Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The verification email can be intentionally vague and agreed upon in advance.

"What's really your favorite band, then?"

"Beatles, I guess."



The best way would be to send an email disguised as spam, and have the employee respond out of band with its contents without actually replying.

Bonus points for sending similar emails to random @company.com addresses so receiving the email alone doesn’t suggest involvement.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: