To scan a file's contents, a scanner needs the file's bytes. So in most cases you cannot fully check a file that is still on someone else's server. But there is a lot you can check first, and downloading a file is not the same as running it.
Downloading is not the same as opening
Saving a file to your Downloads folder doesn't execute it. The danger begins when you open or run it. The safest workflow for most people is: download, don't open, scan, then decide. With the iMalware scanner, the "scan" step takes seconds and the file still never leaves your device.
What you can check before downloading
The link or website
URL scanners such as VirusTotal's URL tab or urlscan.io visit a link on your behalf and report whether it is known to be malicious. Your browser's built-in protection (Google Safe Browsing in Chrome and Firefox, Microsoft Defender SmartScreen in Edge) also warns about known malicious downloads.
A published hash
If the download page lists an MD5 or SHA-256 checksum, you can search that hash before downloading — paste an MD5 into our hash lookup, or search a SHA-256 on VirusTotal. After downloading, compare your file's hash with the published one.
Email attachments
Gmail, Outlook.com and most business email services already scan attachments and block known malicious file types such as .exe. That doesn't catch everything, so still be wary of unexpected attachments, especially archives and macro-enabled documents.
Cloud storage
Google Drive scans files below a size limit and warns on larger ones that they are "too large to scan". See what that warning means.
iPhone and iPad attachments
iOS doesn't let apps or downloaded files install or run code outside the App Store's sandboxed apps, and Messages processes attachments in a restricted environment. The realistic risks on iPhone are phishing links and fake login pages, not a "virus" in a photo. Keep iOS updated; people at high risk of targeted attacks can turn on Apple's Lockdown Mode, which limits attachment types and link previews in Messages.
Checking a file you already downloaded
- Don't open it.
- Drop it onto the iMalware scanner — it isn't uploaded, so this is fine for private documents.
- On Windows, also right-click it and choose Scan with Microsoft Defender.
- For programs, check the digital signature and the publisher (see is this file malware?).
Frequently Asked Questions
Do I have to download a file to check it for malware?
To scan its contents, yes: a scanner needs the file. But you can check the link with a URL scanner and search a published hash first. Downloading without opening is generally safe, and you can scan the file before running it.
Can I get a virus just by downloading a file?
Rarely. Most malware needs you to open or run the file. Keep your browser and operating system updated to protect against the rare exploits that don't.
Does iMalware upload my file?
No. The file is hashed inside your browser and only the first three characters of its MD5 hash are requested from our server. The full hash is compared on your device.
Can an iPhone get a virus from a text message attachment?
It is very unlikely for normal users because iOS apps are sandboxed. Phishing links in messages are the real risk. Keep iOS updated, and consider Lockdown Mode if you face targeted threats.