Guidance verification: Checked against current Microsoft Support documentation for classic Outlook and new Outlook for Windows, plus current Microsoft Learn documentation for Exchange Online attachment policies. Organization settings can change the available options.
Why Outlook blocks unsafe attachments
Outlook blocks file types that can run code or carry scripts because attachments remain a common route for malware. In classic Outlook, a Level 1 attachment can remain in the message while Outlook prevents normal open, save, print, or copy actions. New Outlook, Outlook on the web, mobile apps, Exchange Online, and third-party security products can apply additional controls.
The warning does not prove that the sender or file is malicious. It means the file type or message matched a security rule. Confirm the sender and the expected business purpose before trying another delivery method.
When email policy is the only obstacle, moving the collaboration to a separate chat workspace can keep the discussion and approved file together. Use only a company-approved location and keep access limited to the intended people.

Choose the safest supported route
The correct method depends on whether Outlook blocked access after delivery or the mail system rejected the whole message. Start with a permission-controlled sharing link. Use compression or renaming only when your organization allows those options and the recipient expects the file.
Share a OneDrive or SharePoint link
Upload the file to an approved OneDrive or SharePoint location, review its sharing permissions, and send a link instead of attaching the file. Grant access only to named recipients when the content is sensitive. A link also lets the owner remove access or replace the file without sending another copy.
Ask the recipient to confirm the sender, file name, and purpose before downloading. A cloud link changes the delivery method; it does not make an unsafe file safe.
Compress the file when policy permits
Microsoft documents ZIP compression as an option for files that Outlook will not attach. Create the archive, use a clear file name, and tell the recipient what it contains. Do not assume that compression bypasses company security.
Exchange Online mail flow rules can inspect compressed archives, detect executable content, identify password-protected files, or act on content that cannot be inspected. A ZIP file may therefore be delivered, rejected, or quarantined depending on policy.
Rename an extension only as a controlled fallback
Microsoft also documents temporarily renaming a blocked extension, then restoring it after the file is saved. Use this only with a trusted sender, an expected file, and an approved transfer process. Modern mail security can identify a file by its properties rather than its visible extension, so renaming is not a reliable bypass.
After restoring the original extension, scan the file with your organization’s security tools before opening it. Never enable macros or run code merely because the message came from a familiar address.
Use a registry exception only in classic Outlook
For advanced classic Outlook users on Windows, Microsoft documents the Level1Remove registry value as a way to allow selected extensions. Back up the registry first, add only the extension that is genuinely required, and restart Outlook. Remove the exception when the business need ends.
This is a local classic Outlook change, not an organization-wide fix. It does not override Exchange Online, Outlook on the web, new Outlook, mobile security, or a recipient organization’s rules. On managed devices, ask IT before editing the registry.
What administrators should check
When a message is rejected, quarantined, or never delivered, a mailbox user cannot solve the problem in Outlook. Exchange Online administrators can use anti-malware policies and mail flow rules to block selected extensions, executable content, oversized files, encrypted archives, or attachments that cannot be inspected.
Send IT the sender, recipient, time, subject, attachment name, extension, and any rejection notice. Those details help the administrator locate the event and identify the policy. The administrator can then decide whether the file should remain blocked, use an approved exception, or move through a controlled sharing service.
Avoid broad allow lists. A narrow exception for a required file type or approved workflow reduces exposure compared with disabling attachment protection for everyone.
How behavior differs by Outlook client
Classic Outlook for Windows has local attachment controls and the documented advanced registry option. New Outlook and Outlook on the web rely more heavily on mailbox and service policies. A file that behaves differently between clients may still be governed by the same Exchange or security policy, so opening another client should not be treated as a security workaround.
Outlook mobile also follows service and device-management controls. Do not forward a blocked executable to another device simply to get around the warning. Use an approved link or ask IT for a supported transfer route.
Troubleshoot the exact failure
- If Outlook displays the attachment but blocks access, ask the sender for an approved cloud link, ZIP archive, or controlled resend.
- If the sender receives a non-delivery report, provide that report to the mail administrator because a server-side rule probably acted before delivery.
- If the message is quarantined, follow the organization’s review process rather than asking the sender to disguise the file repeatedly.
- If a ZIP file is rejected, its contents, encryption, size, or inspectability may match an Exchange policy.
- If Outlook itself freezes while handling ordinary safe attachments, checking whether an add-in is causing a client problem can isolate a desktop issue. Safe mode does not relax attachment blocking.
- If only one recipient is affected, compare the recipient’s mailbox policy, device controls, and security group with those of an unaffected user.
Validate the file before requesting an exception
A blocked extension is a warning about capability, not proof that a specific file is malicious or safe. Confirm the sender through a separate trusted channel and ask what application created the file, why the original format is necessary, and what result the recipient needs. Unexpected executable, script, macro, or archive content should remain blocked until the security team reviews it.
Do not repeatedly rename extensions or place the file inside nested archives to defeat controls. Those actions can trigger additional defenses and remove useful context from the investigation. If the business need is simply to review data or a document, ask the sender for a safer exported format such as PDF, CSV, or a standard Office file without active content.
Use an approved review location
When security policy permits analysis, place the file in the organization’s approved quarantine, sandbox, or managed storage location. Restrict access to the designated reviewer and preserve the original message, sender, file name, and hash or security-alert details. Do not upload confidential attachments to a public scanning service.
After security approval, share through OneDrive or SharePoint with named recipients, limited permission, and an appropriate expiration when available. A link does not make unsafe content harmless; the file still needs validation before anyone opens it.
Make exceptions narrow and temporary
If a required file type remains blocked, the administrator should identify which control acted: Outlook client restrictions, Exchange mail flow, Safe Attachments, endpoint security, or another gateway. Apply an exception only to the necessary users, senders, or workflow and set a review date. Avoid tenant-wide allow rules for one delivery.
Test the approved route with a non-sensitive sample of the same type before transferring production data. Confirm that logging, malware scanning, and access controls still work.
Close the request by recording the business owner, approved format, transfer location, duration, and rollback step. Remove temporary registry or mail-flow exceptions when the need ends. This preserves Outlook’s protection while giving the team a repeatable path for legitimate files.
Questions about blocked Outlook attachments
Can I save one attachment that Outlook has already blocked?
For a Level 1 unsafe file, classic Outlook does not provide normal open, save, print, or copy actions, even though the attachment can remain inside the message. Ask the sender to upload the file to OneDrive or SharePoint and send a sharing link. A compressed archive or a temporarily renamed extension can also work, but verify the sender and scan the restored file before opening it.
Why is a ZIP file still being rejected?
A ZIP archive does not override company security. Exchange Online administrators can block selected extensions, executable content, oversized attachments, encrypted archives, or files that cannot be inspected through anti-malware policies and mail flow rules. If the message is rejected, quarantined, or never arrives, send the notice and timestamp to your mail administrator so they can identify the policy that acted on it.
Will a registry exception unblock attachments for everyone?
No. The Level1Remove registry value is an advanced, per-user option for classic Outlook on Windows, and Microsoft recommends allowing only file types that are genuinely required. It does not replace Exchange, Outlook on the web, or organization-wide security controls. Back up the registry before editing it, restart Outlook after the change, and remove the exception when the business need ends.
What is the safest way to exchange a file Outlook considers unsafe?
Store the file in an approved OneDrive, SharePoint, or managed network location and share a permission-controlled link instead of attaching the file. Give access only to the intended recipients and choose view or edit permission deliberately. The recipient should confirm the sender, expected file name, and purpose before downloading, then scan the file with the organization’s security tools. If policy still blocks access, ask an administrator to approve a supported transfer method rather than repeatedly changing extensions.