Winmail.dat Viewer & Extractor

Open winmail.dat files from Microsoft Outlook. View email content and extract attachments — all in your browser, nothing uploaded.

Your files stay safe — processed entirely in your browser. Nothing is uploaded.

Drop winmail.dat file here

or click to select a file

Supports winmail.dat files (TNEF format).


How to Open winmail.dat Files

If you've ever received an email with a mysterious attachment called "winmail.dat", you're not alone. This file is created by Microsoft Outlook when it sends emails using a proprietary format called TNEF (Transport Neutral Encapsulation Format). Non-Outlook email clients like Gmail, Apple Mail, and Thunderbird can't decode this format, leaving you with an unopenable attachment.

Our winmail.dat viewer extracts the original email content and attachments right in your browser. The file is parsed locally using our custom-built TNEF decoder — nothing is uploaded to any server, so your email content stays completely private.

1

Select Your winmail.dat File

Drag and drop your winmail.dat file onto the upload area, or click to browse and select it from your device. Only one file is processed at a time.

2

View Email Content

The tool automatically parses the file and displays the email subject, sender and message body, whether the body is stored as plain text, HTML or compressed RTF (rich text is shown without its formatting). When both a plain-text and an HTML version exist, you can switch between them.

3

Download Attachments

The attachments embedded in the winmail.dat file are listed with their file names, sizes, and types. Download each file individually, or use the "Download All as ZIP" button to get everything in a single archive.

The winmail.dat viewer after a file is dropped: the message body is shown, and the attachments trapped inside are listed with their names and sizes.
Screenshot What is inside the winmail.dat. The trapped attachments are listed, ready to save.

The parsing process is nearly instant for typical winmail.dat files. Since all processing happens locally in your browser using our custom TNEF parser, your email data — including any sensitive attachments — never leaves your device. You may also see this attachment written as win.dat, windat, "win mail dat" or ATT00001.dat depending on the mail client that delivered it — they are all the same TNEF file and this tool opens all of them.


How this winmail.dat viewer works

No JavaScript library decodes TNEF in the browser, so the parser behind this tool was written from scratch in TypeScript. That is why the file can stay on your device — there is no server step to fall back on.

TNEF is a flat sequence of attribute records. The parser reads the 0x223e9f78 signature, then walks each record's level, attribute id, length and payload.

Message attributes it reads
attSubject (0x8004), attFrom (0x8000, skipping the TRP header), attBody (0x800c) and the MAPI property block (0x9003). Unicode values from the MAPI block take priority over the legacy ANSI copies, which is what keeps accented and non-Latin subjects intact.
Attachment attributes it reads
attAttachRendData (0x9002) opens each attachment, then attAttachTitle (0x8010) and attAttachData (0x800f) supply the legacy name and bytes, with the per-attachment MAPI block (0x9005) carrying the better filenames.
Filename resolution order
PidTagAttachLongFilename (0x3707), then PidTagAttachFilename (0x3704), then PidTagDisplayName (0x3001), and only then the legacy ANSI attAttachTitle. Tools that read just the legacy field are the ones that turn Japanese filenames into mojibake.
Character encoding
The OEM codepage attribute (0x9007) is read first and decides how every following ANSI string is decoded — Shift_JIS (932), GBK, EUC-KR, Big5, the Windows-125x family or UTF-8. MAPI strings are decoded as UTF-16LE.
HTML bodies
An HTML body stored as HTML (PR_HTML) is decoded in the mail's own encoding, PR_INTERNET_CPID — often ISO-2022-JP for Japanese mail. It is untrusted input from a stranger, so it is sanitized with DOMPurify against an explicit tag and attribute allowlist, then rendered inside a sandboxed iframe whose content security policy lets it load nothing from the network: it cannot reach the surrounding page, and remote images that would tell the sender the mail was opened are never fetched.
Bodies stored as compressed RTF
Many winmail.dat files carry the body only as compressed RTF (PR_RTF_COMPRESSED, 0x1009). It is decompressed with the algorithm Microsoft publishes (MS-OXRTFCP). When the RTF wraps an HTML message (\fromhtml1, MS-OXRTFEX), the original HTML is recovered and treated like any other HTML body; other RTF is reduced to its text. If the RTF is damaged, the page says so instead of showing an empty body.

Where it stops

A body stored only as compressed RTF is shown, but one written as rich text comes out as plain text: fonts, colours and layout are dropped (an HTML message wrapped in RTF keeps its HTML). Emails attached inside it and embedded OLE objects are not extracted. Encrypted or signed S/MIME payloads inside a TNEF container are not decoded either, and because everything runs in a tab, a very large winmail.dat on a low-memory phone is bounded by that device's memory rather than by a server.


Frequently Asked Questions

What is a winmail.dat file?
A winmail.dat file is created by Microsoft Outlook when it sends emails using TNEF (Transport Neutral Encapsulation Format). This format bundles the email body, formatting, and attachments into a single binary file. Email clients other than Outlook can't decode this format, so they display it as a generic "winmail.dat" attachment.
Is it safe to open winmail.dat files with this tool?
Yes, completely safe. This tool parses the file entirely in your browser — no data is sent to any server. If the file contains HTML email content, it is sanitized with DOMPurify and displayed in a sandboxed iframe to prevent any potential security risks.
Why do I keep receiving winmail.dat files?
You receive winmail.dat files when someone sends you an email from Microsoft Outlook configured to use Rich Text Format (RTF). The TNEF encoding wraps the email content and attachments into a single file that non-Outlook clients can't read. You can ask the sender to switch to HTML or Plain Text format in their Outlook settings.
Can I extract attachments from winmail.dat?
Yes. This tool extracts the files attached inside the winmail.dat (PDF, Word, Excel, images and so on). Emails attached inside it and embedded OLE objects are not extracted. You'll see each attachment listed with its original file name and size. You can download them individually or all at once as a ZIP archive.
What types of content can be inside a winmail.dat file?
A winmail.dat file can contain the email subject, sender and recipient information, the email body (as plain text, HTML or RTF), and any file attachments. Common attachments include documents (PDF, Word, Excel), images, and other files that were sent with the original email.
How can I prevent sending winmail.dat files?
If you use Microsoft Outlook, go to File > Options > Mail, and under "Compose messages in this format", select "HTML" or "Plain Text" instead of "Rich Text". You can also change the format for individual contacts by editing their contact card and selecting "Internet Format: Send Plain Text Only".
Does this tool work on mobile devices?
Yes! The tool works on any device with a modern web browser, including smartphones and tablets. Simply open the page, select your winmail.dat file, and the tool will parse and display the contents.