viewhack

Open a winmail.dat attachment

An e-mail from an Outlook user arrived with nothing but a file called winmail.dat or ATT00001.dat. The real attachments and the formatted message are packed inside it. Drop it here to read the message and save each file.

The file is read on your device. It is never uploaded, and nothing in it is loaded from the internet.

What it shows

What it cannot do

Useful to know about winmail.dat

Why you got a winmail.dat
Outlook and Exchange write messages in TNEF (Transport Neutral Encapsulation Format), a Microsoft format for passing rich text, attachments and meeting details between Outlook clients. When the sender's message is set to Rich Text and it leaves for someone outside Exchange, Outlook packs all of that into one MIME part of type application/ms-tnef, named winmail.dat. Gmail, Apple Mail, Thunderbird and phone mail apps do not unpack it, so you see the wrapper instead of the files. Some clients rename it ATT00001.dat.
How the sender can stop it
In Outlook for Windows: File › Options › Mail › Compose messages in this format: HTML. A message already open in Rich Text can be switched under Format Text › HTML before sending. An Exchange Online administrator can stop it for all outgoing mail with Set-RemoteDomain Default -TNEFEnabled $false in Exchange Online PowerShell.
What is inside the file
It starts with the four bytes 78 9F 3E 22 (the signature 0x223E9F78, stored little-endian), then a list of attributes: message attributes such as the subject and the body, and attachment attributes for each file's name, data and properties. Each attribute ends with a two-byte checksum, the sum of its bytes. The format is published by Microsoft as [MS-OXTNEF]; this page reads it with code written from that specification.
A winmail.dat with no files in it
Sometimes the .dat holds only the formatted body and no attachments: the sender sent a Rich Text message with nothing attached. The text above is then the whole message.