Password reset email urls causing email to be reported as scam

Edward's Avatar

Edward

27 Apr, 2012 07:53 AM

The url displayed in password reset emails is for a different address then one given in the link. It is also a non-ssl url. This is a method commonly used for phishing and cause airbrake emails to be reporteds as scams.

Actual url is some linke
http://mail.airbrakeapp.com/wf/click?upn=....

Displayed url is something like
http://myproject.airbrake.io/users/.../password/edit?auth_token=...

  1. Support Staff 2 Posted by Morgan on 07 May, 2012 11:58 PM

    Morgan's Avatar

    HI Edward,

    Sorry about the late response!
    Airbrake does have Valid SSL certificates in place.
    Are your emails still being reported as scams?
    Please let me know if you are still having the same issue.

    From,
    Morgan

  2. 3 Posted by Edward on 08 May, 2012 12:22 AM

    Edward's Avatar

    I just tried and the urls are now the same, so it isn't being reported as a scam, but it is still pointing to the http url which seems a bit dangerous for a password reset function.

    Cheers,
    Edward

  3. Support Staff 4 Posted by Morgan on 08 May, 2012 12:48 AM

    Morgan's Avatar

    Hi Edward,

    Thanks for pointing this out.
    We are looking into the issue, and have notified our email client.
    Thank you for the feedback!

    From,
    Morgan

  4. Morgan closed this discussion on 08 May, 2012 12:48 AM.

Comments are currently closed for this discussion. You can start a new one.