Ask Leo! by Leo A. Notenboom

Is plain text email safer?

Search First! Then browse: Categories | Full Archive | By Date | Newsletter

Home » EMail » Using Email

Summary: HTML email can include embedded malware, plain text cannot. So just how risky is HTML formatted email?

Do you think that disabling HTML provides much extra safety in using email?

A small amount.

HTML (and rich text) email allows you to specify various attributes in your email like bold, italics and even color text red.

Plain text is, well, it's plain.

The "problem" is that because HTML is also the way that web pages are encoded, it can often do more than just change the look of your text. Much more.

In the past, the problem was fairly large, as things could be embedded in HTML that could in turn compromise your system when the message was simply displayed. In fact, it was even worse, because the original versions of the "preview pane" would display messages automatically, and thus give that embedded malware an automatic opportunity to infect you.

Nowadays with anti-virus, coupled with preview and image display being off by default, and further coupled with keeping your machine up to date with the latest patches and updates - the threat is extremely small.

But, technically, it is still there.

"There is no way to embed malware into plain text email other than by using attachments ..."

Not long ago an exploit was discovered in the VRML renderer that could be used with in HTML email. If you displayed the email, you were vulnerable. A patch resulted, but there was a window of opportunity. (As always, that window remains wide open for those who do not stay up to date.)

But there's no vulnerability associated with plain text email. There is no way to embed malware into plain text email other than by using attachments which in turn must be manually executed to have any effect.

So there's some legitimacy to the issue. Certainly in highly sensitive areas, I would expect HTML to be disabled as no risk is acceptable, especially one that can be so easily worked around. However, personally, I deal with HTML email all the time. I prefer to send plain text, but for different reasons:

  • plain text looks the same everywhere (most definitely not guaranteed for HTML mail)

  • email messages using only plain text are smaller

  • overuse of fancy formatting can easily detract from the message

  • 9 times out of 10, it's simply not necessary

If security is an issue, and you don't want to risk displaying HTML email, an alternative is to use an email client which will display HTML email as text. By that I mean that there are email clients that will display the text contents of an HTML mail without trying to interpret or display the HTML itself.

Related:

Helpful? Get new articles weekly by email in my FREE newsletter!

Your Name:
Your Email:


Why Subscribe?

Article C2975 - March 25, 2007

Recent Comments
2 Comments

You could also use any email anti-theft software. Basically it'll ensure that all the emails you receive are well protected and virus/malware free!

Posted by: mroonie at March 26, 2007 11:59 AM

Where the recipients can receive HTML, I generally recommend it for formatting. I don't like plain text except in certain circumstances:

Most companies that insist on plain text email will accept HTML format but will deliver plain text to its end users, who then of course reply in plain.

For space reasons some methods of internet access will only allow plain, such as WAP phones or webmail, even if the ISP normally handles HTML.

But the only time I'll choose to use plain text is if I'm forwarding text-only jokes to a number of people - I always send in plain text so it won't take up so much space at the recipients.

Posted by: Zap Coffey-Brittain at April 1, 2007 5:30 PM

Post a comment on "Is plain text email safer?":






(Email Address will not be published.)

Remember Me?

By popular demand...
my tip jar
Cuppa Joe
Buy Leo a Latte!

(you may use HTML tags for style)

RSS feed Subscribe to the RSS Feed specifically for comments on this article.

Before commenting, please...

  • Read the article at the top of this page. If your comment shows you didn't, it'll be deleted and ignored.

  • Comment only on this article. Use the Google search box at the top of the page if you have a question about something else.

  • Don't include personal information in the comment. No email addresses. No phone numbers. No physical addresses.

  • Don't spam. Excessive links to unrelated sites within a comment or across multiple comments will cause all such comments to be removed.

  • Don't ask me to recover lost passwords or hacked accounts. I can't, and those comments will be deleted.

  • I can't respond to every comment. And I can't vouch for the accuracy of others who do.

Please wait. Your comment is being processed ...


Question? Ask Leo!