Mailrelay responsible disclosure policy
Learn how to report a security vulnerability
At Mailrelay, the security and privacy of our users and customers data are top priorities.
We continuously work to ensure the integrity, availability, and security of our infrastructure, email services, and web applications.
We recognize the essential role that the cybersecurity research community plays in identifying vulnerabilities.
Therefore, we encourage responsible disclosure and appreciate the collaboration of researchers who help us secure our systems in an ethical manner.
If you believe you have discovered a security vulnerability in Mailrelay, we invite you to report it to us according to the guidelines outlined below.
Guidelines & ethical conduct
To qualify for protection under this policy and ensure that your research does not lead to legal action on our part, you must comply with the following rules:
- Good faith: act at all times with the intent to protect the security and integrity of our systems and users.
- Confidentiality: do not publicly disclose or share the vulnerability with third parties until we have had reasonable time to review and resolve it, and have mutually agreed on public disclosure.
- Data protection: make every effort to avoid privacy violations. Do not access, download, modify, delete, or destroy personal data or information that does not belong to your own test account.
- Minimization of testing: once you have demonstrated that a vulnerability exists, stop testing immediately. Do not perform actions beyond what is strictly necessary to create a Proof of Concept (PoC).
- Service continuity: do not perform tests that degrade the performance or availability of our systems, or disrupt the experience of other users.
Scope
IN Scope
This policy applies to security vulnerabilities found in assets directly owned and operated by Mailrelay:
- Customer control panels and web applications.
- Mailrelay’s public API and proprietary backend services.
- Server infrastructure used for sending emails directly operated by Mailrelay.
OUT of Scope
Unless explicitly authorized in writing, the following types of tests and findings are strictly excluded:
- Denial of Service (DoS / DDoS) attacks or resource exhaustion attempts.
- Social engineering, phishing, vishing, or spam targeting Mailrelay employees, users, or contractors.
- Physical attacks against facilities, data centers, or Mailrelay personnel.
- Automated vulnerability scans or high-volume automated testing without prior manual evaluation.
- Vulnerabilities requiring highly improbable or unrealistic user interactions.
- Email security header misconfigurations (such as third-party SPF/DMARC/DKIM records) unless they have a direct, demonstrable security impact on Mailrelay.
- User interface (UI/UX) or minor text bugs with no security impact.
- Vulnerabilities in third-party integrations or services integrated with Mailrelay that are not directly managed by us.
How to report a vulnerability
If you have identified a security issue in Mailrelay, please email [email protected], as published in our security.txt file.
To help us review and address your report quickly, please include:
- Detailed description: clear description of the vulnerability and its potential security impact.
- Steps to Reproduce: step-by-step instructions that allow our technical team to easily replicate the issue.
- Proof of concept (PoC): links, screenshots, code snippets, or HTTP/API request samples.
- Affected environment: specific URLs, API endpoints, or parameters involved.
Our commitment
When you report a vulnerability in compliance with this policy, Mailrelay commits to:
- Acknowledge receipt: confirm receipt of your report within 48 to 72 business hours.
- Evaluation & Updates: assess the severity of the issue and keep you updated on our progress toward resolving it.
- Safe harbor: if you act in good faith and fully comply with this policy, Mailrelay will not initiate or support civil or criminal legal action against you regarding your security research.
Limitation of liability
This policy does not grant express or implied permission to access third-party data or disrupt normal operations at Mailrelay.
This Responsible Disclosure Policy may be updated periodically to align with evolving security standards and legal regulations.