From cc855e388dc2c1e02447578d05150c9cff63222f Mon Sep 17 00:00:00 2001 From: "Danilo M." Date: Tue, 8 Sep 2026 16:28:35 +0200 Subject: feat: report List-Unsubscribe urls and a differing Sender A sweep of the user's real spam found List-Unsubscribe naming a domain that appeared nowhere else in the message. It is attacker infrastructure and was going unreported. Every url from that header goes through redact.url() like a body url: an unsubscribe link has to say who is unsubscribing, which makes it one of the likeliest carriers of a recipient token. mailto: entries are skipped rather than redacted, since the address is the whole value and nothing useful survives removing it. Sender is collected on the same terms as Reply-To, included only when it differs from From. One repeating From is noise; one naming a separate relay is the infrastructure behind the run. Also drops the unused urlencode import left in redact.py when _redact_kv_string stopped using urllib to rebuild the query string. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_019NHaqA1Rz5ybed7wFUeQbK --- tests/fixtures/leaky.eml | 2 ++ 1 file changed, 2 insertions(+) (limited to 'tests/fixtures/leaky.eml') diff --git a/tests/fixtures/leaky.eml b/tests/fixtures/leaky.eml index f98d191..5ce3366 100644 --- a/tests/fixtures/leaky.eml +++ b/tests/fixtures/leaky.eml @@ -7,6 +7,8 @@ Received: from sender.example.invalid (unknown [203.0.113.42]) Return-Path: From: "Billing at you@example.org" To: +Sender: envelope@relay.example.invalid +List-Unsubscribe: , Subject: Confirm now Message-ID: Date: Tue, 8 Sep 2026 16:00:00 +0200 -- cgit v1.2.3