Junkmail

Security

Security at Junkmail

Junkmail is designed around a narrow boundary: private aliases receive mail, but they never send, reply, or forward to your everyday inbox. That smaller surface is backed by layered controls for accounts, messages, and service operations.

How the service protects you

Report a vulnerability

Email privacy@junksink.com with the subject Security report. Include the affected URL or component, a concise impact assessment, and reproducible steps. Use the minimum proof needed and never include passwords, recovery codes, API tokens, webhook secrets, wallet material, or another person’s mailbox content.

Responsible testing

Test only accounts and data you control. Do not access another person’s mailbox, degrade availability, automate abusive traffic, attempt social engineering, or retain personal data you encounter. If testing unexpectedly exposes private data, stop, preserve only the minimum evidence, and report it immediately.

Coordinated disclosure

Please allow reasonable time for investigation and remediation before publishing details. Junkmail will use the contact information in your report to clarify findings and share material status updates. Sending a report does not create an entitlement to payment or public recognition.