MailFlow v3.8.3
Undo send, forwarding a message as an attachment and per-sender categories, plus three security fixes and a fix for deletes that skipped the Trash. Update when you can. Thanks to @Monkey7539 for the security and reliability fixes and @prudenciooficial for undo send.
Security
- Sending could fall back to plain text (#566). An account set to STARTTLS sent its login and the message unencrypted when the server, or anyone on the network path, left STARTTLS out. Sending now fails instead, unless the admin setting "Allow insecure TLS" is on. Invite and password-reset emails are covered too.
- Signed-out devices kept getting new-mail notifications (#558). After signing out, a device could still show the sender and subject of new mail to whoever used it next. Signing out now turns off notifications on that device; turn them back on in Settings after signing in again.
- Large requests were read before the sign-in check (#560). A signed-out client could make the server read and parse up to 35 MB per request. Those requests are now refused before their body is read in.
Fixes
- Deletes in some of your own folders skipped the Trash (#559). On an account without a Trash folder mapping, which is the default, any folder whose name contained "trash", "deleted" or "draft", such as "Blog drafts", deleted mail permanently once the undo toast closed. Only the account's real Trash and Drafts folders delete permanently now.
- Forward rules could loop (#564). Two mailboxes whose rules forwarded to each other sent the same mail back and forth without end. Each forward now carries an
X-MailFlow-Loopheader, and a mailbox stops when mail it already forwarded comes back. - A backfill could retry a failed login until restart (#568). After an account was disabled, or its password stopped working, its backfill kept trying to log in every 10 to 30 seconds and held up other background work for that provider. It now stops, and the regular folder check fills in what it missed once logins work again.
- AI features that don't stream (the admin connection test, AI classification and GTD gists) failed against OpenAI's API (#565).
- Antispam: attachments now count toward the verdict on incoming mail, not only after a message is opened (#457).
- Keyboard shortcuts keep working after clicking into an email's body (#537).
- A collapsed folder shows its subfolders' unread mail (#536).
- The bulk move picker shows Recent and Favorites (#551).
- Signing out from the lock screen now also ends the SSO session and clears the previous user's mailbox settings, like signing out from the sidebar (#523).
- A message moved out of Snoozed by hand can be snoozed again right away (#269).
- AI action lists show their bullets and numbers (#557).
- Dependency updates for new advisories in proxy-addr, Capacitor, DOMPurify and source-map-js. None of them was exploitable in MailFlow.
New
- Undo send (#533). A sent message waits 10 seconds on the server before it goes out, and Undo in the toast reopens it as it was, attachments included. Closing the tab during those seconds still sends it. "View" after sending now opens the sent message.
- Forward as attachment (#466), in the message menu, attaches the original email as a .eml file.
- "Always for this sender" and "Always for this domain" (#490), under Categorize. Each saves an inbox rule that puts that sender's existing and future inbox mail in the chosen category.
- A "Set category" rule action (#489). Choosing Primary for a message now sticks, instead of being re-categorized later.
NGINX_TLS=off(#516) turns off the frontend's HTTPS server and its self-signed certificate, for setups where a reverse proxy handles TLS and connects to port 80.
Upgrading
ghcr.io/maathimself/mailflow-backend:latest points at 3.8.3, published for amd64 and arm64. There are no database migrations.
- Sending now requires STARTTLS. If an account's SMTP server doesn't offer STARTTLS, sending from it fails. Use SSL/TLS on port 465 if the server supports it, or turn on "Allow insecure TLS" in the admin panel.
NGINX_TLSneeds the new compose file. If you run the prebuilt images with a compose file downloaded before this release, download it again, or addNGINX_TLS: ${NGINX_TLS:-}to the frontend's environment, before setting it. Without it, nothing changes.- Undo send holds messages in the backend for 10 seconds. Stopping or updating the backend normally sends held messages right away before it exits. If it crashes, the browser reopens any message that didn't go out.
- Tabs opened on 3.8.0 or later reload into the new version by themselves; reload any older ones.