github ShlomiPorush/mailcow-logs-viewer v2.9.0
2.9.0

2 hours ago

[2.9.0] - 2026-10-04

Added

  • DNSSEC and DANE checks - The Domains page shows whether each domain is DNSSEC validated, and whether DANE actually works: TLSA records must be DNSSEC validated and match the certificate each mail server presents. A TLSA record that stops matching the certificate triggers a DNS change alert. #287. Thanks to @Neocridas.
  • TLS-RPT record check - The DMARC page is now called DMARC & TLS, and each domain shows a TLS-RPT Record card next to the DMARC Record card: whether the domain publishes a TLS-RPT record and where TLS reports are sent, so a missing or broken record explains why no reports arrive. A change to the record triggers a DNS change alert. #328. Thanks to @homonto.

Security

  • Safer display of stored values - Escape more values from reports and settings where the interface shows them, reject report domains that are not valid domain names, and accept only known services in the raw logs service list.

Fixed

  • Hebrew and Arabic subjects - Subjects written in Hebrew or Arabic were shown left to right, so brackets, punctuation and numbers landed on the wrong side. They are now shown in their own reading direction in the message lists, the message details, Quarantine and Rate Limits.
  • DKIM records rewritten by DNS providers - A published record with reordered tags, an added h=sha256, a missing t=s or a folded key is no longer reported as a mismatch. Only a different key, key type or hash that breaks signing is an error; other tag differences show as warnings. #292. Thanks to @phende.
  • DMARC reports with empty rows - Some providers send aggregate reports whose rows have no source IP and a count of 0. Such a report failed on every sync with a database error; the empty rows are now skipped and the report is stored. #324. Thanks to @fadorator.
  • Fail2ban Unban - Unban on the Security page failed with an error: the app called an endpoint mailcow does not have. It now uses mailcow's own unban request. Saving the Fail2ban settings, and Ban, also no longer switch off mailcow's "manage external" option.
  • Settings edits lost before the first migration - With UI editing enabled, the settings form accepted changes before Migrate Settings from ENV was clicked, but offered no Save button, so the changes were lost. The form is now read-only until the migration, with a short explanation next to the button. The Settings UI docs describe this step. #354. Thanks to @numericOverflow.

Don't miss a new mailcow-logs-viewer release

NewReleases is sending notifications on new releases.