The keys are one-time generated. The key for backend integration is secure as long as it is not shared with someone else. And the key for front-end is one of the parameters to identify the domain that was already registered at Emailyt.
And the emails that go out via emailyt are all sent from 'Emailyt For {AppName}(relay@emailyt.com)'
3 comments
[ 0.23 ms ] story [ 20.6 ms ] thread>> Emailyt needs authorisation key to validate your subscription, and the key is only valid when using from the pre-configured website
If this means that they are checking the Referer then of course that’s trivial to spoof. So anyone with CURL can trigger emails to be sent?
Unless it’s a one-time key that’s generated on the backend to send a specific email (e.g. hash verified)... how can it truly be secure?
Since these will be valid emails sent from the authorized domain sender, spoofing would be a big problem.
Is this a Show HN?