Inspect the archive before extraction
Treat the ZIP as a container, not as proof that the files inside are safe. If the archive came from an unfamiliar sender, verify the sender and expected contents first. Save it to a known folder instead of opening random entries directly from an email preview.
Extract into a new folder, not over your working files
Create a dedicated destination so you can inspect the result without overwriting an existing project. This is especially important when the ZIP contains common names such as report.xlsx, config.json, index.html, or photos/.
- 1Create a destination
Use a new folder such as ArchiveName_extracted.
- 2Extract the whole archive
Use Windows Extract All, Finder, or a trusted browser-local extractor.
- 3Review the folder tree
Look for unexpectedly deep nesting or files outside the expected project structure.
- 4Open representative files
Verify documents, images, data, and any README before moving content elsewhere.
Built-in Windows and Mac extraction
Windows File Explorer provides Extract All for ZIP files. macOS Finder normally expands a ZIP by double-clicking it. These built-in workflows are suitable for ordinary archives; browser tools are useful when you want a preview or selective extraction without installing software.
Watch for expansion ratio and archive bombs
Compressed size is not the same as extracted size. Highly repetitive data can compress dramatically, so an archive that looks small can consume large storage or memory when expanded. A cautious extractor should cap file count, total uncompressed size, individual entry size, and nesting depth rather than trusting the compressed byte count alone.
| Signal | Why it matters | Practical response |
|---|---|---|
| Thousands of entries | Can overwhelm the browser/file system | Preview counts before extracting |
| Huge uncompressed total | Can exhaust disk or memory | Stop if expansion exceeds your expected workload |
| Nested ZIP inside ZIP | Can hide repeated expansion | Do not recursively expand unknown archives automatically |
| ../ or absolute paths | May attempt path traversal | Reject or normalize unsafe archive entry paths |
After extraction, verify before editing
Compare file counts and expected names with the sender's instructions. For software downloads, datasets, or regulated handoffs, verify a published checksum when one is available. If the archive is a submission package, open the files from the extracted copy so you know the recipient will be able to do the same.
Password-protected ZIPs need compatible encryption support
A password prompt does not tell you which ZIP encryption method was used. Built-in OS tools and browser libraries do not support every encrypted archive variant. If a known-good password fails, confirm the encryption method and use a current compatible archive tool rather than assuming the sender typed the password incorrectly.
Share passwords through a separate trusted channel when practical; putting the archive and password in the same email reduces the value of the protection.
Scenario: a supplier sends specs.zip unexpectedly
You expected a PDF drawing, but the email contains specs.zip. Before extraction, confirm the sender/thread, list the archive entries, check expanded size and inspect extensions. If it contains drawing.pdf plus an unexpected executable such as viewer.exe, you can extract or download only the expected document and escalate the executable instead of launching it.
The safe conclusion is not ‘ZIP is dangerous’; it is ‘the archive is a container, so inspect its contents and source independently’.
Was this archive expected from this sender?
Names, extensions, count and expanded size.
Absolute and traversal paths stay contained.
Do not overwrite working files.
Only expected files with normal security controls.
Understand common extraction errors before trying random tools
Keep the original archive while troubleshooting. Repeatedly extracting over the same destination can make it harder to distinguish a partial old result from the newest attempt.
| Error | Possible meaning | Next step |
|---|---|---|
| CRC / data error | Archive/entry may be corrupted or transfer incomplete | Obtain a fresh copy; compare checksum if available |
| Unexpected end of archive | Truncated download or missing split part | Redownload/obtain all parts |
| Unsupported compression/encryption | Extractor lacks the method | Use a current compatible utility from a trusted source |
| Wrong password | Password wrong or encryption support differs | Confirm password/method separately |
| Path/filename failure | Platform path length/reserved-name conflict | Extract to shorter clean path or use compatible tooling |
Extraction success does not mean every extracted file is safe or useful
After extraction, apply normal file-security and application rules. An executable remains executable; a macro-enabled document can still contain active content; a shortcut can still point somewhere unexpected. The ZIP layer only packaged the files.
If the archive is part of evidence or a controlled transfer, keep the original ZIP and consider recording its checksum before moving or editing extracted files. The archive provides a stable reference to what was received even if working copies later change.
Primary references and current-source checks
Requirements, policies and platform guidance can change. Recheck these sources when the decision matters.
Microsoft Support — Zip and unzip files ↗Apple Support — Compress and uncompress files and folders ↗