Skip to content

Home Topics Email Security Management Attachment and link security

Email Security Management · Attachment and link security

Email attachment and link security checklist for 2026

Short answer

A complete email attachment and link security checklist has 4 setup items and 2 things to audit against. Work through setup in order, then schedule a quarterly review.

Setup checklist#

  • ☐ Block executable and macro-enabled attachment types at the gateway.
  • ☐ Enable URL rewriting with time-of-click reputation checks.
  • ☐ Sandbox unknown attachments before delivery.
  • ☐ For outbound, prefer links to authenticated portals over attachments for sensitive files.

Audit checklist#

  • ☐ Confirm you are not: allow-listing partner domains and bypassing scanning entirely.
  • ☐ Confirm you are not: password-protected archives that evade scanning.

Ongoing monitoring#

  • ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
  • ☐ Monthly: re-run the setup verification after any vendor or DNS change
  • ☐ Quarterly: full audit against this checklist

Frequently asked questions#

Are PDF attachments safe?

Mostly, but PDFs can carry scripts and phishing links. Sandboxing and link rewriting still apply.

Keep reading on Attachment and link security