Notification mail is outbound only. Replying to it should post a comment on the thread.
- Each notification carries
Reply-To: reply+<token>@<domain>; the token binds recipient, repository and issue/MR, and expires. - Inbound: either an SMTP listener in gitbayd behind an MX record, or polling a mailbox over IMAP. The second needs no open port.
- The reply is checked against the recipient's current rights; a revoked or disabled account posts nothing.
- Quoted text and signatures are stripped; the body is stored as markdown.
- Refusals send nothing back (no backscatter), recorded in the audit log.
- Setting per user, off by default, next to
notifications settings mail.
closed by cmc in commit 90d0cc2aad: wiki, changelog: reply by mail; fuzz the reply parsers
2026-09-29 06:52 UTC