Missing User Warnings
Medium
- Confidence
- 82% confidence
- Finding
- MX and A-record checks send the target domain to system-configured DNS infrastructure, which can disclose user-supplied email domains to external resolvers without an explicit warning or consent mechanism. In a signup or bulk-validation context, this may expose sensitive customer, employee, or lead data patterns, especially when validating private or internal addresses.
