Safe attachments: the built-in antivirus
In short
Every attachment you receive is analyzed before you open or save it: instant local checks and, on the PC, a Windows Defender scan. A badge tells you whether it’s verified or dangerous; dangerous files have their preview blocked and need your explicit confirmation.
What does Mailamber check?#
On every plan, on your device and without sending files to anyone, Mailamber looks for the tricks most often used to hide malware, including:
- dangerous executable extensions and misleading double extensions (
invoice.pdf.exe); - names with characters that disguise the extension or imitate other letters;
- content that doesn’t match the declared type;
- Office documents with macros (including hidden ones) and PDFs with automatic actions or JavaScript;
- archives containing executables, and encrypted or nested archives.
On the PC, every attachment also goes through a Windows Defender scan, when Defender is active. The automatic check covers attachments from the last 30 days.
What do the badges mean?#
- Verified: no threats: no problems found.
- Scanning…: the check is in progress.
- Potentially dangerous file: the preview is blocked. To save the file you have to confirm with “I know what I'm doing, save anyway”.
On the phone, the checks are based on the file’s name and type: dangerous or caution appears next to the attachment. Think twice before opening a flagged file.
What is the threat database lookup?#
Check against the threat database is a PC option, off by default, in Settings → Privacy & security. When you turn it on, Mailamber sends its own servers only the file’s SHA-256 fingerprint — a string that can’t be used to rebuild the content — to compare it against a public archive of known malware. The file never leaves your PC.