Security reports
Send vulnerability information to security@emailinfralab.com. Include the affected hostname or service, a clear description, reproduction steps, observed impact, and a safe way to coordinate.
Abuse reports
Send suspected spam, phishing, malicious activity, or unauthorized use to abuse@emailinfralab.com. Complete message headers, timestamps, source addresses, and relevant SMTP evidence can help the investigation.
Responsible-disclosure expectations
- Act in good faith and avoid unnecessary access to data.
- Do not disrupt service availability or damage systems.
- Do not publish sensitive details before reasonable coordination.
- Do not request payment, credentials, or privileged access as a condition of reporting.
- Remove secrets and unrelated personal data from submitted evidence where possible.
Review process
- The report is checked for scope and available evidence.
- Relevant logs, configuration, DNS, service state, and access records are reviewed.
- Containment or correction is applied where necessary.
- The reporter or hosting provider is updated when appropriate.
- Documentation and safeguards are improved based on the finding.