Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Mail adds "@mac.com" to addresses...security issue!

I've had this problem with my mail for several years, and I think I've tracked it down to the Mail application.

I have a very simple e-mail address...let's say it's "bob@mac.com" for argument's sake. I get e-mails day in and day out that people accidentally send to me. They have a friend, "Bob", and they type Bob's name in the Recipient field, but forget the domain. I believe that the Mail application is appending "@mac.com" to anything that's missing a domain. Each person who accidentally sends me mail is using a Mac, and more specifically the Mail application.

The result? I've gotten e-mail that's sensitive...that I shouldn't have. I got a message from somebody about a public company going bankrupt. I got audio files from a doctor about patients that he thought he was sending to a transcriptionist. I got the personal stats from the World's Biggest Loser contestants, including their weight. My .Mac inbox is full of pictures of people's kids and pets, and people send me huge files that max out my storage. The best was a discussion between Hooter's upper management about their girls misbehaving while opening a new store! It is a hassle to say the least. But more importantly, it's a security issue for other Mail users who inadvertently send personal and financial information accidentally to me!

I've contacted others with short .Mac addresses, and each is having a problem with this.

It is a security issue, and could open Apple up to liability. Me having that bankruptcy information could've led to insider trading. HIPAA rules for patient privacy. If I was an unscrupulous person, I could do a lot of damage.

I can't find any settings to turn off the "autocomplete" of @mac.com. There is a setting for autofilling "known" addresses. But this is different.

iMac Intel 20", MacBook Air, iBook G4, iPhone, Mac OS X (10.6.4)

Posted on Jul 14, 2010 9:50 AM

Reply
6 replies

Jul 14, 2010 10:34 AM in response to katkramer

If you send e-mail this way, Mail will send it on to the server... some servers will reject such an e-mail, others will try to send it to a recipient with that name on the same mail server.

If someone is sending confidential information carelessly, it is that person's fault, not Apple's. Sending confidential information via e-mail is stupid. Strong word, but true. E-mail is a postcard. Unless encrypted, the e-mail is sent through all the numerous mail servers between you and the recipient in clear text. Anyone with access to any of those servers could read it. For that matter, anyone sitting back in the corner of the Starbucks or Panera where you're checking your mail could, with some free software, read any e-mail you send or receive.

Jul 14, 2010 11:45 AM in response to katkramer

As the others have said, this doesn't appear to be a problem with Apple Mail or MobilMe mail.

You might want to contact some of the senders. Explain what happened, and ask what mail app they're using. Just a guess, but most likely it's a 3rd-party app, that might be doing something like appending the last "@" that was used.

Aug 24, 2010 7:44 AM in response to katkramer

I have a mac.com email address and use Mac Mail, and I CAN replicate this problem. Some emails with no domain get @mac.com added and some don't -- I assume the difference is whether that address actually exists on mac.com. I did a test using my own address. The sent email shows just the beginning of the address but I received the email in my Inbox with the full address.

I would love to be able to stop this because even if you're not sending sensitive information, it can make you think you've sent an email that never went through.

Any help would be appreciated. Thanks!

Mail adds "@mac.com" to addresses...security issue!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.