Are Gmail attachments secure?

Last reviewed: September 23, 2026 · Markdown version

"Secure" hides three separate questions: is it scanned, is it encrypted, and who can read it. Google answers the first two clearly and the third one only partly. Every quotation below is from one of Google's own pages, cited where it is used.

Scanned: yes, automatically, both directions

"Attachments in Gmail messages you send and receive are automatically scanned for viruses" (Anti-virus scanning attachments, read 23 September 2026). When something is found in mail sent to you, Gmail "will reject the message and let the sender know"; if it is already in your inbox, "you won't be able to download the attachment". When you are the sender, you get a "Virus detected!" error and the option to send without that file.

There is a third state worth recognising: "Gmail virus scanners are temporarily unavailable", where Gmail offers to let you "open the attachment at your own risk". That sentence is doing real work — it means the check you are relying on did not happen.

Blocked outright

Scanning is not the only mechanism. Gmail refuses certain file types outright, "including their compressed form (like .gz or .bz2 files) or when found within archives (like .zip or .tgz files)" — .exe, .apk, .bat, .js, .jar, .msi, .vbs and a long tail of others (File types blocked in Gmail, read 23 September 2026). This is a genuine protection and it is also why zipping something "to get it through" does not work.

Encrypted: in transit, usually

"All Gmail messages use TLS automatically", and Google notes that "Almost all major email services use TLS" — so in ordinary use the hop is encrypted (Learn how Gmail encrypts your emails, read 23 September 2026). Gmail also tells you when it was not: a message with standard TLS carries a grey lock, and an unencrypted one carries a red open lock, where Google's advice is to "Not send sensitive information" and to "Let the sender know their message is unencrypted". Two stronger states, hosted S/MIME and client-side encryption, are shown as a green lock and a blue shield — but Google lists both as available for work or school accounts only, so a personal account will not see them.

The honest caveat: TLS is about the journey. Google's encryption page describes protecting a message "until it reaches the right person"; it does not describe how the message is kept once it has arrived, so the padlock tells you nothing about who can open the mailbox it lands in.

What "confidential mode" is and is not

Google describes confidential mode in terms of what it switches off. You can "Set an expiration date for an email", and it will "Disable options for recipients to forward, copy, print, and download your emails" (Send & open confidential emails, read 23 September 2026).

What it is not is stated on the same page, in Google's own words: "While confidential mode can help prevent recipients from accidentally sharing emails, they can still take screenshots or photos of your emails. Recipients with malicious programs may still be able to copy or download your messages." Note the word accidentally. The help page makes no encryption claim at all, and neither should you — it is a guard against mistakes, not against someone who wants the file.

The question people usually mean

Most people asking this are not worried about viruses. They are asking who can read the contents of the tax return sitting in their mailbox — and the honest answer is that anyone who can sign in to the account can open it, virus scanning and padlocks notwithstanding. The controls that matter are the boring ones: two-factor authentication, reviewing which apps have access to the account, and not keeping documents you no longer need.

That last one is the only part that shrinks the problem rather than guarding it. A statement from 2017 that nobody will ever open is pure exposure with no upside.

Related: Why do my attachments keep failing? · Where are attachments in Gmail? · The Gmail spam folder · How to stop spam emails