Add KamoMail domain validator to block cross-tenant email addresses

FeatureEmailService
Shipped
April 20, 2026 at 3:21 AM UTC
Author
Kamo
Commit
25340fc

Introduces KamoMailDomainValidator component that checks, at service layer, whether the submitted email domain matches the org's verified default domain when KamoMail is the active provider. Injected into MailboxProvisioningService, AliasService, and SharedMailboxService — called before any provisioning occurs. Returns 403 FORBIDDEN if the domain does not match.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing