Skip to content

Home Topics Email Security Management Attachment and link security

Email Security Management · Attachment and link security

Email attachment and link security and CASL compliance in the Canada

Short answer

CASL requires express or implied consent before sending and identification of the sender in every message. Email attachment and link security supports compliance by making sender identity verifiable and recipient choices enforceable.

What CASL requires#

CASL requires express or implied consent before sending and identification of the sender in every message.

Attachment and link security covers scanning files and URLs in inbound mail (sandboxing, detonation, URL rewriting and time-of-click checks) and safe handling policies for outbound content.

Why it matters#

Malicious attachments and links remain the main payload delivery method for ransomware and credential theft.

Regulators and recipients need to identify who sent a message and trust that opt-out mechanisms work. Email attachment and link security contributes by malicious attachments and links remain the main payload delivery method for ransomware and credential theft.

Implementation steps#

  1. Block executable and macro-enabled attachment types at the gateway.
  2. Enable URL rewriting with time-of-click reputation checks.
  3. Sandbox unknown attachments before delivery.
  4. For outbound, prefer links to authenticated portals over attachments for sensitive files.

Frequently asked questions#

Are PDF attachments safe?

Mostly, but PDFs can carry scripts and phishing links. Sandboxing and link rewriting still apply.

Keep reading on Attachment and link security