# Splitting the email atom: exploiting parsers to bypass access controls

DevFeed: [Splitting the email atom: exploiting parsers to bypass access controls](<https://devfeed.tech/articles/splitting-the-email-atom-exploiting-parsers-to-bypass-access-controls-7699.md>)

Original publisher: [Read original article](<https://portswigger.net/research/splitting-the-email-atom>)

Author: Gareth Heyes

Published: 2024-08-07T21:32:47Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article explains how discrepancies between email-address parsers can lead to access-control bypasses and remote code execution when applications make security decisions from an inferred email domain.

## Source excerpt

Some websites parse email addresses to extract the domain and infer which organisation the owner belongs to. This pattern makes email-address parser discrepancies critical. Predicting which domain an