Record Brevo authentication tracking limitation

This commit is contained in:
SimpleTest 2026-08-21 01:28:56 +03:00
parent e618ec80dd
commit 8b9dadba39
2 changed files with 23 additions and 1 deletions

View File

@ -181,7 +181,10 @@ as forward-only rather than receiving an invented database rollback.
and is DKIM-signed by the production domain.
- [ ] Authentication-email action URLs use the production domain directly.
Brevo currently rewrites the action href through its tracking domain even
though the visible fallback origin is `https://whoneedhelp.com/`.
though the visible fallback origin is `https://whoneedhelp.com/`. A
read-only account check on 2026-08-21 found only Brevo's account-wide
anonymous-tracking control; Brevo documents that this still records
aggregate clicks, so it is not evidence that action URLs remain direct.
- [x] The Web Push provider accepts a production notification for a real active
browser subscription without disabling the device.
- [ ] A person has observed the resulting operating-system browser notification

View File

@ -3307,3 +3307,22 @@ promoted.
externally verify an inbound project address, or deliberately publish another
monitored email address. Current outbound Brevo delivery does not prove that
`contact@whoneedhelp.com` can receive mail.
# 2026-08-21 Brevo authentication-link tracking recheck
- A read-only check reused the existing authenticated Chrome dev-port tab and
inspected `Settings > Automations > Transactional emails > Tracking`. The
account exposed one control, `Anonymous email tracking`, and its observed
value was `No`. No setting was changed or saved.
- Brevo's current help documentation states that anonymous tracking continues
to record opens and clicks in aggregate while removing their association with
specific contacts. The current SMTP documentation does not publish a
per-message header that disables click tracking. Therefore neither enabling
the observed anonymous option nor adding an undocumented SMTP header is
accepted as proof that authentication action URLs remain on the production
domain.
- The direct-production-domain action-URL gate remains open. Resolving it
requires an explicit provider/account decision followed by a newly delivered
authentication message whose actual href is inspected; no provider setting,
application email format, production deployment, frozen test deployment, or
public Git remote was changed by this recheck.