Security Issue Reporting
Security issue reporting guidelines
Looking for help with your Fastmail account, like a login issue? Please contact our support team. Received an email that you’re not sure is from us? Learn how to recognise and report phishing in our help, or contact our support team if you’re still not sure. This page is only about reporting security vulnerabilities and bugs in Fastmail’s code and infrastructure.
If you’ve found a security vulnerability in Fastmail, please report it to us straight away by emailing security@fastmailteam.com. Include detailed steps to reproduce the issue and a brief description of the impact. We encourage responsible disclosure (as described below), and we promise to investigate all legitimate reports in a timely manner and fix any issues as soon as we can.
We do read all reports within 24 hours, but as all reports are reviewed and personally investigated by our senior staff, it may take up to 10 business days before you hear back from us.
Responsible disclosure policy
We ask that during your research you make every effort to maintain the integrity of our users’ data, avoiding violating privacy or degrading our service. You must give us reasonable time to fix any vulnerability you find before you make it public. In return we promise to investigate reports promptly and not to take any legal action against you.
Bug bounty
As a measure of our appreciation for security researchers, we are happy to give full credit in any public postmortem after the bug has been fixed, and we offer a monetary bounty for certain qualifying bugs. To qualify for the bounty, you must:
- Follow our responsible disclosure policy (see above).
- Report the bug to us first, and give us reasonable time to fix the issue before making it public.
- Be the first person to report the issue to us.
- Use a test account (a free trial account is fine), or an account that you control. Never interact with other accounts without the owner’s consent.
- Find a bug that could allow access to private user data, or enable access to a system running Fastmail infrastructure.
Examples of valid vulnerability types include:
- Authentication or session management issues
- Cross-Site Scripting (XSS) (only on
www.fastmail.comorbeta.fastmail.com, not onuser.fmorfastmailusercontent.com; see below) - Cross-Site Request Forgery (CSRF/XSRF)
- Remote Code Execution
- Privilege Escalation
The decision of whether a bug qualifies for a bounty is solely at the discretion of Fastmail. Any qualifying bug will be eligible for a bounty of a minimum of US$100 and a maximum of $5,000. The exact value will be determined by Fastmail after taking into account the severity of the vulnerability, the number of users potentially affected etc. All bounties will be paid via PayPal. Any taxes or fees are the sole liability of the recipient. We process bug bounty payments once a month.
Specific exclusions
People seem to report these regularly, so we’re putting them up front to make it clear we do not regard these as bugs
- Email spoofing bugs do not qualify. We are quite aware that users can set arbitrary From addresses on emails, that our SPF records allow arbitrary hosts to send email as our domains, and that our DMARC policy is not enforcing passes. These policy decisions are by design, and we track the actual sender in a separate header.
- CSV Excel Macro Injection bugs via address book exporting do not qualify. The user has complete control over their address book. We regard convincing someone to add a particular address to their address book, export and download it as a CSV, open it in Excel, click through a warning dialog as exceedingly unlikely user interaction. If you can get them to do that, just get them to run cmd from the Start menu and paste some arbitrary command.
General Exclusions
- Denial of Service (DOS) and social engineering attacks do not qualify and must not be attempted against Fastmail or our users under any circumstances.
- Bugs that require exceedingly unlikely user interaction or are caused by insecurities in browser extensions do not qualify.
- Brute force log in attempts.
- The domains
user.fmandfastmailusercontent.comare used to host potentially unsafe user content. By keeping this content in completely separate domains, we avoid any security issues with our corefastmail.comdomain. As such, any Cross-Site Scripting (XSS) attacks on these sites are not of interest to us. Please note that if you go to a user web site such astestuser.fastmail.comit immediately redirects totestuser.fastmail.com.user.fmand is thus in theuser.fmsecurity domain, not thefastmail.comdomain. - Bugs on sites associated with Fastmail but not run by Fastmail do not qualify. This includes www.fastmailfbl.com. We are grateful for any reports on issues with these sites, and we will pass on the bugs to the relevant company, however they do not qualify for a bounty.
- Anything related to enumeration of usernames does not qualify.
- Bugs related to unpatched, out of date or exceedingly rarely used browsers or other client software out of our control.
- We are public about the software we run. We are not interested in reports about “leakage” of the fact we run nginx, or the version number, or Perl module names or file paths.
