You can set up emails to be forwarded to your HackerOne inbox to enable report management directly through HackerOne. Hackers that discover these specific email addresses will be able to submit reports directly to your program. Upon sending reports through the email, they'll also automatically get invited to your program.
Note: This feature isn't available until your program is launched and not in sandbox mode.
How Does it Work?
When a hacker discovers a vulnerability and sends their finding in an email to email@example.com:
- Their emails are forwarded to HackerOne's inbox and saved as report drafts.
- The hacker will receive an auto-response email notifying them that your program uses the HackerOne platform to coordinate vulnerabilities. They can click the Submit Vulnerability Report link.
- The link will prompt the hacker to create a HackerOne account if they don't already have one, or to log in to their existing account.
- After the hacker signs in to the account, the Submit Vulnerability Report button will be available for them to click. Upon clicking this button, the hacker is automatically invited into your program. The button will take them to the report submissions page, where they can claim the report draft and submit a valid HackerOne report to your program.
- You will then be notified of a new vulnerability submitted by the hacker in your inbox where you can use the platform tools to comment, triage, and pay bounties.
- Go to Settings > Program > Hacker Management > Email Forwarding.
- Click on Add email address.
- Enter the email address the vulnerability reports should be sent to. A common example is: firstname.lastname@example.org.
- The inbox address that your email will be configured to will automatically generate. Upon configuration, emails sent to email@example.com will be forwarded to the inbox address given.
- Click Run test to ensure that forwarding is set up correctly.
Note: You can add multiple email addresses to forward to the same inbox.
Don't know how to set up email forwarding for your email provider? Check out these resources for: