Eh.

Sendgrid isn't a mailbox provider. Holding them to that standard of things
isn't the right way of looking at it.

For an Email Service Provider (like Sendgrid), the headers likely do have
the information to find the outgoing job where the actual messages were
built and there will be sufficient information there about the bodies (even
if it's without the precise personalization that the recipient saw) that an
abuse desk can take action if the content is important to the case.

When I was last running an ESP abuse desk, there were a very few customers
who were running things all over an API and I couldn't see the message
bodies, but I was looking for the bodies to see if there was additional
evidence (like "I found your contact information on LinkedIn") and was able
to move forward with my cases anyway.

I have grave concerns about running an ESP abuse desk on Google, but that's
from data access standpoint (i.e.: Google requires
<https://apps.google.com/supportwidget/articlehome?hl=en&article_url=https%3A%2F%2Fsupport.google.com%2Fa%2Fanswer%2F178266%3Fhl%3Den&assistant_id=generic-unu&product_context=178266&product_name=UnuFlow&trigger_context=a>
that
they be able to monitor abuse@ for domains it's hosting in Workspaces, but
has no reasonable right to data access regarding complaints regarding
messages not sent through their infrastructure).

On Wed, Mar 22, 2023 at 5:29 AM Jaroslaw Rafa via mailop <mailop@mailop.org>
wrote:

> Dnia 22.03.2023 o godz. 10:01:53 Sebastian Nielsen via mailop pisze:
> > A good idea when you get this type of response, just include the full
> > headersand not the actual body of message.A competent abuse department
> > should be able to fish out a verbatim copy of the message being reported
> > in their logging systems using the headers alone.
>
> I would not trust any email provider who is able to do this - because this
> means that they are either: a) logging and storing all your emails (if they
> are able to do this even if the message is not stored in sender's mailbox);
> or b) snooping through users' mailboxes (if they are able to do this only
> if
> the message is stored in sender's mailbox, by pulling it out from there).
> --
> Regards,
>    Jaroslaw Rafa
>    r...@rafa.eu.org
> --
> "In a million years, when kids go to school, they're gonna know: once there
> was a Hushpuppy, and she lived with her daddy in the Bathtub."
> _______________________________________________
> mailop mailing list
> mailop@mailop.org
> https://list.mailop.org/listinfo/mailop
>
_______________________________________________
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop

Reply via email to