How the message looks
552 5.7.0 This message was blocked because its content presents a potential security issue. 552-5.7.0 Our system detected an illegal attachment on your message. Please visit https://support.google.com/mail/?p=BlockedMessage 550 5.7.1 Message content rejected due to attachment policy

What gets blocked

The large providers maintain fixed lists that do not depend on detection. Typically affected:

  • Executables — .exe, .msi, .bat, .cmd, .scr, .com, .pif.
  • Scripts — .js, .vbs, .hta, .wsf, .ps1.
  • Shortcuts — .lnk. A shortcut contains no code itself and still launches arbitrary programs; it is blocked across the board for that reason.
  • Disk images — .iso, .img, .vhd. They were widely used to bypass the mark-of-origin on downloaded files and have been on the lists ever since.
  • Macro-capable Office documents — .docm, .xlsm, .xlsb, and depending on the provider the legacy .doc and .xls too.

Crucially, the inspection reaches inside archives. An .exe in a ZIP is found, even several levels deep.

The three workarounds that do not work

  1. Renaming. Filters read the first bytes of the file. An executable disguised as .txt is recognisable by its signature, and the contradiction between extension and content is itself a suspicion marker.
  2. Password-protected archive. The classic false conclusion. An encrypted archive cannot be inspected — and what cannot be inspected gets rejected. Sending the password in the same mail deepens the suspicion, because that is exactly how malware is distributed.
  3. Double extension. invoice.pdf.exe is a well-known pattern that is actively searched for, not overlooked.

What actually helps

The only reliable route for executable content is not to mail it: store it and link to it, publish it in a repository, or share it through a file service the recipient knows. For documents the format is worth a look — a .docx without macros is unremarkable, a .docm with the same content is not.

If the block appears unexpectedly on a harmless file, check embedded objects: a PDF with an embedded attachment or an Office document with a linked object carries the objectionable type inside it.

Telling it apart

If the total size is the issue, the code reads 552 5.3.4. If the filter objects to the text or the linked domains, you get 550 5.7.350 or a general spam message. This one is exclusively a statement about the file type in the attachment.

Find the cause in the actual message

Send or forward the affected email to hello@analyzemy.email. For that exact message the report shows which IP sent it, how SPF, DKIM and DMARC turned out, and where the chain breaks.

Analyze your email now

Last updated: · All error messages