Contact
Corsair is software, not a company. Where to go depends on what you need.
Something is wrong with the software#
Bugs, missing features, and questions about how it works belong on the issue tracker: github.com/wess/corsair.
Include the version, what you expected, and what happened. For anything to do with mail delivery, include the full headers of the message — a delivery report without headers is almost never actionable.
Something is wrong with mail on this server#
If you are a customer of somebody running Corsair, the operator of this instance is who you need, not the project. They set the abuse and support addresses; the footer of their site is the place to look.
Security#
Report vulnerabilities privately rather than on the public tracker. The contact address is published at /.well-known/security.txt on every instance.
Please include enough detail to reproduce it. If it involves mail flow, a message that demonstrates the problem is worth more than a description of it.
Reporting abuse from this server#
Send the full message, with headers, to the operator's abuse address. A report without headers cannot be traced to an account and cannot be acted on.