- Shipped
- September 28, 2026 at 10:00 PM UTC
- Author
- Kamo
- Commit
- 2e5b272
SP99-T1-f, finished (SP98 Task 8). SP99's final review already refuses a KamoMail binding whose address is not on a domain the organization holds (95c58af); this completes the item. - HeldMailDomains keeps each organization's held mail domains for a minute, so the check in **************** adds no database read to a mail request (it added two, four under PARENT_ORG). Only a grant comes from the copy: a domain missing from it is read again before the answer is no. - A save of the organization's provider that leaves its mail on KamoMail deactivates every mailbox row on a domain it doesn't hold: SUSPENDED, and its member assignments removed (each logged), so no switcher, From picker or mailbox privilege offers it. The row stays; the shared server's account is never touched. - A send or a draft on behalf of a refused mailbox answers 403 MAILBOX_ACCESS_DENIED, as reading it does (master §11 SP99-FINAL item 2), not a 500. - The nightly storage sweep measures only rows on a domain their organization holds: a row naming another tenant's account logged in to that account and charged its bytes to the wrong organization. Audited 2026-09-28 (read-only): both KamoMail organizations' 33 rows are on domains they hold, so no row changes and every mailbox still opens.
