# ReciteMail security contact (RFC 9116) # # We welcome genuine vulnerability reports and reply to every credible one. # We do NOT operate a paid bug bounty program, and we do not pay for reports. # # Out of scope (please do not report these): missing optional DNS records # (MTA-STS, CAA, DNSSEC, BIMI), security header suggestions with no # demonstrated impact, raw scanner output, self-XSS, clickjacking on pages # with no sensitive actions, and social engineering of staff. # The full policy and scope live at the Policy URL below. Contact: mailto:info@recitemail.io Expires: 2027-07-01T00:00:00.000Z Preferred-Languages: en Canonical: https://recitemail.io/.well-known/security.txt Policy: https://recitemail.io/security