Strengthen your web sign-in.
Enable optional two-step authentication with an authenticator app and save your one-time recovery codes. Review active sessions and recent account access, then revoke sessions you no longer recognize or need.
Evolena’s two-step protection applies to its web sign-in. It does not replace authentication settings for a separate IMAP, SMTP or mail-administration service.
- Authenticator-app codes and recovery codes
- Active web-session review and revocation
- Sensitive account changes require additional verification
Choose how external content is loaded.
Remote email images are blocked by default. You can allow images for a message or change your account preference. Loading a remote image may contact the sender’s server and disclose network or viewing information.
Email content is sanitized for display. Attachment downloads and supported image previews use the account’s current access permissions. No claim of end-to-end email encryption is implied by these controls.
Report a suspected vulnerability privately.
Send security reports to [email protected] with “Security report” in the subject. Include the affected Evolena URL, a clear description, steps to reproduce and the likely impact.
Use your own account and sample data. Remove passwords, session cookies and unnecessary personal information from screenshots or examples. Please do not include other people’s email content.
- Contact: [email protected]
- Include dates, affected URLs and reproducible steps
- The discovery contact is also published at /.well-known/security.txt
Keep a report focused on the issue.
Stop if a test exposes another person’s data, interrupts service or requires access you do not have. Report what you observed without extracting more information.
Publishing a reporting contact does not grant permission for disruptive testing, establish a bounty or promise a response deadline. For spam, phishing or abusive email, use [email protected].