github postalsys/mailauth v7.2.0

2 hours ago

7.2.0 (2026-10-09)

Features

  • bimi: apply the exact Assertion Record syntax in strict mode (85c4363), closes #166
  • dkim: over-sign header field names repeated in headerList (021218f), closes #153

Bug Fixes

  • arc: check a large authResults value without running out of stack (624e8a3)
  • arc: do not modify the caller's seal options (5c57a9d), closes #159
  • arc: fail a chain whose d= is not a host name (2f0babe)
  • arc: refuse an ARC-Authentication-Results value that breaks the header (43713b4), closes #161
  • arc: seal a malformed chain with cv=fail (c9a4e85), closes #162
  • arc: seal with the computed chain status and AAR in authenticate() (d6f7efc), closes #160
  • auth-results: write a U-label domain unquoted in strict mode (a24ffd6), closes #169
  • bimi: check the SVG Tiny PS document rules, add strict mode (4cf9bfc), closes #165
  • bimi: count From addresses with the parser of the DMARC check (0fb165e)
  • bimi: ignore an invalid BIMI-Selector header (7f62164), closes #167
  • bimi: read the avp= avatar preference tag (f577b50), closes #164
  • bimi: report validateVMC() results in Authentication-Results (6b03caa), closes #168
  • bimi: restrict logo and evidence downloads (658d8c2)
  • bimi: validate logos against an SVG Tiny PS element allowlist (0cf9679)
  • bimi: validate the logo from l= before building BIMI headers (bdc7b90)
  • dkim: check the key type against a= in both modes (4b9ef52), closes #146
  • dkim: encode i= as dkim-quoted-printable and check its syntax (59f63e1), closes #150
  • dkim: never align a signature when From has no single Author Domain (ac882e2)
  • dkim: parse key records without removing whitespace inside values (4b40376), closes #149
  • dkim: read the canonicalization option like a c= value (1383056), closes #152
  • dkim: reject a d= that is not a host name and never align it (387db0c)
  • dkim: reject an l= larger than the canonicalized body in strict mode (5139833), closes #147
  • dkim: report a key record name that can not exist as no key (d4f60ca), closes #145
  • dkim: report signatures that are skipped for a missing key (bda5402), closes #151
  • dkim: validate the c= syntax and canonicalize with the parsed value (5da00a5), closes #148
  • dmarc: discard a policy record with whitespace before v=DMARC1 in strict mode (d84decf), closes #143
  • dmarc: discard record fragments without "=" (0cdcf56), closes #142
  • dmarc: parse the From header by the RFC 5322 grammar (08da841)
  • dmarc: reject a From local-part with a domain literal between its words (ec0af9e)
  • dmarc: reject an Author Domain with control or format characters (e1f1bb7)
  • mailauth: use the HELO name from the Received header with trustReceived (f7e2869), closes #156
  • mta-sts: limit retries of a new policy ID while a cached policy is used (599b988), closes #170
  • received: do not guess the client IP when the HELO adds ";" or Exim comments (49b9a45)
  • received: take the client IP only from an unambiguous from clause (be23ede)
  • spf: accept 0 for maxVoidCount and maxResolveCount (e1826d7), closes #158
  • spf: accept a MAIL FROM or HELO domain with a single trailing dot (11256ae)
  • spf: check the expanded explanation string for US-ASCII (b4e844e), closes #155
  • spf: do not count the %{p} PTR query as a void lookup (46f3298), closes #154
  • spf: report the reason of macro syntax errors in the permerror comment (d3fe2bf), closes #157
  • spf: split macro values on exactly the delimiters that are listed (98c32c0)
  • types: mark DMARCResult policy fields optional and cite RFC 9989 9.1 (10dd7fe), closes #144

Don't miss a new mailauth release

NewReleases is sending notifications on new releases.