Files
validate/email.go
T
aneurinandClaude Sonnet 5 b47fc29e3c email: validate with net/mail.ParseAddress
Replace the RFC 5322 mega-regexp with net/mail.ParseAddress, which is the
standard library's address parser and far easier to audit. A bare address
is required: inputs with a display name, angle brackets, a comment, or
trailing content are rejected, as is an address list.

Behaviour change: ParseAddress does not require the domain to contain a
dot, so "alice@localhost" now validates. Layer Match or a DNS lookup on
top if a stricter domain is needed.

Also rewrites FuzzEmail, which previously asserted that *every* input is
invalid, into checks that Email never returns an unexpected error type,
never panics, and gives a stable verdict.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-07 13:21:17 +01:00

26 lines
699 B
Go

package validate
import (
"net/mail"
)
var (
ErrInvalidEmail = NewError("invalid email address")
)
// Email validates an email address using net/mail.ParseAddress.
//
// Only a bare address is accepted (alice@example.com). Anything with a
// display name, angle brackets, a comment, or trailing content is rejected,
// as is a list of addresses. Note that ParseAddress does not require the
// domain to have a dot, so "alice@localhost" is considered valid; layer on
// Match or a DNS check if you need to be stricter.
func Email(value string) error {
addr, err := mail.ParseAddress(value)
if err != nil || addr.Name != "" || addr.Address != value {
return ErrInvalidEmail
}
return nil
}