Email security@blamepost.com
with a description of the finding and a reproduction
recipe. We acknowledge every report; if the report
represents a real vulnerability, we coordinate on a
disclosure timeline with you. Coordination follows
ISO 29147 / 30111 norms.
What the program doesn't cover: network-layer
denial-of-service against the public mail listeners
(front-end rate-limiting is best-effort, not a guarantee);
findings that require admin access we issued you;
findings against third-party services blamepost uses
(those go to the upstream provider).