# Email Delivery Hardening

## Context

The public contact form creates a `Reply-To` address from visitor-controlled name and email values. The locked Laravel 13.6.0 and Symfony Mime 8.0.8 versions are affected by CRLF/header-injection advisories. A folded address such as `test\r\n @example.com` can pass the vulnerable default email validator.

## Design

- Upgrade Laravel and Symfony mail packages to patched releases, resolve the lock against the declared PHP 8.3.0 minimum, and retain Composer's resolved versions in `composer.lock`.
- Add an application-level `SafeMailHeader` validation rule that rejects carriage returns and line feeds.
- Apply it to both the contact name and contact email because both values become mail headers.
- Replace the inline throttle with a named `contact-mail` limiter capped at five attempts per minute per IP. Turnstile and the honeypot remain in place.
- Keep contact orchestration in the existing allowlisted legacy controller; the shared validation rule lives in `app/Rules`.

## Verification

- Regression tests submit folded CRLF values and assert HTTP 422 with no mail sent.
- A rate-limit test asserts the sixth request from one IP returns HTTP 429.
- Run the focused tests, strict architecture audit, full Laravel suite, and `composer audit --locked`.
