How to Fix PDF Attachment Preview Issues in C# Encrypt-Only Emails
Question details
Recipients of encrypt-only Microsoft 365 emails sent via a C# Web Forms application cannot preview PDF attachments within their email client.

- Product
- C# SmtpClient / Microsoft 365
- Device & OS
- not provided
- Scenario
- Sending protected Microsoft 365 emails programmatically using C# Web Forms and SmtpClient.
- Observed behavior
- Recipients are unable to preview attached PDFs; instead, they must download the files, open them in a supported reader, and authenticate using a one-time passcode.
Ensure you have access to your C# source code to modify the MailMessage properties and administrative access to the Microsoft Purview portal if policy adjustments are required.
Set the Correct MIME Type for the PDF Attachment
Explicitly defining the MIME type helps the recipient's email client recognize the file as a PDF, which is essential for triggering built-in preview handlers.
When attaching files programmatically using the SmtpClient and Attachment classes in C#, omitting the MIME type can cause the email client to treat the file as a generic binary stream (application/octet-stream). Setting it correctly to 'application/pdf' ensures the client attempts to render it properly.
Open your C# Web Forms project and find the method responsible for constructing the MailMessage and attaching the PDF.
When instantiating the Attachment object, pass 'application/pdf' as the media type parameter. For example: new Attachment(fileStream, "document.pdf", "application/pdf").
Ensure the correctly configured Attachment object is added to the MailMessage.Attachments collection before calling SmtpClient.Send().

Review Azure Information Protection (AIP) Settings
Microsoft 365 'Encrypt-Only' policies may strictly enforce DRM rules that intentionally block web-based previews to prevent data leakage.
View and Secure PDFs Locally with WPS Office
If Microsoft 365 encryption is causing preview complications and deployment hurdles, consider managing your PDFs with WPS Office. It provides robust PDF viewing, editing, and built-in password encryption that remains highly compatible without relying on complex programmatic DRM rules.
- 1. Open PDF in WPS Office: Launch WPS Office and open your target PDF document.
- 2. Access Protection Tools: Navigate to the Protect tab on the top ribbon and select the Encrypt option.
- 3. Set Passwords: Set an Open Password or Editing Password to secure your file locally, then save the document.

Frequently Asked Questions
Why do recipients have to enter a one-time passcode for encrypted PDFs?
Microsoft 365 Encrypt-Only features utilize Microsoft Purview Message Encryption (OME). When sending to external users outside your tenant, OME often requires the recipient to authenticate via a secure web portal or a one-time passcode to ensure unauthorized users cannot access the protected attachment.
Can I force a PDF preview in Outlook for a DRM-encrypted email?
If an email is highly encrypted using Azure Information Protection (AIP), previewing in the reading pane is sometimes disabled by design for security purposes. Setting the MIME type to 'application/pdf' gives the client the best chance to render it, but tenant-level security policies will ultimately override client preview features.
What are the supported protected-document readers for Microsoft 365?
Microsoft officially supports the Azure Information Protection (AIP) Viewer and natively integrated applications, such as Adobe Acrobat equipped with the Microsoft Information Protection (MIP) plug-in, to open and read fully DRM-protected PDF documents.




