Apple’s Mail App can be simply configured to not download embedded content - therefore avoiding the potential risk outlined in your statement.
Settings > Mail > Load Remote Images - set to OFF
When configured correctly, it is possible to examine basic attributes of the received email without downloading or triggering embedded malicious content.
The preview window, triggered with a long-touch, may be similarly configured to not automatically load remote content.
If your checks suggest the email to be “clean”, you simply download embedded images by tapping the button that appears at the top of the email. By contrast, if when checked the email appears in any way suspicious, you simply delete the email along with any attachments.
I hope you find this information to be helpful - both in providing assurance and advice in safe handling of your incoming email.