Skip to content
FRP-117 Fraud & Financial Crime

Could opening an attachment create a new record?

Yes. Opening an attachment can create device, application and provider-side records.

Avoid this assumption: Viewing an attachment is passive. The file may be downloaded, cached, scanned, indexed, added to recent files or recorded as accessed.

The sender or platform may receive a view event, download event or read-status update.

An attachment may also contain active content, tracking mechanisms, malware or links to remote resources.

Before opening, preserve the message, sender, account, filename, file type, visible size, timestamp and any warning.

Capture whether the attachment appears downloaded, pending, unavailable, encrypted or stored remotely.

Do not open it simply to identify what it contains.

Consider whether specialist examination, provider preservation or controlled acquisition is more appropriate.

Avoid opening attachments on a personal or general-purpose device.

If urgent safeguarding or operational need requires access, use an approved controlled environment and record why the evidential and security risks were accepted.

Document the device, application, account, time and network used.

Capture any warning, prompt, download indicator, new file, read receipt or change in message state.

Do not assume the absence of visible activity means no record was created.

Preserve the original message context separately from any later extracted or examined copy.

Record whether the attachment has a provider preview, checksum, document ID or cloud-sharing reference already visible. Those details may help identify it without opening the file.

Preserve these carefully.

Operational takeaway

Treat every attachment opening as a potential access, download and security event, and preserve its original message context before examination.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.