nextcloud / nextcloud/mail

System address book not taken into account for phishing detection

Open
#12,229 2 comments 0 reactions 1 assignee View on GitHub

@kesselb is already working on this.

Since Jan 12, 2026.

1. to develop bug
Dominant language
JavaScript
Stars
1k
Forks
348
Avg merge
12h 28m
Merged PRs (30d)
91

Description

Steps to reproduce

Receive a mail from a person that has an account on the Nextcloud instance. Note that the person has the correct mail address set for the account.

Expected behavior

When checking for a phishing attempt, the address book is checked for known senders. I would expect that the system address book is also taken into account here, unless I am missing a reason for not taking that into account?

Actual behavior
Image
Mail app version

5.7.0-beta.1

Nextcloud version

32.0.3

Mailserver or service

Exchange

Operating system

Debian 13

PHP engine version

Other

Nextcloud memory caching

APCu & Redis

Web server

Apache (supported)

Database

MariaDB

Additional info

PHP 8.4.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.