SmarterMail Release Notes

Build 9693 (Jul 16, 2026)

  • Fixed: A spam bypass issue related to certain email headers.
  • Fixed: Rspamd doesn't have a "Score Only" option similar to other antispam settings.
  • Fixed: Wildcard flag isn't always triggered in Content Filters or Routing Rules.

Build 9686 (Jul 9, 2026)

  • Changed: Windows installer now supports custom username/password for service installation and logon.
  • Fixed: [HA] [HUB] ACME Certs can fail renewal under certain conditions.
  • Fixed: [HA] [HUB] Denial of Service IDS rules are getting double incremented.
  • Fixed: [HA] Hub setup has errors when a new hub joins.
  • Fixed: [HA] Suspending the leader hub can cause nodes to go inactive.
  • Fixed: Bulk attaching domains does not validate the domain names correctly.
  • Fixed: Calendar webcal subscriptions incorrectly parse event end times.
  • Fixed: In some cases, outgoing emails stay in the Drafts folder after sending from webmail.
  • Fixed: Linux path validation for domain primary path does not work as expected for new domains.
  • Fixed: Occasionally emails that contain certain unicode characters in the Subject fail to sync (EWS).
  • Fixed: Outlook (IMAP) does not sync emails to webmail when a folder has special characters in the name.
  • Fixed: Server can hang at startup under certain conditions.

Build 9678 (Jul 1, 2026)

  • Added: [API] Marketplace -> ClearChatProviderSettings.
  • Added: Account Created date and time column for Accounts.
  • Changed: Added HAM reporting when moving an email out of Junk E-mail to any other email folder.
  • Fixed: [HA] "IDS Brute Force" whitelist setting is incorrectly applied.
  • Fixed: [HA] [HUB] Adding a new Standby triggers the Save button incorrectly.
  • Fixed: [HA] Service Unavailable page has a white border.
  • Fixed: #contactpicture# variable display is broken in webmail Compose/Reply window.
  • Fixed: 2FA verification code is inconsistent between various login pages.
  • Fixed: Can't delete other User's appointments in a Shared Calendar even with Owner privileges.
  • Fixed: Domain Defaults is missing validation/error when Collabora/Only Office are enabled but not configured.
  • Fixed: Export ICS does not work in the context menu (right click) in webmail.
  • Fixed: Folder auto-clean gives an error for system administrators.
  • Fixed: German translation for Max Message size still includes obsolete '(0 = Unlimited)'.
  • Fixed: Messages with '@media' in the HTML can render improperly in webmail.
  • Fixed: Non-ASCII unicode characters do not always display properly in Outlook (MAPI) calendars.
  • Fixed: Sender display name is missing in Outlook (MAPI) when the display name includes angle brackets.
  • Fixed: Sending to an alias that includes other aliases causes a 'domain does not match alias domain' error.
  • Fixed: SmarterMail Chat audio and video call features do not work.
  • Fixed: There isn't a way to clear rocket.chat settings from the Marketplace.

Build 9673 (Jun 26, 2026)

