mailto link is blocked as insecure content in Chrome Gmail

10,663

Solution 1

From here: mailto link not working within a frame chrome (over https)

The suggestion is to use target="_top" instead of target="_blank".

Solution 2

I solved this with a little JavaScript trick.

Here is my index.html

<div>
    <input id="cname" required="" name="subject" type="text">
    <label for="cname">Name</label>
    <textarea id="cmessage" required="" name="body"></textarea>
    <label class="label-control" for="cmessage">Your message</label>
</div>
<button onclick="sendMail()">Click me</button>

and script.js which get loaded into index.html earlier.

function sendMail() {    
    var body = document.getElementById("cmessage").value;
    var subject = document.getElementById("cname").value;

    window.location.replace(`mailto:[email protected]?body=${body}&subject=${subject} wants to contact you`);    
}

and now I got the full green lock back.

enter image description here

Share:
10,663
Admin
Author by

Admin

Updated on June 05, 2022

Comments

  • Admin
    Admin almost 2 years

    I've got a link in an encrypted HTML email that goes to mailto:blahblah, but it's being blocked in Chrome Gmail. Anything I can do about this?

    Example:

    1) I open an encrypted HTML email message inside of my encrypted GMail web client (https://gmail.com - notice the s in https).

    2) The email contains a link in the folloiwng format: <a href="mailto:[email protected]">Email the user.</a>

    3) I click on the link, but it is blocked because GMail and/or Chrome is treating the mailto link as insecure content.

    4) I add target="_blank" to the aforementioned link and the problem goes away.

    The rest of the message displays and functions correctly because, again, both the message and my email client are using encryption. The only thing that does not work is the mailto link.

    Bonus question: how are mailto links classified with regard to protocols such as HTTP and HTTPS? Links to a W3C document would be helpful.

  • Mr-Programs
    Mr-Programs over 5 years
    i have tried top and blank and yet "connection is not secure", if i remove the mailto from the action goes fully secure so def is the form, any help? site is www.mr-programs.com
  • kenmistry
    kenmistry over 3 years
    this isn't working for me. did you set up a redirect for your link? and how?