RootBounty runs its own mail server, but only for three kinds of address:
| Address | Who | Purpose |
|---|---|---|
| company-username@rootbounty | Every verified company can activate one. | New reports, program decisions and messages from our staff, in one place for your security team. |
| staff-username@rootbounty | Each RootBounty administrator. | Replies from companies and researchers to messages staff sent. |
| no-reply@rootbounty | The platform. | Sender of every notification. Nobody reads it — don’t reply to it. |
Researchers don’t get a mailbox: notifications go to the personal email you verified at sign-up.
Settings → Mailbox → Create my mailbox. Choose a mailbox password of at least 12 characters, different from your RootBounty password: it is used by webmail and mail apps, which don’t support two-factor authentication. The address stays the same even if you later change your username.
https://mail.<domain> — sign in with the full address and the mailbox password.mail.<domain> port 993 (TLS), SMTP port 465 (TLS), username = the full address.Companies choose in Settings → Mailbox whether notifications go to their email, the mailbox, both or nowhere. Researchers choose in Settings → Notifications between their email and off. Sign-in codes and messages from our staff are always sent to the personal email.