Key Features
  • Enhanced intrusion detection and prevention tools to help administrators prevent attacks that can affect users.
  • SpamFoo Antispam - A fully-integrated AI-driven antispam add-on that interprets intent and context of messages versus relying on keywords and pattern matching. Available for free during the BETA. (Disabled by default.)
  • SpamFoo Email Classification - Intelligent, AI-driven classification for messages in a User's Inbox, similar to Gmail's "labels". (Disabled by default.)
Release Notes
  • IMPORTANT: Due to significant changes in SmarterMail, you may not be able to downgrade to previous versions without restoring a previous settings.json file. This can be done by restoring a backup from the Archived Data folder within SmarterMail.
  • Added: [API] Domain Settings -> AddUsersBypass.
  • Added: [API] Domain Settings -> GetMessageArchiveMessageCollectionAllGet.
  • Added: [API] Domain Settings -> GetMessageArchiveMessageCollectionGet.
  • Added: [API] File Storage -> DownloadCloudFilesGet.
  • Added: [API] File Storage -> DownloadUserFilesGet.
  • Added: [API] System Admin -> ExportRawSpoolMessagesGet.
  • Added: A Classified column to the User Statuses grid that shows whether a user's Inbox has completed Email Classification.
  • Added: A delay to the spool start up when the SmarterMail service starts.
  • Added: A log that captures when an SSL cert fails during mailbox migration.
  • Added: A system administrator Authentication report that shows attempts, successes, and failures.
  • Added: An IDS Delay report.
  • Added: Copy buttons for app passwords.
  • Added: Domain Default setting to manage the ability for guests to upload files during an Online Meeting.
  • Added: Free Edition text to the SmarterMail Licensing card.
  • Added: IDS default rules.
  • Added: Implemented mTLS for joining a hub or node to an HA cluster.
  • Added: New Delay action and success scoring for some IDS rules.
  • Added: New report for connections prevented by an active IDS block.
  • Added: Support for granting delegates permission to view private items on Calendar and Task folders (MAPI/EWS).
  • Changed: The Options card now shows first in Antispam settings.
  • Changed: The styling of the trusted sender/domain and blocked sender/domain modals.
  • Changed: Update Cyren and CyrenIP to version 5.9.2.
  • Changed: Updated What's New modals for users.
  • Removed: Manage Shares from the email folder Actions menu.
  • Removed: Webhooks as Event Actions for users and domain administrators.
  • Fixed: [HA] [HUB] IDS Blocks page shows the incorrect rule name for the triggering rule.
  • Fixed: [HA] [HUB] IDS rules context menu differs from Enterprise versions.
  • Fixed: [HA] [HUB] Licensing page cards are missing max width settings.
  • Fixed: [HA] [HUB] The SmarterMail license buttons are in the wrong area.
  • Fixed: [HA] [HUB] Unable to 'Restore Idle Node' on idle node in a cluster.
  • Fixed: [HA] Failover issue with 2 active node configurations if ACTIVATE response timed out.
  • Fixed: [HA] SmarterMail greylists the same sending IPs repeatedly.
  • Fixed: A timestamp display discrepancy in Thunderbird for 'Schedule Send' messages.
  • Fixed: An error can occur when loading a user that has rocket.chat settings configured.
  • Fixed: An issue that prevents the What's New modal from showing up for a new user in a new domain.
  • Fixed: An issue with log formatting when reporting SMTP send failures.
  • Fixed: Calendar Events are unable to create Online Meetings when the Subject field is empty.
  • Fixed: Calendar images can be lost after adding text to an event with edits between Outlook (MAPI) and Webmail.
  • Fixed: Calendar refreshes to current date when adding future event.
  • Fixed: Can't add a meeting password to an existing Online Meeting.
  • Fixed: Cancelling an occurrence of a recurring meeting sends a cancellation message that lists the attendees twice.
  • Fixed: Clickable links in plaintext emails do not work.
  • Fixed: Clicking on email attachments downloads them twice.
  • Fixed: Common passwords policy is not enforced when changing to a common password.
  • Fixed: Contacts section can take awhile to load the GAL.
  • Fixed: Creating auto-clean rules for sub-folders doesn't save.
  • Fixed: Creating new system administrators bypasses password requirement checks.
  • Fixed: Detaching a domain can sometimes prevent it from moving due to properties.pid file being accessed.
  • Fixed: DMARC may be skipped for null senders with no RETURN-PATH.
  • Fixed: Dragging images into SmarterMail Chat editor causes the UI to get 'stuck'.
  • Fixed: Duplicate ACME orders created due to broken cross-domain deduplication.
  • Fixed: Error trying to active eM Client license.
  • Fixed: From Address content filter does not always trigger.
  • Fixed: German locale Outlook (MAPI) crashes intermittently.
  • Fixed: German translation for Max Attached File Size still includes text for legacy "(0 = Unlimited)".
  • Fixed: IDS Rules sorting by Block/Delay Time doesn't take units into account. (I.e., minutes vs. milliseconds)
  • Fixed: Images pasted in chat are stretch to fit the 1:1 aspect ratio of the preview pane.
  • Fixed: Importing Users over the domain's user limit does not give a toast error.
  • Fixed: Javascript errors can occur when navigating to Routing Rules.
  • Fixed: Large downloads silently fail in webmail.
  • Fixed: Load time regression on Contacts page with large, image-heavy lists.
  • Fixed: Logging in as a system administrator, and clicking on the Settings tab, sometimes displays a blank page.
  • Fixed: Message Archive "copy all" or "copy to" can display email folders incorrectly.
  • Fixed: Navigating to the Contacts page when there's no contacts can make the page shift around.
  • Fixed: Online Meeting Video / WebRTC card always shows on Domain Defaults, but is hidden from Domain Settings.
  • Fixed: Online Meetings tied to Domain calendars can sometimes disappear.
  • Fixed: Password Brute Force by IP and Password Brute Force by Email rules aren't incrementing for users with 2FA enabled.
  • Fixed: Password retrieval error for too many requests doesn't get re-evaluated if you cancel and click "Forgot your password?" again.
  • Fixed: Report fields are misaligned in certain browsers.
  • Fixed: Rocket.Chat Test button doesn't work in Marketplace.
  • Fixed: RTF Teams formatted calendar invites show blank in webmail.
  • Fixed: Sending an email over EWS from an authorized alias to an external recipient relays the message using the wrong MAIL FROM address.
  • Fixed: Signature images don't always load when sending an email.
  • Fixed: SmarterMail Chat notifications disappear for group chats and unread counts don't update properly.
  • Fixed: SmarterMail Chat users sometimes show as offline.
  • Fixed: SmarterMail incorrectly applies strict alignment constraints to matching subdomain From headers.
  • Fixed: Sorting IDS Rules by Action is inconsistent between HA and Enterprise versions.
  • Fixed: Sorting IDS Rules by Type is inconsistent between HA and Enterprise versions.
  • Fixed: Updated messaging when using Detach Domain for a domain with conflicting domain aliases.
  • Fixed: User CSV importing issue on Windows.
  • Fixed: Webmail presence not being updated on users that log on as offline then change their status.
  • Fixed: When configuring Windows Defender exclusions show a toast notification.
  • Security: Possible XSS stored in meeting workspace chat.
  • Security: Resolved issues relating to authenticated users.
  • Translations: Added Hungarian language.

