Downloading files from the internet or email is part of everyday work, but opening the wrong file can put your computer and your business at risk. Here is how to check before you click.
Check who sent it
If the file came by email, make sure you recognise the sender and that you were expecting the file. Criminals often send emails that look like they come from a colleague, client or supplier. If something feels off, contact the sender by phone or a separate message to confirm they actually sent it.
Check the file type
Some file types are riskier than others. Documents like .pdf, .docx and .xlsx are generally safe if they come from a trusted source. Files ending in .exe, .bat, .scr, .js or .zip containing these types should be treated with extreme caution. These are program files and can run harmful software on your computer the moment you open them.
Let Microsoft Defender scan it
If you are on Windows 11, Microsoft Defender scans files automatically when you download them. If a file is flagged as dangerous, Windows will show a warning. Do not ignore this warning. If you want to scan a file manually, right click on it in File Explorer and click Scan with Microsoft Defender.
Use the SmartScreen warning
Microsoft Edge has a built-in feature called SmartScreen that warns you when a download looks suspicious. If you see a warning bar at the bottom of your browser saying the file is not commonly downloaded or could be harmful, do not override it unless you are absolutely sure the file is safe.
When in doubt, do not open it
If you are not sure whether a file is safe, do not open it. Rather forward it to your IT provider and ask them to check it. One bad file can compromise your entire network.