Security Architecture & Strict Defaults
Security Principles
- Mandatory TLS Verification: Server TLS certificates and hostnames are strictly verified against trusted CAs. Insecure certificate bypass flags are intentionally forbidden.
- Enforced Encrypted Authentication: SASL PLAIN / LOGIN credentials cannot be transmitted over unencrypted plaintext sockets.
- BCC Header Omission: Bcc recipient addresses are strictly omitted from generated MIME headers per RFC 5322 security requirements.
- Automatic Log Redaction: Passwords, API tokens, and secret fields are automatically scrubbed from error details in logs.
- Header Injection Protection: CR/LF sequences in headers, addresses, and subject lines are rejected at the validation boundary.