Add KamoMail domain validator to block cross-tenant email addresses

FeatureEmailService
Shipped
20 Aprili 2026, 03:21 UTC
Author
Kamo
Commit
25340fc

Introduces KamoMailDomainValidator component that checks, at service layer, whether the submitted email domain matches the org's verified default domain when KamoMail is the active provider. Injected into MailboxProvisioningService, AliasService, and SharedMailboxService — called before any provisioning occurs. Returns 403 FORBIDDEN if the domain does not match.

All changes

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei