30 August 2026

What travels
inside a ZIP

Archives are assembled by dragging a folder. Whatever was in that folder goes too, including the files your operating system put there without telling you.

Nobody inspects a folder before zipping it

A ZIP is made by selecting a folder and compressing it. The mental model is “the files I put in there”. The reality is everything the folder contains, including the parts that are hidden from view in every file browser by default.

The usual passengers

On macOS, .DS_Store records every file that was in the folder when you last looked at it, including ones you removed before sending. Windows leaves Thumbs.db, which holds small copies of images that were there. Editors leave .swp and files ending in a tilde, which are usually the previous version of the document sitting beside it. None of these appear when you look at the folder.

The ones that matter more

If the folder came from development work, the risk changes character. A .env file holds API keys and database passwords in plain text. A .git directory contains the entire history of the project, including anything committed and later deleted — removing a password in a later commit does not remove it from the history. Files ending in .pem or named id_rsa are private keys, and a private key in someone else's hands is the access it was issued for.

And the files inside the files

Then there is the ordinary content. A folder of photographs carries the coordinates of wherever each one was taken. A proposal in the folder carries its author, its editing time, and possibly tracked changes. Zipping does not remove any of that; it just puts it out of sight behind one filename.

Check before you attach

The checker on this site reads archives: it lists what is inside, flags the file types that should not be in there, and looks inside the images and documents it finds to report what those carry. It runs in your browser, so a ZIP full of client work is not uploaded anywhere in order to be checked.

Try it