Start with the four-box decision matrix
Low sensitivity + known source
A disposable email may be suitable. Examples include public white papers, event materials, and test files. After downloading, verify the file type and source domain.
Low sensitivity + unknown source
Preview only what you need. Do not run executables, enable macros, or open archive links that require you to sign in again.
High sensitivity + known source
Use a secure long-term email address. Contracts, identity documents, medical reports, bills, and account recovery files require reliable access and auditing.
High sensitivity + unknown source
Do not download it. Confirm the sender through an independent channel and report the suspicious delivery to the relevant organization.
Safe steps after receiving an attachment
- Check the context: Did you actually request this file? Do the sender and subject line match?
- Check the file extension: Be cautious with exe, js, scr, iso, macro-enabled documents, and double extensions. Images and PDFs are not automatically safe.
- Preview first: If the page provides readable content safely, verify it before downloading an attachment just to retrieve a verification code.
- Scan after downloading: Use an up-to-date system and security tools, do not bypass browser warnings, and do not enable unknown macros.
- Choose where to save it: Files that truly need long-term retention should be moved to controlled storage and encrypted or deleted according to their sensitivity.
Attachments that should not go through a disposable mailbox
- Identity documents, tax records, medical information, and legal originals
- Password recovery codes, private keys, seed phrases, or multifactor authentication backups
- Invoices, insurance policies, and contracts you may need to download again months later
- Company-internal files, documents covered by confidentiality agreements, or files containing customers’ personal information
- Files from unknown sources that ask you to run a program, disable protection, or enter login credentials
Why an attachment may not open
The sender may have provided an expired link, or the file may exceed service limits, be blocked by security filters, have incorrectly encoded characters in its name, or arrive after the mailbox has expired. Do not bypass security warnings by repeatedly requesting the file. If the attachment is important to your work, ask the sender to deliver it to an email address you control long term or through a controlled file-sharing system.
After downloading, a disposable mailbox does not manage your copies
Downloaded files go to the folder chosen by your browser and are then handled by your device, synced drives, and backup strategy. Deleting the disposable mailbox does not remove local downloads, copies, browsing history, or the original kept by the sender. When finished, manually delete files you no longer need and empty copies from your system recycle bin or sync service.