Malware only needs one click to do considerable damage to your business. That click is still most often triggered the same way it always has been: a hyperlink to a spoofed login page, a Word or Excel file carrying a malicious macro, unpatched software, or a plain old file attachment paired with a convincing social engineering pitch (“invoice attached,” “please review,” “your delivery couldn't be completed”).
What has changed is how attackers get executables past the mail filter. Because most secure email gateways, SecurityGateway included, now block obviously dangerous file types by default, attackers have adapted their delivery methods rather than abandoning executables altogether:
- Archive smuggling: the payload is zipped or packed into a password-protected ZIP, RAR, or ISO/IMG disk-image file so a gateway can't “see” what's inside without unpacking it.
- HTML smuggling: an innocuous-looking HTML attachment reconstructs the malicious archive locally, inside the victim's browser, only after it's already past the gateway.
- Double extensions and disguised filenames: files like invoice_march.pdf.exe or a trailing-space trick are designed to look safe at a glance.
- Off-attachment delivery: QR codes (which SecurityGateway can block) and callback-phishing lures point the recipient toward a payload hosted somewhere else entirely, skipping the attachment scan altogether.
So the takeaway for administrators is that executable attachments are just as dangerous as they've ever been. Attackers have simply gotten better at hiding them. Blocking or quarantining executable file types at the gateway remains one of the most beneficial controls you can put in place, as it keeps them away from your mail server, and thus away from your users. It just needs to account for executables nested inside archives, not only the ones sitting in plain sight.
To help protect your business, SecurityGateway for Email can reject or quarantine incoming messages containing executable files. Watch our tutorial video below to see it configured step by step.
Setting up executable file protection
To configure executable protection in SecurityGateway:
- Define what counts as “executable” for your organization. The standard list includes .exe, .scr, .bat, .cmd, .com, .pif, .msi, .js, .vbs, .ps1, .jar, and .lnk. Extend or trim it to match your risk tolerance.
- Choose reject or quarantine. Rejecting stops the message outright; quarantining holds it for admin review, which is useful if your organization occasionally needs to receive legitimate executables (e.g., internal software distribution) after inspection.
- Layer it with SecurityGateway's other protections: multi-engine attachment scanning, Office macro screening, and Zero-Hour™ Outbreak Protection, so a file that slips past one check still gets caught by another.
These settings can be found under SecurityGateway's content filtering rules.
Why attachment filtering is so important
When attackers do rely on attachments, a disguised or archive-nested executable remains one of the most reliable ways to get a payload to actually run on a victim's machine. A malicious link can be clicked and abandoned, but a downloaded file that gets double-clicked executes immediately. At the same time, more attackers are shifting toward URL-based delivery (and SecurityGateway’s URIBL feature can block these) precisely because attachment filtering has gotten good enough to make file-based payloads a harder sell. That's a sign the control is working, not a reason to loosen it.
SecurityGateway combines executable and attachment filtering with broader protection: data leak prevention (DLP), full SPF/DKIM/DMARC/ARC enforcement, Dynamic Screening against brute-force and reconnaissance attempts, and location-based screening. Together, these give small and mid-sized businesses enterprise-class email security without an enterprise budget.
Click the button below to download your free trial!


