Most files people deal with day to day — PDFs, photos, scanned documents — are completely safe, and it is easy to open dozens of them without a second thought. The exceptions are rare but worth being able to recognise, and a handful of quick, non-technical habits catch the large majority of genuine problems before a file is ever opened.
Check the source first, before the file itself
Where a file came from matters more than almost anything about the file itself. A document from someone you know, expected as part of a normal conversation, carries far less risk than an unexpected attachment from an unfamiliar sender, even if both are technically the same file type. If a file arrives unexpectedly — especially with any sense of urgency in the accompanying message (“open this immediately,” “your account will be closed”) — that pressure itself is a common warning sign, regardless of what the file claims to be.
Check the actual file extension, not just the icon
A file's icon can be visually similar to a legitimate document type while the actual file extension tells a different story — a file named invoice.pdf.exe, for instance, is not a PDF at all despite the name including “.pdf,” since the part after the final dot is what actually determines the file type. Most operating systems can be configured to always show full file extensions rather than hiding them, which is worth enabling if it is not already, since it removes an entire category of disguised file trick.
Be cautious with files that ask you to enable something
A legitimate PDF, photo or scanned document should simply open and display — it should never need you to “enable macros,” “enable content,” or run an additional installer just to be viewed. If opening a document prompts you to actively enable some additional capability before you can see its content, treat that as a significant warning sign rather than a normal step, since this is one of the most common ways a malicious file tries to get you to grant it more capability than simply displaying content requires.
A practical pre-open checklist
- Do I know and trust who this came from, and was I expecting it?
- Does the file extension match what it claims to be (a genuine .pdf, .jpg, .docx, not something ending in .exe or another executable extension)?
- Is the file asking me to enable anything before I can see its content?
- Does the accompanying message use pressure or urgency to get me to open it quickly without thinking?
If any of these raise a concern, it is reasonable to pause and verify through a separate channel — a quick message asking the sender “did you mean to send this?” — rather than opening the file to find out.
Why running a file through a conversion tool is not a safety check
It might seem like uploading a suspicious file to an online converter or compressor would be a safe way to “test” it, but this is not a reliable safety measure and is not what these tools are built for — they are designed to process legitimate document and image content, not to function as a security scanner. If a file is genuinely suspicious, the right response is caution and verification through the sender, not uploading it anywhere to see what happens.
What to do if you have already opened something suspicious
If you realise after the fact that a file you opened may not have been legitimate, disconnecting from the internet and running a reputable, up-to-date security scan on your device is a reasonable immediate step, followed by changing passwords for any sensitive accounts if there is a reasonable chance credentials could have been exposed. Acting promptly rather than waiting to see if something goes wrong is generally the more sensible response.
A note specifically about PDFs
PDFs have occasionally been used to carry malicious content in the past, typically by exploiting outdated PDF reader software rather than through any inherent flaw in the format itself. Keeping your PDF viewer reasonably up to date is a simple, low-effort way to reduce this risk, since security issues in older versions of common software are the kind of thing that gets addressed in updates specifically because they have been identified as exploitable.
Keeping this in proportion
The overwhelming majority of PDFs, photos and documents you will ever receive are completely ordinary and safe, and treating every single file with extreme suspicion is neither necessary nor practical for everyday work. The goal of a checklist like this is recognising the specific, genuine warning signs — an unexpected source, a mismatched extension, a request to enable something, pressure to act quickly — not applying blanket suspicion to routine, expected documents from people you know.
Frequently asked questions
Should I enable full file extensions on my computer as a precaution?
Yes, most operating systems hide common extensions by default, which makes a disguised file (like invoice.pdf.exe shown simply as “invoice.pdf”) harder to spot; turning this display setting on costs nothing and closes off a common disguise trick.
Is a PDF inherently safer than a Word document?
Neither format is inherently immune; both have had security issues exploited in outdated software historically. The precautions above apply similarly to either.
Can a photo or image file be dangerous the same way a document can?
It is less common, but not impossible, particularly if disguised as an image while actually being a different file type — checking the actual file extension applies here too.
Should I avoid opening any attachment from someone I do not know?
Extra caution is reasonable for an unexpected attachment from an unfamiliar sender, though not every such file is a threat; the checklist above helps you judge rather than defaulting to blanket avoidance.
Does keeping my software updated really make a meaningful difference?
Yes, many security issues are specifically addressed in software updates, so staying reasonably current closes off vulnerabilities that are known and, in some cases, actively being exploited elsewhere.
Is it safe to open a file that a legitimate business or government portal generated?
Generally yes, since these come from an established, verifiable source, though the same basic checks (does the extension match what is expected) remain a reasonable habit regardless of the source.
What if I am not sure whether a warning sign is genuine or not?
When in doubt, verifying through a separate channel — contacting the apparent sender directly rather than replying to the message the file arrived in — is a safe, low-effort way to resolve the uncertainty.
Do the tools on this site check files for safety?
No, they are built for processing legitimate documents and images, not as a security scanning service; use dedicated security software for that purpose.
Is it worth teaching this checklist to less tech-confident family members?
Yes, a short, simple checklist like this one is genuinely useful to share, since it is often the people least familiar with technical warning signs who benefit most from a clear, non-technical set of questions to run through before opening something unexpected.
Is there a difference between a file that is malicious and one that is simply corrupted?
Yes, a corrupted file is broken by accident and generally harmless beyond simply not opening correctly, while a malicious file is deliberately constructed to cause harm — the caution in this guide is specifically about the latter.