I feel you’re making a very massive issue out of something that is… not?
Yes, sharing the full headers of your emails will reveal some information, potentially even personally identifiable information.
I feel you’re making a very massive issue out of something that is… not?
Yes, sharing the full headers of your emails will reveal some information, potentially even personally identifiable information.
Their whole spiel is about "privacy first". https://www.fastmail.com/privacy-first-company
I don't even use my @fastmail.com address. I have like 6 domains that I use for various things, and a single domain for one-time/throwaway/order emails via 1Password integration.
I just verified every time I send an email, my main @fastmail account is attached in every email.
I don't care about people knowing my email, but security isn't the point or even the concern.
If I'm using an alias, I don't want account A associated to account B, especially for a service I'm paying for to keep my email out of the hands of Google.
However, you (and other commenters) appear to be indicating it’s also in the headers of all sent emails?
I’ve been using Fastmail for nigh on a decade, however if this turns out to be true, I may accelerate my migration towards Migadu.
"We could enable 2FA on the webmail, but IMAP/POP/SMTP accesses remain unprotected which beats the purpose. We are working on solution here which will allow sand-boxing a username/password pair to a webmail use only."
That's an incredibly misguided sentiment
This feels like an architectural flaw to me. If it's supposed to be private, then why is it available to send to on the public Internet, in a way that you are now therefore sensitive about?