Is it a security risk to view an .eml file in a viewer?

0

This is not similar to Are .eml attachments a security risk? as the .eml file doesn't any attachment.

My supplier has some email issues he is sending so I sent him the .eml files to check it. Even I am doing him a favor he says that he is not going to view the .eml files with a viewer due to security risks and I have to understand it.

My questions:

  1. Is there any know security issue viewing an .eml file by a viewer, e.q. not in Outlook?
  2. Or, what can theoretically happen when the .eml file is viewed by any external viewer?

The .eml files I would send are generated by my Exchange based on emails he sent me and do not contain any attachment.

Al Bundy

Posted 2020-01-17T20:59:21.583

Reputation: 127

Answers

1

Can .eml files contain anything harmful?

Yes.

Will .eml files I create contain anything harmful?

No.

You can send anything you create knowing that it won't be harmful. The problem with .eml attached emails are that if you get them from someone you don't know, then it is possible the .eml contains a script that installs something on your system. In any case, this is always done purposely. Given that you create the .eml file yourself, this is not a security risk.

Do note that .eml files themselves are often forbidden email attachments by spam filters, so your message may be classified as spamming and not reach the destination.

There is nothing that prevents you from zipping the .eml file first and attach that to your email message instead.

So, after you get the .eml file, zip it, then email it.

LPChip

Posted 2020-01-17T20:59:21.583

Reputation: 42 190

The point is, their IT claims they are not going to open the .eml files with a viewer. They don't have Exchange so they need a viewer. And this is what I don't understand why viewing an .eml file with a viewer should be a security risk. – Al Bundy – 2020-01-17T21:17:07.863

If that's the problem, can't you export it to .html or something? That does not require anything. – LPChip – 2020-01-17T21:22:34.570

This doesn't answer my question. I am doing him a favor to sending him his emails back to check it and their IT which causes the issue just says We don't open the eml files because of security risks. Thank you for your understanding. Why should I bother with exporting/converting to PDF when they don't move a bit? So, my question is: Is there any security risk viewing an .eml file with an external viewer? – Al Bundy – 2020-01-17T21:26:02.250

My answer is If you trust the sender, then no. Their IT is just stupid. – LPChip – 2020-01-18T10:36:39.383