Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not sure I understand the tradeoff here.

It sounds like people are gaining a little bit of extra privacy (by preventing spammers harvesting your email) while sacrificing a ton of privacy (by allowing a a third party MitM to intercept all of their emails to and from that domain).

I actually like the idea a whole lot, but I'd prefer if this could be done in some provably confidential way (where your service has no ability to see the content of messages, only To and From).



Of course you're putting some kind of trust in a third party. But the idea here is that you do that with all your good intentions and have a better alternative than just plain listing the address. It is up to us to prove our reliability, got some ideas on how to do that, but love to discuss that with you!

Apart from that it could also provide a service to your customers with the webhooks you utilize.


It's not hard to believe in good intentions, but a bit harder to believe that your service is and will always be secure. One breach and suddenly millions of emails from thousands of domains from old backups are all over the internet. There is a way of making a service like this with minimal risk if you have a full breach, but it's hard to verify that as an outsider.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: