Email privacy
Silktide finds the email addresses published on your pages so you can check that none of them expose personal data without consent. Addresses like a personal work email may need the owner's agreement to publish, while shared addresses usually don't.
Why this matters
An email address that identifies a person, such as jane.smith@example.com, is
under privacy laws like the
. Publishing it needs a lawful basis - usually the
person's consent - and people can ask for it to be removed. Role-based addresses
such as info@ or support@ identify a function rather than a person, so they
carry far less risk.
Published addresses are also harvested by spam bots, so every address you list attracts junk mail and phishing attempts aimed at its owner.
How to fix it
This check gathers addresses for you to review; Silktide cannot judge whether publishing a given address is appropriate.
- For each address, decide whether it identifies a person. Shared addresses
like
hello@example.comare usually fine. - For personal addresses, confirm the owner consents to the publication, and record that consent. Where practicable, prefer a shared alias or a contact form.
- Remove addresses that no longer need to be public, such as those of former staff.
- When an address is acceptable as published, the finding so it is not raised again.
How Silktide tests this
- Examine the content of each page, including
mailto:links. - Find text that appears to be an email address.
- Skip any elements you have excluded from testing.
- Report each address found, with where it appears, for you to review.
Troubleshooting
The same address is reported on many pages
Addresses in headers and footers appear on every page. Fixing the template fixes every page at once.
An obfuscated address isn't found
Addresses written as "jane dot smith at example dot com" or assembled by may not be detected. Note that determined harvesters often defeat these tricks too, so do not rely on obfuscation as a privacy measure.