Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Exim does this since forever (http://www.exim.org/exim-html-current/doc/html/spec_html/ch-... - look for max_recipients). I would assume other MTAs do so too.

Problem is, options like these feel nice until they annoy you because you do in fact need more recipients. At that point you build a workaround into your software to send a new mail for every max_recipient users which brings you right back to square one with the additional technical dept caused by potential bugs in your batch sending code (off-by-one errors for example)

Be careful what you wish for :)



Just like one can have safe_parse() and unsafe_parse(), there could be an elevated API that could be safely used when vetted. For instance, when the SMTP server rejects a request it could put it in a special queue which requires manual confirmation.

This type of problems happen so regularly. In fact, a Japanese trader accidentally punched one too many zeros and lost a lot of money for the company. This type of problems can get very expensive in an instant. As an industry, we tend to think of input validation in passing because we don't pay enough attention to the problem domain.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: