Donor lists age quickly; re-engagement and sunset policies protect reputation.
What email attachment and link security is#
Attachment and link security covers scanning files and URLs in inbound mail (sandboxing, detonation, URL rewriting and time-of-click checks) and safe handling policies for outbound content.
Why it matters#
Malicious attachments and links remain the main payload delivery method for ransomware and credential theft.
Implementation plan for nonprofits#
- Block executable and macro-enabled attachment types at the gateway.
- Enable URL rewriting with time-of-click reputation checks.
- Sandbox unknown attachments before delivery.
- For outbound, prefer links to authenticated portals over attachments for sensitive files.
Priorities specific to nonprofits#
Donor lists age quickly; re-engagement and sunset policies protect reputation. Weight your effort toward the steps above that address this constraint first, and measure with metrics that match how nonprofits generate value from email.
Common mistakes#
- Allow-listing partner domains and bypassing scanning entirely.
- Password-protected archives that evade scanning.
Frequently asked questions#
Are PDF attachments safe?
Mostly, but PDFs can carry scripts and phishing links. Sandboxing and link rewriting still apply.