Open a winmail.dat attachment
An e-mail from an Outlook user arrived with nothing but a file called winmail.dat or ATT00001.dat. The real attachments and the formatted message are packed inside it. Drop it here to read the message and save each file.
The file is read on your device. It is never uploaded, and nothing in it is loaded from the internet.
What it shows
- Every file inside, with its full name, type and size, each saved from this tab byte for byte, or all of them at once as one .zip. Outlook stores a short 8.3 name (
QUICK~1.HTM) beside the long one (quick.html); the long name is used, so non-Latin names such asÜberblick – 第3四半期.txtcome out right. - The message. A winmail.dat usually holds the body as compressed RTF, Outlook's rich-text format. It is decompressed here and shown as text, and can be saved as an .rtf that Word, WordPad, TextEdit or LibreOffice open with the formatting. When the RTF is really HTML that Outlook wrapped, the HTML is unwrapped and shown in a locked-down frame: scripts are removed, and every remote image, stylesheet or font is blocked and counted, so the sender cannot see that you opened it.
- Who and when, when the file has them: subject, sender, recipients and the time it was sent, in UTC and in your own time zone. Many winmail.dat files carry none of these, because Outlook leaves them in the e-mail around the attachment.
- Attached messages. An e-mail forwarded as an attachment sits inside as a complete message of its own. It is listed with its subject, opens right here with its own text and attachments, and can be saved as its own .dat file.
- Meeting requests. An invitation sent as winmail.dat (class
IPM.Microsoft Schedule.MtgReq) shows its start, end and location in your time zone. - Damage, said plainly. Every part of a TNEF file carries a checksum. A part whose checksum does not match, or a file that was cut off, is reported with where it went wrong, and everything that could still be read is shown.
What it cannot do
- Send or reply. This page only reads the file. To answer the sender, reply from your own mail program.
- Protected messages. A message encrypted with S/MIME can only be opened with the recipient's private key, and a rights-protected one (IRM, “Do Not Forward”, an encrypting sensitivity label) only by Outlook signed in to the recipient's account. The page says when a message is protected, and shows no text it cannot decrypt.
- Check files for viruses. Nothing is scanned. A file from a stranger can be harmful whatever its name says; check it before you open it.
- Embedded objects. An object pasted into the message (an Excel chart inserted as an object, say) is saved as the raw OLE data Outlook stored, which few programs open on their own.
- Calendars beyond the time and place. No calendar view, recurrence rule or reply buttons for a meeting request. For a whole calendar file use the .ics viewer.
- Compress the .zip. “Save all” stores the files without compressing them, so it is made instantly and is about the size of the files added together.
Useful to know about winmail.dat
- Why you got a winmail.dat
- Outlook and Exchange write messages in TNEF (Transport Neutral Encapsulation Format), a Microsoft format for passing rich text, attachments and meeting details between Outlook clients. When the sender's message is set to Rich Text and it leaves for someone outside Exchange, Outlook packs all of that into one MIME part of type
application/ms-tnef, named winmail.dat. Gmail, Apple Mail, Thunderbird and phone mail apps do not unpack it, so you see the wrapper instead of the files. Some clients rename it ATT00001.dat. - How the sender can stop it
- In Outlook for Windows: File › Options › Mail › Compose messages in this format: HTML. A message already open in Rich Text can be switched under Format Text › HTML before sending. An Exchange Online administrator can stop it for all outgoing mail with
Set-RemoteDomain Default -TNEFEnabled $falsein Exchange Online PowerShell. - What is inside the file
- It starts with the four bytes
78 9F 3E 22(the signature 0x223E9F78, stored little-endian), then a list of attributes: message attributes such as the subject and the body, and attachment attributes for each file's name, data and properties. Each attribute ends with a two-byte checksum, the sum of its bytes. The format is published by Microsoft as [MS-OXTNEF]; this page reads it with code written from that specification. - A winmail.dat with no files in it
- Sometimes the .dat holds only the formatted body and no attachments: the sender sent a Rich Text message with nothing attached. The text above is then the whole message.