Build 9652 (Jun 5, 2026)

  • Added: [API] Chat -> GetChatHistoryTranscriptByIdOnly.
  • Changed: [API] Settings -> UserGetAppPasswords.
  • Changed: [API] User Settings -> UserRecoverTwoFactor.
  • Changed: [API] User Settings -> UserSetTwoFactorRecovery.
  • Changed: [API] UserSettings -> AdminSetTwoFactorRecovery.
  • Changed: [API] UserSettings -> UserGenerateTwoFactor.
  • Fixed: A race condition in domain user creation can sometimes allow bypassing user account limits.
  • Fixed: An issue where some attachments are missing "Save link as" option in the context menu.
  • Fixed: CC'd recipients are cut off when printing an email.
  • Fixed: Configuring a secondary path isn't moving all files.
  • Fixed: Deleting a single calendar instance with an all day event fails.
  • Fixed: It's not possible to impersonate more than one user.
  • Fixed: Rooms can trigger NDRs when receiving Out of Office messages.
  • Fixed: Rspamd is not being calculated for "Outbound SMTP" spam checks.
  • Fixed: Syncing issues occur when an email response contains a Control character (EAS).
  • Fixed: The #SendingEmail# signature variable isn't changing when sending from a domain alias.
  • Fixed: When using 2FA, the "Trouble with code" link on the webmail login page returns an error when clicked.
  • Security: Finalized encryption changes and upgrade logic.
  • Security: Removed obsolete SignalR functions.
  • Security: Resolved issues related to calendars and chat that could allow Server-Side Request Forgery (SSRF).
  • Security: Resolved issues relating to authenticated users.

