**Describe the bug** When using Nextcloud Mail, legitimate mailbox synchronization requests trigger a ban within roughly a minute. CrowdSec sees requests such as: ```text http_path: /apps/mail/api/mailboxes/<id>/sync http_status: 403 http_verb: POST log_type: http_access-log service: http ``` **To Reproduce** 1. Open browser developer tools on the Network tab. 2. Open Nextcloud Mail. 3. Observe `POST /apps/mail/api/mailboxes/<id>/sync` requests returning `403`. 4. Get banned by CrowdSec. **Expected behavior** Legitimate mailbox sync requests should not trigger a ban. **Screenshots** > [!Note] > `/auth/token` in the screenshot is not from Nextcloud but another service. <img width="1418" height="901" alt="Image" src="https://github.com/user-attachments/assets/8b646e3d-a32d-4e77-a8bc-781fa31dabae"/> **Additional context** `<id>` in `/apps/mail/api/mailboxes/<id>/sync` is a numeric mailbox ID.
Describe the bug
When using Nextcloud Mail, legitimate mailbox synchronization requests trigger a ban within roughly a minute.
CrowdSec sees requests such as:
To Reproduce
POST /apps/mail/api/mailboxes/<id>/syncrequests returning403.Expected behavior
Legitimate mailbox sync requests should not trigger a ban.
Screenshots
Note
/auth/tokenin the screenshot is not from Nextcloud but another service.Additional context
<id>in/apps/mail/api/mailboxes/<id>/syncis a numeric mailbox ID.