Reviewed September 15, 2026

How to Unzip Files Safely on Windows, Mac, or in Your Browser

Extract ZIP archives into a clean destination, avoid overwriting important files, and verify suspicious or unusually large archives before opening content.

Inspect the archive before extraction

Treat the ZIP as a container, not as proof that the files inside are safe. If the archive came from an unfamiliar sender, verify the sender and expected contents first. Save it to a known folder instead of opening random entries directly from an email preview.

Extract into a new folder, not over your working files

Create a dedicated destination so you can inspect the result without overwriting an existing project. This is especially important when the ZIP contains common names such as report.xlsx, config.json, index.html, or photos/.

  1. 1
    Create a destination

    Use a new folder such as ArchiveName_extracted.

  2. 2
    Extract the whole archive

    Use Windows Extract All, Finder, or a trusted browser-local extractor.

  3. 3
    Review the folder tree

    Look for unexpectedly deep nesting or files outside the expected project structure.

  4. 4
    Open representative files

    Verify documents, images, data, and any README before moving content elsewhere.

Built-in Windows and Mac extraction

Windows File Explorer provides Extract All for ZIP files. macOS Finder normally expands a ZIP by double-clicking it. These built-in workflows are suitable for ordinary archives; browser tools are useful when you want a preview or selective extraction without installing software.

Watch for expansion ratio and archive bombs

Compressed size is not the same as extracted size. Highly repetitive data can compress dramatically, so an archive that looks small can consume large storage or memory when expanded. A cautious extractor should cap file count, total uncompressed size, individual entry size, and nesting depth rather than trusting the compressed byte count alone.

SignalWhy it mattersPractical response
Thousands of entriesCan overwhelm the browser/file systemPreview counts before extracting
Huge uncompressed totalCan exhaust disk or memoryStop if expansion exceeds your expected workload
Nested ZIP inside ZIPCan hide repeated expansionDo not recursively expand unknown archives automatically
../ or absolute pathsMay attempt path traversalReject or normalize unsafe archive entry paths

After extraction, verify before editing

Compare file counts and expected names with the sender's instructions. For software downloads, datasets, or regulated handoffs, verify a published checksum when one is available. If the archive is a submission package, open the files from the extracted copy so you know the recipient will be able to do the same.

Password-protected ZIPs need compatible encryption support

A password prompt does not tell you which ZIP encryption method was used. Built-in OS tools and browser libraries do not support every encrypted archive variant. If a known-good password fails, confirm the encryption method and use a current compatible archive tool rather than assuming the sender typed the password incorrectly.

Share passwords through a separate trusted channel when practical; putting the archive and password in the same email reduces the value of the protection.

Scenario: a supplier sends specs.zip unexpectedly

You expected a PDF drawing, but the email contains specs.zip. Before extraction, confirm the sender/thread, list the archive entries, check expanded size and inspect extensions. If it contains drawing.pdf plus an unexpected executable such as viewer.exe, you can extract or download only the expected document and escalate the executable instead of launching it.

The safe conclusion is not ‘ZIP is dangerous’; it is ‘the archive is a container, so inspect its contents and source independently’.

Unknown archive review
1
Verify source

Was this archive expected from this sender?

2
List entries

Names, extensions, count and expanded size.

3
Reject unsafe paths

Absolute and traversal paths stay contained.

4
Extract to new folder

Do not overwrite working files.

5
Open selectively

Only expected files with normal security controls.

Understand common extraction errors before trying random tools

Keep the original archive while troubleshooting. Repeatedly extracting over the same destination can make it harder to distinguish a partial old result from the newest attempt.

ErrorPossible meaningNext step
CRC / data errorArchive/entry may be corrupted or transfer incompleteObtain a fresh copy; compare checksum if available
Unexpected end of archiveTruncated download or missing split partRedownload/obtain all parts
Unsupported compression/encryptionExtractor lacks the methodUse a current compatible utility from a trusted source
Wrong passwordPassword wrong or encryption support differsConfirm password/method separately
Path/filename failurePlatform path length/reserved-name conflictExtract to shorter clean path or use compatible tooling

Extraction success does not mean every extracted file is safe or useful

After extraction, apply normal file-security and application rules. An executable remains executable; a macro-enabled document can still contain active content; a shortcut can still point somewhere unexpected. The ZIP layer only packaged the files.

If the archive is part of evidence or a controlled transfer, keep the original ZIP and consider recording its checksum before moving or editing extracted files. The archive provides a stable reference to what was received even if working copies later change.

Primary references and current-source checks

Requirements, policies and platform guidance can change. Recheck these sources when the decision matters.

Microsoft Support — Zip and unzip files ↗Apple Support — Compress and uncompress files and folders ↗
Use the browser tool

Apply the workflow to your own file or trade record.

Open Unzip Files