Bugtraq mailing list archives

Re: Web Tool Announcement: ismymailsecure.com


From: Chuck Swiger <cswiger () mac com>
Date: Thu, 19 Aug 2010 15:11:45 -0700

Hi, Holger--

On Aug 18, 2010, at 2:59 AM, Holger Rabbach wrote:
I am happy to announce the immediate availability of a web based email
security testing tool at http://www.ismymailsecure.com.  [ ... ]
If you have any concerns about having to enter a full email address,
please be advised that this address is never stored anywhere. The only
reason that the site asks for an email address rather than a domain is
that it makes it easier for end-users to enter the correct information.
Feel free to enter anything you like as the left hand part of the
address, as it will be immediately stripped off by the tool anyway.

Your tool doesn't implement RFC-822 (2822/3696) address-checking properly; it returns:

  "cswiger+test () mac com is an invalid email address"

Regards,
-- 
-Chuck


Current thread: