Skip to content

"For security reasons, we have not included a link with this email." #887

@anthonygood

Description

@anthonygood

Why is this? The CONTRIBUTING.md adds a detail which offers no clarification:

For security reasons, it is currently HMRC policy that there are no links in emails, either in HTML or plain text, hyperlinked or not.

This is because there is no guaranteed way to stop an email reader, plain text or HTML based, from spotting a http://wherever.com/some-url link and turning it into a hyperlink - this has been researched extensively. The only permissible exception to this under policy is verification links, which are vital for proving a customer's address.

What's the rationale for this policy?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions