run code — do not do this unless you created the document yourself or trust the sender completely.
Compressed files like .zip and .rar are neutral — they are just containers. The risk depends on what is inside them. If you download a .zip file, extract it to a folder and check what files are in it before opening anything.
Be suspicious of files with double extensions, like document.pdf.exe. This is a common trick to hide the real file type. The file is actually an executable program, not a PDF.
How to scan a file before opening it
Your antivirus software can scan individual files. Right-click the file, look for an option like "Scan with [your antivirus name]" or "Scan for viruses", and wait for the result. If your antivirus flags the file as a threat, delete it immediately and do not open it.
If you do not have antivirus software installed, or if you want a second opinion, use VirusTotal. Go to virustotal.com, click the upload button, and select the file. VirusTotal scans the file with more than 70 antivirus engines at once and shows you the results in seconds. If multiple engines flag it as malware, the file is not safe. If only one or two flag it, it could be a false alarm, but err on the side of caution.
Scanning takes less than a minute and can catch threats that your regular antivirus might miss. Make this a habit for any file you are unsure about.
Red flags that suggest a file is not safe
Certain warning signs mean you should not open a file. An unexpected email attachment from someone you know, especially one that asks you to enable macros or download something else, is a major red flag. Messages that create urgency — "act now", "verify your account", "confirm your password" — are almost always malicious.
A file with a misleading name is suspicious. For example, a file named "invoice.pdf.exe" is actually a program, not a PDF. A file that claims to be a document but has an executable extension (.exe, .msi, .bat) should not be opened.
Files from links in emails or messages are riskier than files you download directly. If an email tells you to click a link to download something, go to the official website instead and download it from there.
A file that your antivirus software flags as a threat should be deleted, not opened. Trust your antivirus software — it is designed to catch these things.
What to do if you already opened a suspicious file
If you opened a file and now you are worried it might be unsafe, do not panic. Many suspicious files do nothing harmful. Run a full antivirus scan on your computer right away. Most antivirus software has a "full scan" or "deep scan" option that checks every file on your system. This can take an hour or more, but it will catch most threats.
If your antivirus finds something, follow its instructions to remove or quarantine the threat. If you are concerned about your passwords or financial information, change your passwords from a different device (like your phone) and monitor your bank and credit card accounts for unusual activity.
If the file was an email attachment and you are still worried, contact your email provider's support team. They can help you determine whether your account has been compromised.
When you should ask for help
If you are not sure whether a file is safe and you cannot reach the person who sent it, do not open it. Deleting a file you did not need is always safer than opening something risky.
If your antivirus software flags a file as malware and you believe it is a false alarm, you can submit the file to the antivirus company for review. Most antivirus publishers have a website where you can report files. However, if you are not certain, it is safer to delete the file and ask the sender to resend it through a different method.
Frequently Asked Questions
Is it safe to open a PDF file from an unknown sender?
PDFs are generally lower risk than executable files, but they can still contain malware. If the PDF came unexpectedly and you do not know the sender, scan it with your antivirus software or VirusTotal before opening it. If it asks you to enable anything or click links, treat it as suspicious.
What should I do if I get an email with an attachment I was not expecting?
Contact the sender through a different method — by phone, text, or a known email address — and ask if they actually sent it. Do not open the attachment until you confirm. If you cannot reach them, delete the email.
Is VirusTotal safe to use?
Yes. VirusTotal is run by Google and is widely used by security professionals. When you upload a file, it scans it with multiple antivirus engines and shows you the results. The file is not stored or shared with third parties.
Can a file be safe even if one antivirus engine flags it?
Possibly. One antivirus engine flagging a file while 60 others do not could be a false alarm. However, if multiple engines flag it, or if the file came from a suspicious source, treat it as unsafe and delete it.
What file types are safest to open?
Plain text files (.txt), PDFs, and images (.jpg, .png) are generally safest. Executable files (.exe, .msi, .bat), scripts (.vbs, .ps1), and Office documents that ask to enable macros are riskier. The safest approach is to scan any file you are unsure about, regardless of type.