Hacker News new | ask | show | jobs
by mkdirp 1589 days ago
I did not know this, I moved to mailbox.org in December.

Surely they'll only allow that if they pass the auth and the domain belongs to your account?

1 comments

No, they don't do that check, that is the problem.
I don’t think they can implement such a check without breaking changes.
And that's why we shouldn't fix bugs anymore? https://xkcd.com/1172/

Fixing this would only affect users who send emails "from" other users email addresses, basically users who commit fraud.