|
|
|
|
|
by tjames7000
11 days ago
|
|
We'll publish more details soon. In short, emails that triggered 550 5.7.1 or 552 5.7.0 were what we saw the most. 550 5.1.1 was also a problem in the real world, but not possible to exploit. The error message contained the meant-to-be-hidden address. We don't know whether attachment-related rejections or other rejections, e.g. for a full inbox, were a problem. Apple fixed most of the issues on July 2 or July 3, so if you were testing after that, you may have been too late. These are basically the reproduction instructions we provided with our initial report:
1. Send a spammy email to the Hide My Email address. Or send an email that doesn't strike you as spammy and hope that the email is rejected as spam anyway.
2. If the email is rejected SMTP code 550, look at the long description field and observe the real email address.
3. If the email wasn't rejected by the email server as spam, try again with a spammier email or different email. I think that once you've identified a message that's rejected as spam consistently, you can keep using it. Post-fix, we're realizing that it seems like emails forwarded via Hide My Email bounce as spam at higher rates than the same emails sent directly. Which could explain why we were getting bounces for non-spam transactional emails sent only to paying customers, and why the bounces were only happening for icloud addresses. The issue may have been more prevalent than someone might assume, given typical bounce rates. |
|
I tested on July 2 when the original submission was made: https://news.ycombinator.com/item?id=48767855