KamoCRM

A mail domain, and every account on it, belongs to the organization that proved it

FixEmailService
Shipped
September 28, 2026 at 6:40 AM UTC
Author
Kamo
Commit
855076b

The KamoMail server's virtual_domains and virtual_users are shared by every tenant, and nothing stopped one tenant from writing to another's part of them: - POST /api/email/domains put ANY domain into virtual_domains, after which postfix delivers that domain's mail locally for every tenant. It now needs an ownership_verified org_domains root of the org's own covering the domain; a Kamo operator with an open god-mode window may add a *.kamocrm.com host for a test org. - DELETE /api/email/domains/{d} deleted ANY virtual_domains row, cascading every mailbox account on it (all of kamocrm.com). Now only the org's own domain row. - Creating a mailbox, shared mailbox or alias skipped the domain check for every org without an org_email_providers row (all but KamoCRM), so they could create accounts on kamocrm.com. The check now holds for every org and provider. - Mailbox sync imported every server account on any domain the org had merely TYPED into org_domains; resetting the password of such a row took the account over. Sync, password changes, deletes and both self-heals now act only on domains the org holds. What an org holds **************** its ownership-verified, non-platform org_domains roots, plus its EmailService domain rows for hosts under those roots or for platform subdomains - rows only the gated add can write; provider sync no longer imports platform hosts, and a KamoMail sync no longer rewrites a row's status. An org at Google/Microsoft/etc. may also create mailboxes on domains its provider reports VERIFIED, since the provider creates those.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing