Skip to content

Scan rule · RSC-PRV-023

List of e-mail addresses public in the markup

Privacy (GDPR)Severity: Medium

Counts distinct e-mail addresses in the shipped HTML of the start page and the discovered sub-pages and reports from ten upwards — that looks like a publicly rendered member or customer list.

Why this matters

A handful of addresses in the legal notice or on the contact page is normal. Ten or more distinct addresses on one page are rarely operator contacts — usually it is a member, participant or customer list that an application renders without login because access control sits in the menu, not on the route.

Every crawler harvests these addresses. For the people concerned that means spam and phishing; for the operator a disclosure of personal data without a recognisable legal basis — and the question why the page is public at all. Role addresses of the operator (info@, contact@) are unproblematic; what counts is the number.

Check it yourself: open the named page in a private window, view the source and search for `@`. The evidence shows two examples masked — the report must not become the list itself.

Scan tier

External scan (anonymous)

How to fix it

Put lists containing personal data behind a login or remove the addresses; where publication is intended, document the consent of the people concerned.

Scan your own app for free