The system must guarantee that exposed email addresses can only be read by humans.
Sometimes, corporate email addresses are exposed on the company’s website or another overly public medium. These emails should only be visible to human beings, which can be accomplished by, for instance, publishing them as images instead of as plain text. This prevents automatic tools from collecting them and adding them to bulk email distribution lists.
- OWASP-ASVS v4.0.1 V11.1 Business Logic Security Requirements.(11.1.4): Verify the application has sufficient anti-automation controls to detect and protect against data exfiltration, excessive business logic requests, excessive file uploads or denial of service attacks.