New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

message-ID in header exposes domain #1432

Closed
derStephan opened this Issue May 18, 2017 · 4 comments

Comments

2 participants
@derStephan

derStephan commented May 18, 2017

When I send an eMail via SMTP, the domain of the rainloop installation is exposed to the receiver in the eMail headers:

Mime-Version: 1.0
Date: Thu, 18 May 2017 08:56:40 +0000
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: RainLoop/1.11.0.203
Message-ID: <a7602bac614e8f8345cfa3d472882338@my-domain.com>

I do not think, that anybody out there should see this. Especially when it is impossible to prevent new users to log in using their credentials for gmail.com or outlook.com.

My suggestion is to change this domain to the eMailaddresses'.

So instead of
a7602bac614e8f8345cfa3d472882338@my-domain.com
it should be
a7602bac614e8f8345cfa3d472882338@gmail.com
for a gmail.com-address or
a7602bac614e8f8345cfa3d472882338@outlook.com
for a outlook-address

Otherwise, I could be held responsible for abuse that any foreign user may do with my installation.

RainLoop added a commit that referenced this issue May 18, 2017

Change Message-ID regenerate logic (#1432)
Add additional configuration to hide x-mailer header  (#1426)
@RainLoop

This comment has been minimized.

Owner

RainLoop commented May 18, 2017

Thanks! Fix will be available in the next release.

@derStephan

This comment has been minimized.

derStephan commented May 19, 2017

wow, that was quick. Thank you very much. Is there a planned time point for the next release?

@RainLoop

This comment has been minimized.

Owner

RainLoop commented May 19, 2017

Next week I think.

@derStephan

This comment has been minimized.

derStephan commented May 19, 2017

Thanks for all of your work. It is really appreciated.

@derStephan derStephan closed this May 19, 2017

Techwolfy added a commit to Techwolfy/rainloop that referenced this issue Jun 20, 2017

Change Message-ID regenerate logic (RainLoop#1432)
Add additional configuration to hide x-mailer header  (RainLoop#1426)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment