diff --git a/docs/operations.md b/docs/operations.md index 7836be3..fb75a37 100644 --- a/docs/operations.md +++ b/docs/operations.md @@ -208,6 +208,13 @@ test checkout. The generated file uses the ordinary runtime names: | Verified Android links | `ANDROID_APP_LINKS_PACKAGE_NAME`, `ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS` | | Transactional email | `SMTP_*`, sender, and `SUPPORT_INBOX_ADDRESS` | +`SUPPORT_INBOX_ADDRESS` configures `Reply-To` and the optional operator-alert +destination. The environment readiness script validates only that this value is +present and syntactically usable; it does not prove that the domain has inbound +MX routing or that the mailbox is monitored. Check DNS and perform an actual +inbound delivery/reply test before presenting the address as a public support +contact. + Do not reuse a Google client, VAPID private key, Firebase project/service account, SMTP credential, or Android signing key between dev and production. The public Firebase Android values are build configuration; the Base64 FCM diff --git a/docs/public-launch-checklist.md b/docs/public-launch-checklist.md index d7317bb..a54d353 100644 --- a/docs/public-launch-checklist.md +++ b/docs/public-launch-checklist.md @@ -67,6 +67,9 @@ The release check covers the application origin and secrets, database selection, SMTP and support routing, Google OAuth, browser VAPID, Firebase/FCM, Android package/signing configuration, and production App Links. It does not prove that external providers will deliver successfully after deployment. +In particular, a configured `SUPPORT_INBOX_ADDRESS` is not evidence of inbound +mail delivery: verify its MX routing and complete a real receive-and-reply test +before using it in Google Play or public support pages. ## 3. Record human and legal decisions diff --git a/scripts/check-environment-readiness.sh b/scripts/check-environment-readiness.sh index dca5713..8bfaa7c 100755 --- a/scripts/check-environment-readiness.sh +++ b/scripts/check-environment-readiness.sh @@ -226,9 +226,10 @@ else fi if is_set SUPPORT_INBOX_ADDRESS; then - ready "support inbox" "operator destination is configured" + ready "support reply address" \ + "address is configured; inbound DNS and mailbox delivery require a separate test" else - missing "support inbox" "SUPPORT_INBOX_ADDRESS" + missing "support reply address" "SUPPORT_INBOX_ADDRESS" fi rate_limit_policies_json=$(value RATE_LIMIT_POLICIES_JSON)