There was a problem loading the comments.

cPanel: Default attachments on incoming emails that are blocked on IndicHosts.net email servers.

Support Portal  »  Knowledgebase  »  Viewing Article

  Print

cPanel's Exim configuration, by default, blocks a list of potentially dangerous attachment file extensions to protect against viruses and malware.  While the exact list can vary slightly with updates, here's a common set of extensions that are typically blocked:

 

Executable files and scripts:

    • .ade
    • .adp
    • .bas
    • .bat
    • .chm
    • .cmd
    • .com
    • .cpl
    • .crt
    • .exe
    • .hlp
    • .hta
    • .inf
    • .ins
    • .isp
    • .js (JavaScript)
    • .jse (JScript Encoded Script File)
    • .lnk (Windows Shortcut)
    • .mda
    • .mdb2
    • .mde
    • .mdz
    • .msc
    • .msi
    • .msp
    • .mst
    • .pcd
    • .pif (Program Information File)
    • .reg (Registry Entry File)
    • .scr (Screen Saver)
    • .sct (Windows Script Component)
    • .shs (Shell Scrap Object)
    • .url (Internet Shortcut)
    • .vb (VBScript File)
    • .vbe (VBScript Encoded Script File)3
    • .vbs (VBScript File)
    • .wsc (Windows Script Component)
    • .wsf (Windows Script File)
    • .wsh (Windows Script Host Settings File)
  • Other potentially problematic files:

    • .eml (email message files - often blocked because they can contain embedded malicious content or reference external malicious content)
    • .jar (Java Archive)
    • .ace (ACE Archive)
    • .r00 (part of a multi-volume ACE archive)
    • .iso (Disk Image File)
    • z (Unix Compressed File)

Important Notes:

  • Security Focus: The primary reason for blocking these attachments is security, as they are frequently used in phishing, malware, and virus attacks.
  • Customization: While these are the defaults, cPanel and Exim allow server administrators to customize these blocked lists through the Exim Configuration Manager in WHM (Web Host Manager).  You can whitelist or blacklist additional extensions as needed.
  • Packaging: If you need to send files with these extensions, the usual recommendation is to compress them into a .zip file or another non-executable archive format, which can then be safely transmitted. But we block .zip on incoming emails on some servers on client's requirements.  
  •  Evolution of Threats: The list of blocked extensions may be updated over time by cPanel as new threats emerge.

Share via
Did you find this article useful?  

Related Articles


Comments

Add Comment

Replying to  


Self-Hosted Help Desk Software by SupportPal
© Indichosts.net