From aab8dd2fad8d3237fef6ccc9bab1db275a8061f9 Mon Sep 17 00:00:00 2001 From: RonniSkansing Date: Thu, 1 Oct 2026 20:43:23 +0200 Subject: [PATCH] add fallback even for invalid senders to mask default hostname leak Signed-off-by: RonniSkansing --- backend/service/messageID.go | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/backend/service/messageID.go b/backend/service/messageID.go index 01830f5f..04233068 100644 --- a/backend/service/messageID.go +++ b/backend/service/messageID.go @@ -24,15 +24,20 @@ func domainFromEmailAddress(address string) string { return domain } +// fallbackMessageIDDomain is a neutral right side used when the sender address +// has no usable domain. It keeps the machine hostname out of the Message-ID +// that go-mail would otherwise fall back to. +const fallbackMessageIDDomain = "localhost.localdomain" + // setMessageIDFromAddress sets the message "Message-ID" header as uuid@domain, // using the sending domain as the right side, so outgoing mail does not carry // the machine hostname that go-mail would otherwise use by default. -// when the address has no usable domain the message keeps whatever Message-ID -// go-mail assigns. +// when the address has no usable domain a neutral right side is used so the +// hostname is never leaked. func setMessageIDFromAddress(m *mail.Msg, address string) { domain := domainFromEmailAddress(address) if domain == "" { - return + domain = fallbackMessageIDDomain } m.SetMessageIDWithValue(uuid.NewString() + "@" + domain) }