KamoCRM

Refuse a guessed recipient at the org's own domain before it reaches the mail server

FixEmailService
Shipped
September 29, 2026 at 1:14 AM UTC
Author
Kamo
Commit
ec2c638

Luna (AI member) asked to email the owner and guessed **************** instead of looking up the real address (sage@kamocrm.com). kamouniverse.com is one of the org's own verified mail domains, so nothing rejected the send until postfix bounced it at RCPT TO with a 550, minutes later, as an opaque execution_error nobody read as an actionable answer. RecipientDomainValidator checks every recipient that names one of the organization's own KamoMail domains (its verified root domains, or a Settings -> Email -> Domains alias such as kamouniverse.com, which forwards local-part for local-part onto the primary domain) against its mailboxes, aliases, shared mailboxes, personal mailboxes and members, each by one exact indexed lookup. /api/email/send now refuses with 422 RECIPIENTS_UNKNOWN before preparing or attempting anything, naming the address. An organization on an external provider (Google Workspace, ...) is left untouched: this checks only KamoMail's own address space. Tests: RecipientDomainValidatorTest (new, 11 cases) exercises resolution against a mailbox, alias, shared mailbox, personal mailbox and member, an alias-domain address whose canonical form resolves, addresses outside the org's domains, and an org on an external provider. EmailControllerSendContractTest gained a case proving the refusal happens before compose/send are ever called. Four existing controller tests pick up the new constructor parameter. heavy mvn test **************** 74 run, 0 failures.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing