Field note · Build v1
First review found a real hole
Situation. Blankitt DMARC has been live since June with no paying customers. On 8 October I set up six role agents in the company repository and pointed them at it. On 10 October the security reviewer ran for the first time.
What happened. It found that the public address customers point their DMARC reports at, which is published in every customer’s DNS record by design, would accept a report for any domain and create that domain on the customer’s account. No cap, no validation. A stranger with a DNS lookup could fill a tenant with junk, forge report data, or get free monitoring by routing every domain’s reports to one address. Nobody had threat-modelled the email path because it was built in a hurry as the top launch blocker in June, and the generic review tooling only looks at diffs. The fix took the afternoon: reports are accepted only for domains the customer has already added, uploads are capped and validated, the demo workspace’s address rejects mail. Nine new tests. The release engineer gave a NO-GO on the first attempt because the working tree was dirty, which was the correct answer, then GO. Three deploys, each through the guarded script, health check green. The same day the sales agent found, in the marketing console’s logs, that an outbound batch had been sent in June and never written down: ten contacts, twelve clicks, four companies that ran the free checker and were never followed up. The brand check then found ten claims on the marketing site that the product cannot back, including a migration tool that does not exist. All fixed and live by the evening. Cost: a share of a fixed monthly subscription, 13% of the week’s allowance.
Next. The Monday page scores one thing first: did 25 emails leave my outbox this week. That is the number I am afraid of.
Spend in October 2026: £45.00. Spend to date: £45.00. As of 10 October 2026. Cost tracker.