This repository holds guides, a static HTML page, an example filter file and a small Python builder. It runs no service. In scope:
- The signature builder sending anything typed into it anywhere. It is meant to run entirely in the browser
outlook/build_oft.pyreading or writing anything outside the repository- Guidance that would weaken mail security if followed, for example a DNS record that is wrong
- Behaviour of Gmail, Outlook or Google Workspace themselves
- Vulnerabilities in msgforge, which belong with that project
Important
Report privately, never in a public issue. Use GitHub private vulnerability reporting or email contact@isaacadjei.me with details and reproduction steps. Expect an acknowledgement within a few days.
Note
The full policy is in zaccesss/security-policy and on my site. This file takes precedence where the two differ.