Skip to content

fix(leads): stop cold outreach reaching opt-out and data-protection inboxes - #141

Merged
ralyodio merged 1 commit into
masterfrom
fix/never-contact-gaps
Jul 28, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/never-contact-gaps

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Live sends reached these three addresses:

Address What it is
optout@dribbble.com an opt-out mailbox
dpo@ecoconsult.it a Data Protection Officer
candidate-accomodations@activisionblizzard.com a disability accommodations queue

The guard wasn't missing — its list was

NEVER_CONTACT_LOCALPART ran correctly and is applied in three places. It already listed unsubscribe, privacy, and legal. It just didn't list optout, dpo, or anything accessibility-related — and a list of exact words doesn't generalise to its own near-synonyms.

Now enumerated: opt-out variants, data protection (dpo, gdpr, compliance), reporting/enforcement, accessibility queues, and hiring inboxes — including accomodation, the misspelling the Activision address actually used.

Exact matching was the second half

accomodations was blocked while candidate-accomodations was not. Matching now also splits the localpart on -._+ and checks each token.

Splitting only on separators is what prevents over-blocking. A substring match would refuse privacyengineering@ and hrothgar@ — ordinary addresses that stay one token and stay contactable.

Deliberately still allowed

hello@ · info@ · contact@ · support@ · sales@

For a small company that's often the only published address and a legitimate B2B target. Over-blocking costs real prospects; these aren't in the same category as an opt-out queue.

Tests

The three leaked addresses are asserted verbatim, so the case that failed is the case that's covered — plus 20 category cases and 10 must-still-work cases.

  • tsc --noEmit clean
  • 846/846 tests pass, 35 new
  • production build compiles

🤖 Generated with Claude Code

…nboxes

Live sends reached optout@, dpo@ and a candidate-accomodations@ queue.

The guard was not missing — it ran, and it already listed unsubscribe,
privacy and legal. It simply did not list optout, dpo, or anything
accessibility-related, and a list of exact words does not generalise to
its own near-synonyms. The fix is enumeration: opt-out variants, data
protection, reporting and enforcement, accessibility queues, and hiring
inboxes, including the misspelling the Activision address actually used.

Exact matching was the second half of the problem. `accomodations` was
blocked while `candidate-accomodations` was not, so the compound form
went through. Matching now also splits the localpart on separators and
checks each token.

Splitting only on separators is what keeps this from over-blocking.
A substring match would refuse privacyengineering@ and hrothgar@, which
are ordinary addresses; as tokens they stay contactable. Shared business
inboxes — hello@, info@, contact@, support@ — stay allowed too, since for
a small company that is often the only address published and is a
legitimate target, unlike anything on the list.

The addresses in the test are the real ones that were mailed, kept
verbatim so the case that failed is the case that is asserted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit dba24be into master Jul 28, 2026
8 checks passed
@ralyodio
ralyodio deleted the fix/never-contact-gaps branch July 28, 2026 04:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant