# Suspicious links in emails sent from vaultwarden?

**URL:** <https://vaultwarden.discourse.group/t/suspicious-links-in-emails-sent-from-vaultwarden/1299>\
**Category:** Help\
**Created:** [December 5, 2021, 4:41am UTC](https://vaultwarden.discourse.group/t/suspicious-links-in-emails-sent-from-vaultwarden/1299 "2021-12-05T04:41:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bb4242](https://avatars.discourse-cdn.com/v4/letter/b/3d9bf3/32.png) [@bb4242](https://vaultwarden.discourse.group/u/bb4242)\
**Post date:** [December 5, 2021, 4:41am UTC](https://vaultwarden.discourse.group/t/suspicious-links-in-emails-sent-from-vaultwarden/1299/1 "2021-12-05T04:41:03Z")

</div>

Hi, and thanks for a great project! I just installed vaultwarden using the `vaultwarden/server` docker image. I sent two emails from vaultwarden to verify my SMTP server settings and invite a user. The emails I received both contained suspicious looking links that begin with `https://0llnh.mjt.lu/lnk/` followed by a lot of random characters. I would have expected any links generated by vaultwarden to point back to my own server. Furthermore, a quick search through github ([Search · 0llnh.mjt.lu · GitHub](https://github.com/dani-garcia/vaultwarden/search?q=0llnh.mjt.lu)) for that domain turns up nothing. This all appears pretty suspicious, especially for software with critical security implications, and makes me wonder whether the docker image I’m using has been compromised in some way. Can anyone explain why these links point to `0llnh.mjt.lu`, and what their purpose is?

---

<div class="post-metadata">

**Author:** ![BlackDex](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/blackdex/32/8_2.png) [@BlackDex](https://vaultwarden.discourse.group/u/BlackDex)\
**Post date:** [December 5, 2021, 7:50am UTC](https://vaultwarden.discourse.group/t/suspicious-links-in-emails-sent-from-vaultwarden/1299/2 "2021-12-05T07:50:49Z")

</div>

This has nothing to do with Vaultwarden, but with the mail server you are using it looks like.

If i go to that link [http://0llnh.mjt.lu/](http://0llnh.mjt.lu/), it tells me it is a mail platform and that it shortens links.

I’m not sure what kind of mail server you are using but it looks like it is using mailjet.

---

<div class="post-metadata">

**Author:** ![bb4242](https://avatars.discourse-cdn.com/v4/letter/b/3d9bf3/32.png) [@bb4242](https://vaultwarden.discourse.group/u/bb4242)\
**Post date:** [December 5, 2021, 1:31pm UTC](https://vaultwarden.discourse.group/t/suspicious-links-in-emails-sent-from-vaultwarden/1299/3 "2021-12-05T13:31:32Z")

</div>

Ah, yeah, you’re right! I just started using mailjet and didn’t even consider the possibility that the mail server itself might modify the links. Thanks!
