After trying out the product, I discovered that the constraint for the email field is a bit loose given that emails like a@bc are allowed to be entered even though this is clearly not a valid email.

I suggest the development team can maybe reference some standards from RFC or OWASP
After trying out the product, I discovered that the constraint for the email field is a bit loose given that emails like a@bc are allowed to be entered even though this is clearly not a valid email.
I suggest the development team can maybe reference some standards from RFC or OWASP