Hall of fame
Our thanks to the following security researchers for their submissions:
2026
| Researcher | Vulnerability found | Bounty paid |
|---|---|---|
| Ahmed Saeed | Missing calendar ACL checks and Cyrus memory mismanagement | $3750 |
| Renaldas Ivanauskas | Android app credentials vulnerability | $2000 |
| Lyra Rebane (rebane2001) | CSS sanitisation bypasses | $2000 |
| interpolwantme | OAuth redirect URI verification bypass | $2000 |
| Miro Hatachi | Email authentication bypass | $400 |
| Ahmed Saeed | Email identity verification bypass | $200 |
| Ahmed Saeed | Internal metrics leak | $200 |
| Thomas Johnson (MailRoute) | ARC Authentication-Results forgery | $200 |
| Bug Raiders (JAC) | Sensitive action reauthentication bypasses | $200 |
| Marish Pasco | External link protection bypass | $100 |
| Miro | BIMI Validation issue | $100 |
| Bug Raiders (JAC) | Trial abuse prevention bypass | $100 |
| Jubril Busari (Jaybeepy) | Trial abuse prevention bypass | $100 |
2025
| Researcher | Vulnerability found | Bounty paid |
|---|---|---|
| Lyra Rebane (rebane2001) | Multiple CSS sanitisation bypasses | $3500 |
| Mohsin Ali | Topicbox firewall misconfiguration | $500 |
| Kurachan | Address parsing inconsistencies | $250 |
| Jaikishan Tulswani | Internal documentation leak | $200 |
| Hao Wang & Caleb Sargent | DMARC bypass | $100 |
| Abdullah Shittu (LegaciesofLekan) | Internal metrics leak | $100 |
2024
| Researcher | Vulnerability found | Bounty paid |
|---|---|---|
| Amethama Luturmas | Topicbox ACL bypass | $100 |
2023
| Researcher | Vulnerability found | Bounty paid |
|---|---|---|
| Mohammad Eldawody | Fastmail 2FA vulnerability | $3000 |
| Max Raams | Email authentication weaknesses | $250 |
2022
| Researcher | Vulnerability found | Bounty paid |
|---|---|---|
| Vivek Kumar Yadav | Topicbox app vulnerability | $100 |
| Vivek Kumar Yadav | Android app vulnerability | $100 |
| Milan Jain | CRLF injection vulnerability | $250 |
| Ilkin Javadov | Pobox password link expiry | $100 |
| Huzaifa Muhammad | Topicbox mobile app vulnerability | $100 |
| Huzaifa Muhammad | Anti-abuse bypass on mobile app | $100 |
| Jonathan Page | DKIM oversigning | $200 |
2021
| Researcher | Vulnerability found | Bounty paid |
|---|---|---|
| Dennis Trappe | iOS app vulnerability | $100 |
| Sheikh Rishad | Android app vulnerability | $100 |
| Jaikishan Tulswani | Access vulnerability for third party service | $250 |
| Mohammed Eldawody | Bypass security screen in Topicbox | $100 |
| Vicky Sahputra | Deleted group vulnerability in Topicbox | $100 |
| Markus Holtermann | Fingerprint authentication vulnerability in Fastmail app | $100 |
| N Krishna Chaitanya | Password reset vulnerability in Pobox | $100 |
| Pravas Ranjan Kanungo | Image proxy vulnerability in Fastmail | $100 |
| Mohammed Eldawody | Password recovery bug in Pobox | $3000 |
| Roman Zabaluev | Caching of “don’t require 2FA again on this device” cookie validity | $500 |
2020
| Researcher | Vulnerability found | Bounty paid |
|---|---|---|
| Mohammed Eldawody | Privilege escalation bugs in Topicbox | $2000 |
| Mohammed Eldawody | Bypass security screen in Topicbox | $200 |
| Daniel Santos | Mutation bypass in DOMPurify | $100 |
| Michał Bentkowski (Securitum) | CSS sanitisation bypass | $750 |
| Michał Bentkowski (Securitum) | DOMPurify mXSS (sponsored bug bounty; did not affect Fastmail products) | $250 |
| Mohammed Eldawody | Stored XSS in Pobox | $200 |
| Mart Gil Robles | Login CSRF in Pobox | $100 |
| Basavaraj Banakar | Self-XSS in Pobox | $100 |
| Alexander Harkness | Unnecessary information disclosed in DMARC report |