Open any Word document you have ever sent out and somewhere inside the file is a small block of Word document metadata that knows more about your office than you do. Your full name. The colleague who edited it last. The exact minute you printed it. The name of your network share. The internal template the document was copied from. None of it appears on the page, but all of it ships with the file the moment you attach it to an email.
Word has worked this way for more than two decades. The information is genuinely useful inside an organisation, where document properties feed search, version control and DLP tooling. Outside the organisation, it is a quiet leak.
What is actually inside a .docx
A .docx file is a ZIP archive. Rename one to .zip and unpack it, and you will see two small XML files that hold most of the metadata: docProps/core.xml and docProps/app.xml.
The core properties file holds:
creator— the Windows account name of whoever first saved the file.lastModifiedBy— the account name of whoever saved it most recently.revision— how many times the file has been saved.createdandmodified— timestamps to the second.lastPrinted— the exact moment the document last hit a printer.title,subject,keywords,description— whatever the author typed into File → Properties, plus anything Word inferred.
The app properties file adds:
Company— pulled from your Office activation when the install was set up.ApplicationandAppVersion— the exact build of Word that wrote the file.TotalTime— the cumulative editing minutes across every session.Template— the path to the .dotx the document was based on, often a network share with a server name.
The leaks people do not expect
Most of the surprising leaks come from things Word records without asking.
Revision save IDs
Each editing session writes a new rsid (revision save ID) into the document body. Open the underlying document.xml and you will find a list of every distinct save event, along with which paragraphs were touched in which session. A document edited by two people across five sessions makes that obvious to anyone with a text editor.
Tracked changes that look removed
Accepting all changes hides them visually, but if Track Changes was on at any point, the underlying revision marks may still be embedded until the document is properly cleaned. Re-saving does not always strip them. The same is true of comments deleted from the comment pane: the threading IDs can persist.
Embedded objects
If someone pasted in a chart, an Excel range, a Visio drawing or an Outlook screenshot, Word often keeps the source object intact alongside the rendered image. The reader can right-click and open it — sometimes revealing entire spreadsheets, original email signatures, or draft figures the author thought they had cropped out.
Network paths
Hyperlinks and template references inside the file can include UNC paths like \fileserver01\policies\drafts\. Those server names alone tell an outside reader the shape of an internal network.
Recent file lists and custom XML parts
Some documents accumulate a custom XML data store under customXml/ when they have been opened by SharePoint, DLP scanners or third-party plugins. The store often holds organisational classification labels, document IDs that link back to internal libraries, and the names of the workflow approvers who signed the file off. None of that is visible in Word itself; all of it ships when the .docx is forwarded.
Why it matters in real cases
The most quoted example is the 2003 UK government dossier on Iraq, where Word's revision history listed the four civil servants who had edited the document — including one whose section had been lifted, lightly edited, from a graduate student's thesis. The metadata did not write the dossier. It just made the chain of authorship undeniable.
Law firms have lost ground on the same mechanism: a redline sent to opposing counsel where Accept All was used in haste and the originating partner's earlier draft language remained embedded. HR teams have sent rejection letters built from a template still bearing the original candidate's name in the document properties. Press offices have published statements that, opened in Word rather than viewed in a browser, named the political adviser who actually wrote them.
What to do before you send
Word's built-in Document Inspector (File → Info → Check for Issues) will strip most of this, but it does not always touch the rsid history, the embedded objects, or the template path. For a one-off file the simplest option is to drop it through a cleaner that scrubs every property field at once and re-emits a fresh .docx. You can try the cleaner on the homepage with whatever document you were about to send: it will show you exactly what was inside before it strips it.
The point is not paranoia. Word document metadata is a useful tool for the organisation that wrote the file. It is rarely the message you meant to send to the person on the other end.