Build 9623 (May 7, 2026)

  • Added: A configurable Maximum Booking Window on domain resources.
  • Added: A debug log Archive data processing (file movement).
  • Added: A Delete button to Content Filters and Routing Rules.
  • Changed: Calendar source folders are now always displayed when creating a new calendar item.
  • Changed: Deleting a calendar appointment from the calendar no longer sends a reply to the sender.
  • Changed: TCP Proxy setting on whitelist entries now apply to HTTP requests.
  • Changed: The cursor now focuses on the Code line when using 2FA and logging in to webmail.
  • Fixed: "Bypass spam filtering for unverified senders" is being skipped if the sender is in the 'Trusted Senders' list.
  • Fixed: [HA] An XMPP authentication issue when a client doesn't use the full email as the username.
  • Fixed: [HA] Cyren is using the wrong method for getting a sender's IP.
  • Fixed: [HA] Moving a domain to a new node breaks cached contact image URLs.
  • Fixed: [HA] Selecting Impersonate User when managing a node causes you to return to the login page.
  • Fixed: A folder synchronization issue with the Nine email client. (EAS)
  • Fixed: A user Event is still there even after deleting and recreating the user.
  • Fixed: A webmail Attachment/Image Preview issue.
  • Fixed: An issue where adding a new calendar item refreshes webmail.
  • Fixed: An issue where the Outbound SMTP Spam Block threshold is being ignored.
  • Fixed: Conditions and Actions are not able to be set for Events, Content Filters, and Routing Rules until the Option is created and saved.
  • Fixed: Copy To Mailbox action in a domain's Message Archive Search is not working when done by a system administrator.
  • Fixed: DMARC Subdomain Policy tag is not being honored.
  • Fixed: Email avatar images are loading in before the email data shows.
  • Fixed: GRP files are being duplicated when using a Secondary Path.
  • Fixed: Images are not displayed in the Print Preview window when attempting to print a message in webmail.
  • Fixed: Images pasted in a chat don't show a preview nor do they load when clicked.
  • Fixed: Importing 50k tasks from ICS files is failing.
  • Fixed: Importing Calendar, Contacts, Tasks, and Notes allows you to add more files while the import is running.
  • Fixed: Importing Calendars, Contacts, Tasks, and Notes allows folder changes while the import is running.
  • Fixed: Large domains freeze webmail after logging in as a user when Chat is enabled.
  • Fixed: Outlook Classic on Mac sends email immediately instead of scheduled send (EWS).
  • Fixed: Routing Rules are not triggering all Actions.
  • Fixed: Selecting a chat does not immediately bring up the chat history until selecting a different user chat.
  • Fixed: Sending from an authenticated SMTP session to an alias that has an external email address can show the wrong email address in the delivery logs with "Delivery for".
  • Fixed: Shared Contacts is not using the correct translation key.
  • Fixed: The sender's display name sometimes shows the full email address then removes it.
  • Fixed: Unread Chat notifications disappear after refreshing the webmail.
  • Fixed: When an HTTP request is received from a trusted proxy, the earliest entries in the X-Forwarded-* headers are automatically trusted.
  • Fixed: When joining an Online Meeting that's created for authenticated users, the meeting window needs to be manually refreshed after a user joins.
  • Fixed: When using an alternate From address in webmail, read receipts are sent back to the webmail inbox address and not the alternate address.
  • Fixed: Zoom integration is not connecting calendars (EWS).

Build 9610 (Apr 24, 2026)

