Skip to content
Security

Hostile input, by design.

EmailAuthLab is a public, internet-facing tool that accepts email from anyone. We treat public input as hostile by design: inputs are size-capped and rate-limited, pasted headers are rendered as text, results store verdicts only, and the service runs with least-privilege access to its own data.

Reporting an issue

EmailAuthLab is operated by TrustYourInbox, and security reports follow the same responsible-disclosure path. See the TrustYourInbox security disclosure page for how to report and what to expect. Please report privately and give us a reasonable window to fix before publishing.