# How do I know if a PDF is safe to open? — DocFind

Last reviewed: October 4, 2026. HTML version: https://docfindapp.com/answers/know-if-a-pdf-is-safe

**You cannot tell from the file name or the icon, and no scanner can promise a PDF is clean. What you can do is check three things in order: whether the message it arrived in is genuine, what the automatic scanning in your email, cloud drive or browser has said about it, and whether the file tries to do anything beyond showing you pages once it is open.** The first check needs no software at all, so start there.

## What a PDF can try to do <p>A PDF is more than printed pages. Adobe's list of what sets off a security warning in Acrobat is a useful map of the risky parts: "Attempts to access external resources or websites", "Presence of JavaScript or other executable content", "Requests to run multimedia content", "Efforts to submit form data" and "Attempts to access or modify system settings" ([*Security warnings in PDFs*, Acrobat Desktop Help](https://helpx.adobe.com/acrobat/desktop/protect-documents/mitigate-security-risks/security-warnings.html), read 4 October 2026). Acrobat's Protected View opens an untrusted file read-only and holds back, among other things, "JavaScript execution and form filling". To leave it you select Enable All Features, and Adobe's condition for doing that is plain: "If you trust the PDF and where it came from, select Enable All Features" ([*Protected View and Protected Mode overview*, Acrobat Desktop Help](https://helpx.adobe.com/acrobat/desktop/protect-documents/use-protected-view/protect-view-mode.html), read 4 October 2026). So a warning bar on a PDF you did not expect is the point to stop, not a box to click past.</p>

## Check one: is the message genuine? <p>The UK's National Cyber Security Centre lists the pressure tactics that scams lean on, including *authority* ("your bank, doctor, a solicitor, or a government department") and *urgency* ("within 24 hours" or "immediately"). Its test for doubt is to go around the message: "contact the organisation directly. Don’t use the numbers or address in the message – use the details from their official website" ([*How to spot a scam email, text message or call*, NCSC](https://www.ncsc.gov.uk/collection/phishing-scams/spot-scams), read 4 October 2026). The US Cybersecurity and Infrastructure Security Agency adds that a familiar name is not enough: "Be wary of unsolicited attachments, even from people you know", because a return address can be spoofed. Its advice for a message that still feels wrong is blunt: "don't open it, even if your antivirus software indicates that the message is clean" ([*Using Caution with Email Attachments*, CISA](https://www.cisa.gov/news-events/news/using-caution-email-attachments), read 4 October 2026). That CISA page dates from 2021 and talks about attachments in general rather than PDFs in particular, but the advice transfers directly.</p>

## Check two: what the automatic scanning covers, and where it stops <p>**Gmail.** Gmail refuses some attachments outright, including "Documents with malicious macros", and publishes a list of blocked file types. The list runs to formats such as .exe, .js and .msi, and .pdf is not on it ([*File types blocked in Gmail*, Gmail Help](https://support.google.com/mail/answer/6590?hl=en), read 4 October 2026). The same page does not say how Gmail checks a PDF attachment that it lets through, so a PDF arriving in your inbox tells you only that its type was allowed.</p> <p>**Google Drive.** For work and school accounts, Google says it "will automatically evaluate any files that are shared with you from outside of your organization for phishing or malware" and blocks access if it finds a problem. Two caveats sit on the same page: "There's a 100MB scanning limit and some file types can't be scanned", and if a scan fails, "use caution when you open the file" ([*Learn how we help keep Google Drive secure*, Google Drive Help](https://support.google.com/drive/answer/141702?hl=en&co=GENIE.Platform%3DDesktop), read 4 October 2026).</p> <p>**Chrome.** Chrome "automatically blocks dangerous downloads", and lets you download anyway after a warning. Google's advice is to "take download warnings seriously", adding that "Attackers may ask you to turn off or ignore warnings to avoid antivirus detections" ([*Google Chrome blocks some downloads*, Google Chrome Help](https://support.google.com/chrome/answer/6261569?hl=en), read 4 October 2026). A PDF whose email tells you to ignore the warning has answered the question for you.</p>

## A second opinion, and what it costs you <p>VirusTotal will check a file against many engines at once; it says it "inspects items with over 70 antivirus scanners and URL/domain blocklisting services". The same page is open about where uploads go: "The contents of submitted files or pages may also be shared with premium VirusTotal customers" ([*How it works*, VirusTotal documentation](https://docs.virustotal.com/docs/how-it-works), read 4 October 2026). That makes it a reasonable check for an unexpected invoice from a stranger and the wrong one for your own payslip, contract or medical letter. Remember CISA's point too: a clean result lowers the risk, it does not remove it.</p>

## Check three: open it with the walls up <p>If the source checks out and you open the file, open it somewhere that limits what it can do. Which readers sandbox files, and how to turn off JavaScript in Acrobat, are covered on [what makes a PDF reader safe](https://docfindapp.com/answers/the-safest-pdf-reader), so we will not repeat them here. Once it is open, the warning signs are mostly behaviour rather than content:</p> <ul> <li>**It asks for something.** A prompt to enable features, allow a connection or run content is the file trying to do more than show pages.</li> <li>**It is only a button.** A one-page PDF whose whole content is a "view document" link or a sign-in request is a way of carrying a link past a mail filter. Treat the link as you would one in the email itself.</li> <li>**It carries a QR code.** The NCSC warns that criminals "are increasingly using QR codes within phishing emails" and that "you should be wary of scanning QR codes within emails" (the NCSC page above). A QR code inside an attached PDF arrives by the same route.</li> <li>**It does not match what you were told.** An "invoice" for a service you never used, or a "court notice" from an address that is not the court's, is the authority and urgency pattern again.</li> </ul> <p>Those four signs are our reading of the guidance above, not any one agency's checklist.</p>

## If you already opened it <p>Do not type a password into any page the PDF took you to. If you already have, change that password from the service's own site or app, and report the message: the NCSC page above links to reporting routes for scam emails, texts and websites in the UK.</p>

Related: [What is the safest PDF reader?](https://docfindapp.com/answers/the-safest-pdf-reader) · [Open a PDF without internet](https://docfindapp.com/answers/open-a-pdf-without-internet) · [Search a password-protected PDF](https://docfindapp.com/answers/search-a-password-protected-pdf) · [Search PDFs offline without uploading](https://docfindapp.com/answers/search-pdfs-offline-without-uploading)