  • Added: [API] Calendars -> CalendarStartImport.
  • Added: [API] Contacts -> ContactsStartImport.
  • Added: [API] Notes -> NotesStartImport.
  • Added: [API] System Admin -> GetDeletingDomains.
  • Added: [API] System Admin -> GetDomainAliases.
  • Added: [API] System Admin -> GetDomainAliases.
  • Added: [API] System Admin -> ListInternationalizedDomainNames.
  • Added: [API] System Admin -> ListInternationalizedDomainNames.
  • Added: Authenticated SMTP sessions to the user's Connectivity page matching other protocols.
  • Added: Better handling when popups are blocked when impersonating.
  • Added: The ability to choose between RSA and ECDSA for ACME certificates.
  • Added: The ability to select a 90 minute meeting time option in Scheduled Meetings.
  • Changed: "Remember Me" tokens are now invalidated when enabling 2FA or a user resets their password.
  • Changed: 2FA now uses JWT tokens.
  • Changed: DKIM Header Fields to sign now filter out fields for "X-MS-*".
  • Changed: Improve ACME certificate generation logic.
  • Changed: Improved the flow for forcing a password reset.
  • Changed: Now account for Let's Encrypt certificates having a shorter expiration date.
  • Changed: Removed the success toast notification from all grid "refresh" buttons.
  • Changed: Updated EULA text.
  • Changed: Updated Maxmind database.
  • Changed: Updated to ClamAV 1.5.2 for Windows.
  • Fixed: "What's New" modal shows a scrollbar when it's not needed.
  • Fixed: [HA] [HUB] Fresh Hub installs do not create the hub-settings.json file as needed.
  • Fixed: [HA] [HUB] Log lines can show up out of order.
  • Fixed: [HA] [HUB] Logs return inconsistent results for searches.
  • Fixed: [HA] [HUB] When viewing combined hub logs, the truncated view shows the earliest lines instead of the most recent.
  • Fixed: [HA] AUTH PLAIN not working for IMAP sessions.
  • Fixed: [HA] Deleting and recreating large domains results in combination of error toasts.
  • Fixed: [HA] Deleting large domains (100,000+ users) times out resulting in garbled red toast error.
  • Fixed: [HA] Hub Protocol Proxy session logging lists multiple session ID's per log line during on-going concurrent sessions.
  • Fixed: [HA] Importing large number of users via CSV results in red toast error.
  • Fixed: [HA] Incorrect caching on a Backup MX causes deliverability issues.
  • Fixed: [HA] It's possible to impersonate a broken domain and user from the hub.
  • Fixed: [HA] MD5 auth methods not respecting app passwords for IMAP, SMTP, XMPP in HA environments.
  • Fixed: [HA] Plain text authentication methods for all protocols failing for app passwords.
  • Fixed: [HA] Routing Rule "Enable wildcards" option toggles off upon initial save and for subsequent saves as well.
  • Fixed: [HA] SmarterMail initiating SSL certificate requests for non-FQDN hostnames.
  • Fixed: [HA] SMTP Proxy logs aren't providing sufficient data, even when set to trace.
  • Fixed: [HA] Unable to enable 'Force all traffic over HTTPS'.
  • Fixed: A connected internet calendar can be set as a default calendar.
  • Fixed: An issue adding/editing External Senders when using "Add Text to Subject" and "Known External Domains" option.
  • Fixed: Attaching a base domain path and going back will not allow you to go forward again.
  • Fixed: AUTH call still appears if no associated authentication methods are enabled.
  • Fixed: Calendars and Task upload is clickable before any file is selected.
  • Fixed: Cannot disable ChatGPT in Marketplace.
  • Fixed: Cannot save an outbound gateway in a disabled state.
  • Fixed: Changing a username over the Windows character limit presents an untranslated toast notification.
  • Fixed: Chromium-based browsers show the wrong pointer on filter rules.
  • Fixed: Contact import hangs when importing a malformed CSV.
  • Fixed: Content Filters do not show the correct number of conditions or actions when deleted.
  • Fixed: Content Filters/Routing Rules fail to save 'include system messages..." toggle on initial save operation.
  • Fixed: Conversion issues when migrating to Linux.
  • Fixed: Conversion page will set secondary storage url to the domain archive url if archive folder already exists.
  • Fixed: Creating a Routing Rule for Inbound, then saving, reverts the Rule to Inbound + Outbound.
  • Fixed: Delegate settings aren't properly syncing between MAPI and EWS clients.
  • Fixed: Deleting an instance of a recurring all-day calendar event is failing for users in UTC+01:00 time zones.
  • Fixed: Document servers (OnlyOffice or Collabora) still show as available even if the server address is incorrect.
  • Fixed: Domain Defaults are not respecting the gateway setting.
  • Fixed: Exceptions can occur when trying to bind TCP listeners to ports on IPv6.
  • Fixed: Expire Password shows when an AD/LDAP authenticated user is selected in the Users tab.
  • Fixed: Extraneous SignalR errors in the browser console.
  • Fixed: IMAP connections stick around even after IMAP is disabled server side.
  • Fixed: Importing a large number of Contacts causes webmail to stall.
  • Fixed: Initial chat message from webmail to eM Client (XMPP) is not being received.
  • Fixed: Issue with GetUser API endpoint not returning "lastLoginTime".
  • Fixed: Issues with previewing and downloading attachments in messages that use winmail.dat.
  • Fixed: Light Mode/Dark Mode menu option has extraneous spacing.
  • Fixed: MAPI delegation permissions do not sync correctly.
  • Fixed: Message Archive attachments show "Access Denied".
  • Fixed: Moving/renaming a folder can break related Auto Cean rules and Content Filters.
  • Fixed: Not all Delivered and Forwarded messages are triggering for Routing Rules.
  • Fixed: Notes failing to load or can show a spinner.
  • Fixed: Online Meetings duplicate links in chat.
  • Fixed: Rare issue where a server locks up at night when running cleanup tasks.
  • Fixed: Routing Rules condition doesn't display correctly in some scenarios.
  • Fixed: S/MIME encrypted e-mail is not being passed to Outlook correctly.
  • Fixed: Schedule meeting link no longer works after a user rename.
  • Fixed: Schedule send date discrepancy can occur between typed and icon selected dates.
  • Fixed: Searching SMTP Logs for an IP with "Display related traffic" selected returns no results.
  • Fixed: Sent messages are not being delivered if messages are moved out of Sent Items before send notification completes.
  • Fixed: The image zoom selector does not work well with Chrome and Firefox.
  • Fixed: The WebDAV incorrectly processing some requests on any path, except when using the API.
  • Fixed: There's no validation when entering an email address on a Scheduling page.
  • Fixed: Tool Tip for conditions (in Content Filters, Events, etc.) is displaying javascript.
  • Fixed: User Status page is missing columns when exported.
  • Fixed: Validation is choppy when typing a recovery address during the Getting Started process.
  • Security: Possible link traversal issue when using Plus Addressing.
  • Security: Updated installers to use .NET 10.0.7.
  • Security: Upgraded and strengthened encryption across multiple areas, reducing potential for brute force attempts.
  • Translations: Added Russian language support.

