3 ms·
One issue I have with FastMail is the reuse of email addresses. It is possible to "hack" accounts on websites which were registered to expired email addresses b
by vivan 9y ago
One issue I have with FastMail is the reuse of email addresses. It is possible to "hack" accounts on websites which were registered to expired email addresses by simply registering that email address anew and doing a password reset. This is very common in the domain space, where email addresses are publicly listed.
- _rknLA 9y agoDoes this affect custom domains, or is it only an issue with @fastmail.com accounts?
- vivan 9y agoWell, with custom domain email addresses this is always true regardless of service provider. If you ever abandon the domain, someone else could come along and buy the domain and create the same email address. They could then receive any mail intended for that email address (e.g. password resets). This is why I consider any domains purchased for email purposes to be lifetime investments.
- regecks 9y agoThere are other "security issues" too. One is that you can send email as any other FastMail user, and it won't stop you. SPF passes and DKIM signatures signed (even for other customers' custom domains), totally impossible to tell the difference between a legitimate and spoofed message. To be fair, DKIM is a borderline useless technology and doesn't really prove anything, but it still appears to be an intentional policy decision by FM to be "lax". Interestingly enough they do track the real sender in mail headers (which I suspect enables them to mark their own official emails with "verified" badges), but it's a dynamic obfuscated value iirc so it's absolutely worthless for regular users. It kind of makes my stomach churn when I consider that it's trivial for any other FastMail user to impersonate me, but OTOH, it's best not to be under the delusion that email is authenticated, so I'm staying with them. Great service, despite my comments.