Record Brevo authentication tracking limitation
This commit is contained in:
parent
e618ec80dd
commit
8b9dadba39
|
|
@ -181,7 +181,10 @@ as forward-only rather than receiving an invented database rollback.
|
||||||
and is DKIM-signed by the production domain.
|
and is DKIM-signed by the production domain.
|
||||||
- [ ] Authentication-email action URLs use the production domain directly.
|
- [ ] Authentication-email action URLs use the production domain directly.
|
||||||
Brevo currently rewrites the action href through its tracking domain even
|
Brevo currently rewrites the action href through its tracking domain even
|
||||||
though the visible fallback origin is `https://whoneedhelp.com/`.
|
though the visible fallback origin is `https://whoneedhelp.com/`. A
|
||||||
|
read-only account check on 2026-08-21 found only Brevo's account-wide
|
||||||
|
anonymous-tracking control; Brevo documents that this still records
|
||||||
|
aggregate clicks, so it is not evidence that action URLs remain direct.
|
||||||
- [x] The Web Push provider accepts a production notification for a real active
|
- [x] The Web Push provider accepts a production notification for a real active
|
||||||
browser subscription without disabling the device.
|
browser subscription without disabling the device.
|
||||||
- [ ] A person has observed the resulting operating-system browser notification
|
- [ ] A person has observed the resulting operating-system browser notification
|
||||||
|
|
|
||||||
|
|
@ -3307,3 +3307,22 @@ promoted.
|
||||||
externally verify an inbound project address, or deliberately publish another
|
externally verify an inbound project address, or deliberately publish another
|
||||||
monitored email address. Current outbound Brevo delivery does not prove that
|
monitored email address. Current outbound Brevo delivery does not prove that
|
||||||
`contact@whoneedhelp.com` can receive mail.
|
`contact@whoneedhelp.com` can receive mail.
|
||||||
|
|
||||||
|
# 2026-08-21 Brevo authentication-link tracking recheck
|
||||||
|
|
||||||
|
- A read-only check reused the existing authenticated Chrome dev-port tab and
|
||||||
|
inspected `Settings > Automations > Transactional emails > Tracking`. The
|
||||||
|
account exposed one control, `Anonymous email tracking`, and its observed
|
||||||
|
value was `No`. No setting was changed or saved.
|
||||||
|
- Brevo's current help documentation states that anonymous tracking continues
|
||||||
|
to record opens and clicks in aggregate while removing their association with
|
||||||
|
specific contacts. The current SMTP documentation does not publish a
|
||||||
|
per-message header that disables click tracking. Therefore neither enabling
|
||||||
|
the observed anonymous option nor adding an undocumented SMTP header is
|
||||||
|
accepted as proof that authentication action URLs remain on the production
|
||||||
|
domain.
|
||||||
|
- The direct-production-domain action-URL gate remains open. Resolving it
|
||||||
|
requires an explicit provider/account decision followed by a newly delivered
|
||||||
|
authentication message whose actual href is inspected; no provider setting,
|
||||||
|
application email format, production deployment, frozen test deployment, or
|
||||||
|
public Git remote was changed by this recheck.
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user