# Question about email attachments and viruses

**URL:** https://boards.straightdope.com/t/question-about-email-attachments-and-viruses/196223
**Category:** Factual Questions
**Created:** [August 19, 2003, 3:52pm UTC](https://boards.straightdope.com/t/question-about-email-attachments-and-viruses/196223 "2003-08-19T15:52:42Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![KidCharlemagne](https://avatars.discourse-cdn.com/v4/letter/k/ed8c4c/32.png) [@KidCharlemagne](https://boards.straightdope.com/u/KidCharlemagne)
#### Post date: [August 19, 2003, 3:52pm UTC](https://boards.straightdope.com/t/question-about-email-attachments-and-viruses/196223/1 "2003-08-19T15:52:42Z")

</div>

In Yahoo mail whenever I get photos I can usually see them when I simply open the mail and don’t have to open the attachment. Does this mean that if I received a virus in an email attachment that I would “open” it just from opening the message itself or would I have to actually open the attachment?

---

<div class="post-metadata">

### Author: ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)
#### Post date: [August 19, 2003, 4:04pm UTC](https://boards.straightdope.com/t/question-about-email-attachments-and-viruses/196223/2 "2003-08-19T16:04:53Z")

</div>

No, it only displays JPG and GIF files in the HTML page. It does not (and cannot) execute a program in your computer.

---

<div class="post-metadata">

### Author: ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)
#### Post date: [August 19, 2003, 8:10pm UTC](https://boards.straightdope.com/t/question-about-email-attachments-and-viruses/196223/3 "2003-08-19T20:10:39Z")

</div>

I agree with **sailor** for garden variety executable attachments, but I’m not sure that’s entirely true for all situations, although I’m not knowledgeable enough to give a specific refutation. But if your email client supports HTML format, there are things that can be put in HTML that might do unwanted things. I think the techniques involve exploiting obscure security holes in the email client or browser rather than straightforward code. It may not kick in unless you actually click on a link on the page; as I said, I’m not sure. And I think this is rather rare.

This is not quite the same as a virus attachment, which is typically a .exe or .scr file that indeed you must explicitly execute for it to run.
