vulns.co
/
GKData.io MCP

Fastmail Pty Ltd · 2 min read

Fastmail Bug Bounty

Fastmail Pty Ltd · Direct vendor program. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Protect data integrity, privacy and service availability. Disruption and social engineering are prohibited. Intended email behavior, unlikely-interaction findings, third-party services, username enumeration, obsolete clients and low-impact metadata are excluded.

Eligibility and submission status

First reports must demonstrate a qualifying threat to private user data or infrastructure. Use controlled test accounts; interacting with another account requires its owner’s consent. Responsible disclosure and reasonable remediation time are required.

The policy expressly invites immediate email reports and commits to investigating all legitimate submissions. This is published intake evidence, not a delivery test.

Advertised rewards

Qualifying reports advertise USD 100–5,000, determined by severity and affected users at Fastmail’s discretion. Payments are processed monthly through PayPal; recipients bear taxes and fees. These are guidelines, not individual awards.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 2 published rows
AssetTypeGroup / eligibility
Fastmail-operated code and infrastructurepolicy_category
app.fastmail.comPublished location: https://app.fastmail.comwebsite
Out of scope · 3 published rows
AssetTypeGroup / eligibility
user.fmdomain
fastmailusercontent.comdomain
www.fastmailfbl.comwebsite

Review limitations

  • The reward sentence explicitly uses US$ for its minimum; the adjoining dollar maximum belongs to that same schedule.
  • No revision date, change log, age or residency criterion was established. No submission was made. Live terms prevail; no testing authorization is granted.

Sources and provenance

  1. Fastmail Security Issue Reporting Fastmail Pty Ltd · reviewed 2026-10-03
  2. Fastmail security issue reporting policy Fastmail Pty Ltd · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software