3 comments

[ 0.23 ms ] story [ 20.6 ms ] thread
Frontend developers can now send emails from their web applications without the need to setup backend server.
> How is my subscription secure if authorisation key is made public?

>> Emailyt needs authorisation key to validate your subscription, and the key is only valid when using from the pre-configured website

If this means that they are checking the Referer then of course that’s trivial to spoof. So anyone with CURL can trigger emails to be sent?

Unless it’s a one-time key that’s generated on the backend to send a specific email (e.g. hash verified)... how can it truly be secure?

Since these will be valid emails sent from the authorized domain sender, spoofing would be a big problem.

Is this a Show HN?

The keys are one-time generated. The key for backend integration is secure as long as it is not shared with someone else. And the key for front-end is one of the parameters to identify the domain that was already registered at Emailyt. And the emails that go out via emailyt are all sent from 'Emailyt For {AppName}(relay@emailyt.com)'