All reports

Improved security for meil.no mail

WAYSCLOUD-TR-2026-0020Responsible DisclosureinformationalAction Taken
Published: 2026-06-03 15:49:29 UTC

Summary

Follow-up on Internet.nl findings for meil.no raised by Per Thorsheim. Score improved 73% to 83%; mail crypto hardened, RPKI/IPv6/IMAP items ongoing.

What Happened

In May 2026, security researcher and advisor Per Thorsheim highlighted several findings identified by Internet.nl.

After review, we implemented a number of improvements and confirmed that several previously reported issues have been resolved. As a result, the latest Internet.nl assessment shows a significantly improved score, rising from 73% to 83% compared to the original report.

Impact

No customer data exposure, service compromise or active security incident was identified. The findings relate to infrastructure hardening, resilience and adherence to modern Internet standards.

Actions Taken

In particular, cryptographic settings on our backup mail infrastructure were updated to align with current recommendations. These changes were completed and scheduled for full production rollout on 2026-06-05.

Preventive Measures

The remaining items primarily relate to infrastructure hardening and adherence to modern Internet standards:

  • RPKI / Route Origin Validation — We are continuing discussions with our upstream providers regarding ROA publication for relevant prefixes. RPKI helps reduce the risk of route hijacking and accidental route leaks on the global Internet.
  • IPv6 Mail Infrastructure — Additional IPv6 improvements for mail transport remain planned as part of our ongoing platform modernization efforts.
  • IMAP Security Considerations — IMAP remains widely supported across the industry, but the protocol does not natively support modern multi-factor authentication in the same way as web-based access. We continue to evaluate the balance between compatibility, usability and security when defining future access policies.

Affected Services

workspace

Acknowledgement

  • Per ThorsheimIndependent Security Advisor — Provided constructive feedback based on Internet.nl testing results, highlighting opportunities for improvement related to RPKI deployment, mail transport hardening and protocol security. The feedback contributed to several infrastructure improvements and helped validate our ongoing security roadmap.

See all security acknowledgements →