catmail.ltd Sign in Create mailbox

Security

Updated 2026-07-10 · coordinated disclosure

This page explains what CatMail protects today, how to report a vulnerability, and where the limits are. We would rather be precise than impressive.

Report a vulnerability

Send reports to security@catmail.ltd. Please include the affected URL, steps to reproduce, expected impact, and a safe proof of concept. We do not have a paid bounty program yet, but we welcome coordinated disclosure.

Do not access other people’s mail, exfiltrate data, run destructive tests, or degrade service availability. If a proof needs real account data, use an account you control.

security@catmail.ltd

Web transport

HTTPS with HSTS, secure cookies, same-origin forms, and no third-party analytics.

Mail transport

TLS on public mail endpoints, SPF/DKIM/DMARC for catmail.ltd, and TLS reporting records.

Account security

Password hashes use bcrypt; TOTP is available; recovery and backup codes are stored as hashes.

Mail privacy

Remote images are blocked or proxied, and support tools are built for metadata-only investigation.

security.txt · Privacy policy · Service status