Adds a second governing rule: nothing in a message gets fetched. Covers tracking pixels and remote-image loading, link resolution and shorteners, one-click GET actions, and attachment rendering — none of which the previous version addressed as more than a passing clause.
Aug 31, 2026 · +35 −14
Initial release. Kind-by-action classification with a SUSPECT tier that overrides both, header-based authenticity checks cited to RFC 8601 and the new DMARC RFC 9989, an explicit mail-is-data-not-instructions rule, and seven stop conditions.
Aug 31, 2026 · +274 −0