The limit that limits nothing · 11 of 20

A form that echoes visitor text inside your signed email is a phishing relay

Hit in our code
Check it
# against YOUR staging site, with an inbox you own as the addresscurl -s -X POST https://staging.yoursite.com/api/contact -H "Content-Type: application/json" \  -d '{"email":"you+relay@yourdomain.com","message":"click here: http://evil.example","website":""}'# if that inbox gets your branded email with the link inside, it is a relay
Free, no call

Get every Fix AI Slop Code episode

The code it wrote, the code it should have written and a check, for every episode

Free, straight to your inbox. No call, no pitch

What is going on

If a contact endpoint accepts a recipient and a message, and sends a branded, DKIM-signed email containing that message, anyone can send anything to anyone from your domain. A honeypot field stops bots that fill every input. It does not stop a person with curl.

Where it bit

Our own contact form echoed visitor text in a branded email to any address they supplied, guarded only by a honeypot. An older auto-reply worker was worse: its check was "if a secret is configured," and the forms never sent one, so the endpoint was open. Both are closed now: the echo drops links, and the endpoint checks where the request came from and limits it at the edge.

The practice

Recipients are never a request parameter. Visitor text goes to you, and the confirmation to them is a fixed template with no echoed body. Turnstile or an equivalent on anything that sends email. Signature check on every inbound webhook, with timingSafeEqual.

Free, no call

Get this check as a script you can run tonight

Free, straight to your inbox. No call, no pitch

What to do with this

If this check came back with more than you expected, that is worth a conversation

Book a free 30-minute call