This knowledgebase article expands on our original security announcement:
https://jucra.com/whmcs/announcements/159/
Table of Contents
Overview
Email continues to be one of the most common methods used by cybercriminals to deliver malware, ransomware, steal credentials, and compromise business systems.
For this reason, JUCRA Digital blocks a specific list of attachment types that present an increased security risk.
These restrictions apply to both incoming and outgoing email handled by our SmarterMail platform.
Blocked Attachment Types
The following file extensions are currently blocked by our SmarterMail security policies:
.bat, .cmd, .com, .cpl, .dll, .docm, .dotm, .exe, .hta, .htm, .html, .img, .iso, .js, .jse, .lnk, .msi, .msp, .pif, .potm, .pptm, .ps1, .psm1, .rar, .reg, .scr, .sct, .svg, .vbe, .vbs, .vhd, .vhdx, .wsf, .wsh, .xlsm, .xltm, .zip
| Extension | Description |
|---|---|
| .bat | Windows Batch File |
| .cmd | Windows Command Script |
| .com | MS-DOS Application / Executable File |
| .cpl | Windows Control Panel Item |
| .dll | Dynamic Link Library |
| .docm | Microsoft Word Macro-Enabled Document |
| .dotm | Microsoft Word Macro-Enabled Template |
| .exe | Windows Executable Program |
| .hta | HTML Application |
| .htm | HTML Document |
| .html | HTML Document |
| .img | Disk Image File |
| .iso | ISO Disk Image |
| .js | JavaScript File |
| .jse | Encoded JavaScript File |
| .lnk | Windows Shortcut |
| .msi | Windows Installer Package |
| .msp | Windows Installer Patch |
| .pif | Program Information File |
| .potm | Microsoft PowerPoint Macro-Enabled Template |
| .pptm | Microsoft PowerPoint Macro-Enabled Presentation |
| .ps1 | PowerShell Script |
| .psm1 | PowerShell Module |
| .rar | RAR Archive |
| .reg | Windows Registry File |
| .scr | Windows Screen Saver Executable |
| .sct | Windows Script Component |
| .svg | Scalable Vector Graphics File |
| .vbe | Encoded VBScript File |
| .vbs | VBScript File |
| .vhd | Virtual Hard Disk |
| .vhdx | Hyper-V Virtual Hard Disk |
| .wsf | Windows Script File |
| .wsh | Windows Script Host Settings File |
| .xlsm | Microsoft Excel Macro-Enabled Workbook |
| .xltm | Microsoft Excel Macro-Enabled Template |
| .zip | ZIP Archive |
How Does This Work?
If an email contains one of the restricted attachment types listed above, the message will normally be rejected during the delivery process.
This applies to both incoming and outgoing email.
- If an external sender attempts to send a blocked attachment to a SmarterMail mailbox, the message can be rejected before reaching the recipient.
- If a SmarterMail user attempts to send a blocked attachment to an external recipient, the message can be rejected before leaving our platform.
The security system does not simply remove the attachment and continue delivering the rest of the message. In most cases, the complete message is rejected so that the potentially dangerous file cannot enter or leave the mail platform.
Why Are These Attachments Blocked?
Email attachments remain one of the most frequently exploited routes for malware, ransomware, credential theft, and business email compromise.
Attackers commonly disguise malicious files as invoices, quotations, delivery documents, shared files, account notifications, purchase orders, or other legitimate-looking business correspondence.
Archive formats such as ZIP and RAR can also be used to hide dangerous files inside another file, making them particularly attractive to attackers attempting to bypass email security systems.
Macro-enabled Office documents can execute embedded instructions, while executable and script files may run commands directly on a user's computer.
Blocking these file types at mail-server level significantly reduces the opportunity for this type of attack to reach users.
What Attachments Can I Still Send?
The restriction does not mean that normal email attachments are disabled.
Common business attachment types continue to be supported, including:
- PDF documents
- Microsoft Word .docx documents
- Microsoft Excel .xlsx spreadsheets
- Microsoft PowerPoint .pptx presentations
- JPG and JPEG images
- PNG images
- Text files
- Many other standard non-executable business file formats
Recommended Alternatives
If you need to transfer a blocked attachment, a collection of files, artwork files, fonts, software, archives, or folders, we recommend using a dedicated file-sharing service rather than email.
Suitable options include:
- JUCRA Secure File Upload: https://up.jucra.com
- Microsoft OneDrive
- Google Drive
- Dropbox
- WeTransfer
These systems are designed specifically for transferring and sharing files and provide a much more appropriate method than embedding potentially dangerous files directly inside email messages.
Where editing is not required, converting a document to PDF before sending it by email is also recommended.
Our Ongoing Commitment to Security
We appreciate that these restrictions may require some customers to adjust existing workflows, particularly where ZIP files or other archive formats have traditionally been exchanged by email.
However, security is an ongoing process and email remains one of the primary attack vectors used against businesses worldwide.
Our mail security policies are continually reviewed as threats evolve. The blocked attachment list may therefore change in the future where a file type becomes either significantly more dangerous or can safely be permitted again.
These attachment controls form part of a wider security strategy that includes spam filtering, malware protection, phishing detection, reputation monitoring, authentication controls, and ongoing threat analysis.