We block executable files and we scan compressed files for executable content. Do people still allow compressed files through mail? Was thinking of adding this to our block list but haven't found time to search if it's now best practice to block it. our Fortigate firewall is usually quite quick in blocking those dodgy websites through clickable links. But again those zero day attacks are difficult.