I’ve always wondered if it’s possible to have a valid email address which is also an SQL injection attack, XSS or similar ?
One of our testers found XSS with email injection (RFC compkiant validation passed) in our website.
And we are an e-mail company and should now better :D
Never trust user input!
But the way to prevent injection attacks is not to disallow or sanitize input, it is to escape correctly when interpolating strings in other languages.