# \[PRIVACY\] E-mail recipients shouldn't be disclosed

**URL:** <https://community.letsencrypt.org/t/privacy-e-mail-recipients-shouldnt-be-disclosed/16859>\
**Category:** Uncategorized\
**Created:** [June 11, 2016, 2:08am UTC](https://community.letsencrypt.org/t/privacy-e-mail-recipients-shouldnt-be-disclosed/16859 "2016-06-11T02:08:00Z")\
**Posts on this page:** 1\
**Showing post:** 9

<div class="post-metadata">

**Author:** ![LtTragg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lttragg/32/6607_2.png) [@LtTragg](https://community.letsencrypt.org/u/LtTragg)\
**Post date:** [June 12, 2016, 2:51pm UTC](https://community.letsencrypt.org/t/privacy-e-mail-recipients-shouldnt-be-disclosed/16859/9 "2016-06-12T14:51:12Z")

</div>

Apparently the email was sent by a service called “Mandrill” which is a “transactional email platform from MailChimp”. See also [https://www.mandrill.com/](https://www.mandrill.com/)

Since the sensitive content appears in the message body of the emails, one imagines it might have been a bug on LE’s part when interacting with the Mandrill service. If so, shame on you, LE, and one hopes a strict process will be put in place to prevent this in future.

On the other hand, if Mandrill’s service was responsible for the leak, then as a provider of the very kind of service one expects not to exhibit this kind of fault, they should be sacked outright.

---

_[View the full topic](https://community.letsencrypt.org/t/privacy-e-mail-recipients-shouldnt-be-disclosed/16859)._
