Skip to content

SMTP Injection SendEmailCommand #5802

Answered by iann0036
nicosuerohynds asked this question in Q&A
Discussion options

You must be logged in to vote

SES performs server-side validation of customer input on the SendEmail API, but only for validity - i.e. the source field, in addition to being well-formatted, must also be a verified identity.

The SES team recommend customers apply best-practices and sanitise any external input themselves before passing it to any downstream system including SES.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by nicosuerohynds
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants