Scanning a file you were sent
The useful question is not “is this a virus” but “was I expecting this file”. The scan supports that judgement, it does not replace it.
Antivirus scans a file with AI-driven detection, works on any file type, returns a threat intelligence report with a confidence score, and keeps a history of what you have scanned.
Read the confidence score as a probability, not a verdict
A high score on a file you did not expect is a strong signal. A low score on the same file is a weak reassurance, because the honest limit of any scanner is that it recognises what resembles known threats.
So treat the number as one input. The other input is context: did you ask for this attachment, does the sender normally send files, does the extension match what the message claims. A clean scan on an unexpected invoice from an address you half-recognise is still an unexpected invoice.
The habit worth having
Scan before opening, not after something feels wrong. That sounds obvious and almost nobody does it, because opening is one click and scanning is two.
The case it actually earns its place: files that arrive through channels where you cannot control the sender — a community inbox, a shared drive a client uploads to, a CV attachment. Internal files from colleagues are a different risk profile and scanning every one of them is theatre.
The history is the part people ignore
Scan history matters after an incident rather than before one. If something did get through, the record of what was scanned, when, and what the result was turns a vague worry into a specific timeline.
It also settles the question that always comes up: whether the file that caused a problem was ever checked at all.
Questions people actually ask
Does a clean result mean the file is safe?
It means nothing recognisable was found. That is useful but not a guarantee — pair it with context, especially whether you were expecting the file and whether the sender normally sends attachments.
Which files are actually worth scanning?
Anything from a source you do not control: a community inbox, a client upload, an unsolicited attachment. Scanning every internal file from a colleague is theatre and it trains people to click through the result.
Does scanning cost tokens?
Yes, detection is an AI operation and draws from your balance like any other. That is another reason to scan what actually warrants it rather than everything.