X-Get-Message-Sender-Via should have option to be removed from email header for security reason
We found a security information leak in our email headers: X-Get-Message-Sender-Via
this part include our cpanel account name and our confidential file path and name which send out the email, the file path disclose our web admin directory path. (like oscommerce websites, we login admin area to process order and send email to customers, hackers can easily get our admin login path by register as a fake customer and receive an email from us.)
we don't want our cpanel account name and admin path disclosed in email, so cpanel should have an option to disable X-Get-Message-Sender-Via info in email header, very important for security reason.