Security

Responsible Disclosure

If you have found a security issue in MailThreatZero, please tell us. We would much rather hear it from you than from an incident.

Last updated 2026-08-06.

How to report

Use the contact form and select Security vulnerability report. Machine-readable contact details are at /security.txt.

Helpful things to include: what you found, the steps to reproduce it, what an attacker could achieve, and how you would like to be credited.

What we ask

  • Give us a reasonable opportunity to fix the issue before publishing it.
  • Do not access, modify or delete data that is not yours — if you can demonstrate access, stop there.
  • Do not run denial-of-service tests, spam the service, or degrade mail delivery for real customers.
  • Test against your own account and domains wherever possible.

What you can expect

  • An acknowledgement that a human has read your report.
  • An honest assessment, including if we think it is not a vulnerability and why.
  • Notification when it is fixed, and credit if you want it.
  • No legal action against good-faith research that follows this policy.

We acknowledge reports promptly and keep you informed while we investigate. We do not operate a paid bug-bounty programme.

Scope

In scope: the MailThreatZero gateway, the administrative console and API, and this website. Out of scope: third-party services we depend on (report those to their owners), and findings that require physical access or a compromised administrator account.