They could always password protect the zip files and put the password in the email body. Don't think there are any virus/spam filters that actually try to crack the zip password to try and find an executable (.DOC being one of those "executable macro" types).
|