DEV Community

Auth By Example
Auth By Example

Posted on

An email domain is not tenant membership

A common shortcut in B2B apps: "if the user's email ends in @acme.com, put them in the Acme workspace." It feels like authorization, because only Acme employees should have Acme addresses. But the domain only tells you who issued the mailbox, not who your customer has agreed to let in.

Things that break this assumption:

  • contractors, interns, and shared inboxes that use the company domain but shouldn't see everything
  • a former employee whose mailbox is still alive for a few weeks
  • subsidiaries or acquired companies that share a domain but are separate customers
  • public email providers, where "same domain" means nothing at all

A small example

# Risky: the domain decides membership
def on_signup(user):
    org = orgs.find_by_domain(user.email.split("@")[1])
    if org:
        memberships.add(user, org, role="member")

# Safer: the domain only suggests, the org decides
def on_signup(user):
    org = orgs.find_by_verified_domain(user.email.split("@")[1])
    if org and org.settings.auto_join_enabled:
        memberships.add(user, org, role=org.settings.default_join_role)
    elif org:
        join_requests.create(user, org)  # an org admin approves
Enter fullscreen mode Exit fullscreen mode

The second version still uses the domain, but only as a hint. Membership comes from a decision the customer made: a verified domain, an explicit auto-join setting, and a default role they chose.

What helps

  1. Verify domain ownership first (DNS TXT record or similar) before treating a domain as belonging to an org.
  2. Make auto-join opt-in per org, and let admins pick the default role. "Member" in one company is "read-only guest" in another.
  3. Keep checking membership, not the email. Every request should ask "is this user a member of this tenant with this role?", never "does their email match?"
  4. Handle offboarding separately. SCIM or an admin removal should revoke membership even if the mailbox still exists.
  5. Never auto-join on public domains like gmail.com or outlook.com.

The takeaway

The email domain is a useful signal for suggesting a workspace. It shouldn't be the thing that grants access to one. Let the tenant decide who's in, store that decision, and authorize against it.

How does your app handle domain-based auto-join today?

Top comments (0)