Security and privacy
Reading safely
Section titled “Reading safely”- External content is blocked until you allow it; trusted senders are remembered.
- HTML is sanitized through DOMPurify; CSP is enforced with a per-request nonce, plus SSRF redirect validation, a sandboxed PDF iframe and IP-spoofing prevention.
- SPF / DKIM / DMARC indicators surface the most severe SPF result and drop the “via” badge on spoofed mail.
- Newsletter unsubscribe (RFC 2369) is offered on bulk mail.
S/MIME
Section titled “S/MIME”Manage certificates, then sign, encrypt, decrypt and verify. Legacy 3DES / PBE is supported, and keys stay isolated per account.
Signing in
Section titled “Signing in”- OAuth2 / OIDC with PKCE against Keycloak, Authentik or the built-in provider, plus OAuth-only mode, OAuth app passwords and non-interactive SSO for embedded deployments.
- TOTP two-factor authentication, and password / 2FA management through the admin API.
- Remember me is optional and rides an AES-256-GCM encrypted httpOnly cookie. User authentication endpoints are rate-limited (10 attempts per IP+username per 15 minutes); admin sessions support token revocation (JTI blacklist) on logout.
Extensibility safely
Section titled “Extensibility safely”Plugins are scanned for dangerous patterns and need admin approval before they run.