In the tutorials for security measures step 10 says

10. Disable "Allow Guest To Tell A Friend" feature

You may wish to go to Admin > Configuration > Email Options > Allow Guest To Tell A Friend and set the option to false. This will prevent non-logged-in customers from using your server to send unwanted email messages.


On some websites folks are adding addthis social button groups to their product pages. The group of buttons includes an email icon with the ability for people to send emails to others from the product page. The email form has fields for the senders and recipients email address. Is this really ok to have on our product pages?