Outlook's New Blocklist Just Made MSIX Attachments a Headache

·
Listen to this article~4 min

Microsoft is blocking .msix and .msixbundle attachments in Outlook Web and the new Outlook for Windows next month. Here's what changes and how to work around it.

Microsoft dropped a quiet little bombshell for anyone who regularly sends or receives app packages through email. Starting next month, Outlook Web and the new Outlook for Windows will block .msix and .msixbundle attachments. If that sounds like a niche IT problem, stick with me — it actually touches a lot of people who work with Windows apps every day. ### What Exactly Is Changing? Microsoft is adding those two file types to its existing list of blocked attachments. That list already includes stuff like .exe, .bat, and other formats that can carry malware. The goal is simple: stop dangerous files from sliding into your inbox disguised as something harmless. MSIX isn't some random format, though. It's Microsoft's modern packaging system for Windows apps. Developers use it to distribute software cleanly, and IT teams use it to push internal tools across a company. So blocking it isn't just about safety — it changes how real work gets done. ### Why Microsoft Is Doing This Here's the thing. Any attachment format that can execute code is a potential doorway for attackers. MSIX packages can install software, and that means they can carry malicious payloads just like a traditional .exe file. - Attackers love formats people trust - Email remains the number one delivery method for malware - Blocking at the client level is faster than waiting for users to think twice Microsoft would rather inconvenience a few legitimate users than let a single nasty package slip through. It's a trade-off, and honestly, it's the safer bet. ### Who Actually Gets Hurt By This? If you're a developer shipping test builds to colleagues, this stings. If you're in IT and you email internal apps to remote staff, same deal. And if you're someone who manages multiple accounts or works across different environments — say, running an antidetect browser to keep your sessions separate — you're probably used to moving files around quickly. > "Security rules rarely break the people they're meant to protect. They break the people who were using the shortcut." That's basically what's happening here. The shortcut was email. Now you need a different route. ### What Are Your Options? You've got a few practical workarounds, and none of them are painful once you set them up. - Use a cloud drive like OneDrive, Google Drive, or Dropbox and share a link instead - Host the package on an internal server or file share - Use Microsoft Intune or another device management tool to push apps directly - Zip the file — though be careful, since some filters still catch zipped executables The cloud link approach is usually the easiest. It takes about thirty seconds to set up and it sidesteps the block entirely. ### What This Says About Email Security This isn't really about MSIX. It's about the bigger trend of email becoming a locked-down channel. Over the past few years, Microsoft has steadily tightened what can pass through Outlook, and this is just the next step. The lesson for anyone working online — whether you're a developer, a marketer, or someone juggling multiple accounts — is that you can't rely on email as a file delivery system anymore. It's becoming a communication tool first and a transport tool second. ### The Bottom Line If you send MSIX files through Outlook, plan ahead. The change lands next month, and once it does, those attachments simply won't go through. Set up a cloud share, tell your team, and move on. It's a small adjustment, but ignoring it will cost you a confusing afternoon wondering why your emails keep bouncing back.