Build 9581 (Mar 26, 2026)

Key Features
  • Due to significant changes in SmarterMail's encryption, you may not be able to downgrade to previous versions.
Release Notes
  • Fixed: An issue with attaching a domain if the administrator is accidentally logged out while typing the domain path.
  • Fixed: Disabled Folders list for attaching domains is hard to read in dark mode.
  • Fixed: It's not possible to disable a gateway.
  • Fixed: Message Archiving searches can result in high CPU usage.
  • Fixed: Messages sent from New Outlook to Microsoft inboxes fails DKIM.
  • Fixed: Styling issues in the Attach Domain dialog.
  • Fixed: WHMCS integration is unable to manage users.
  • Security: App Passwords are now stored with AES.
  • Security: Changed obfuscated encryption keys.

Build 9575 (Mar 20, 2026)

  • Added: [API] System Admin -> AttachDomainBatch.
  • Added: [API] System Admin -> ValidateAttachPath.
  • Added: An Attach Domains action that allows administrators to Attach All domains from a common parent path.
  • Changed: API documentation now includes IP restriction and blacklist updates.
  • Changed: Domain Resource text now uses "disallow" and "allow" instead of "none" and "manage" when assigning users.
  • Changed: Enable Domain is now greyed out as an Action if a domain is already enabled.
  • Changed: Expanded the window for Domain Signatures making it easier to see your full signature for review.
  • Changed: Updated some buttons across the interface for consistency.
  • Fixed: [HA] Administrators are unable to set a node hostname causing PTR mismatches on outbound SMTP.
  • Fixed: [HA] There's a display issue when selecting a blank Trusted Sender with another Trusted Sender entry in use.
  • Fixed: [HA] Using the scroll wheel to change weight in Settings, then saving and undoing multiple times, will cause an auto save.
  • Fixed: Adding an image to a Contact doesn't always display correctly in the Contacts list.
  • Fixed: An issue affecting the ability to delete appointments from a shared calendar (WebDAV).
  • Fixed: An issue setting a profile image in eM Client's chat area.
  • Fixed: An issue where a Condition set for a Content Filter can change after saving.
  • Fixed: An issue where an ACME certificate that is manually renewed fails to be added if the same cert existed at one time but was not properly deleted.
  • Fixed: An issue where backgrounds and logo images fail to display on the login page.
  • Fixed: An issue with Plesk incorrectly calling a specific SmarterMail API.
  • Fixed: Background User creation does not show a progress, so administrators are unable to track success.
  • Fixed: Blacklisting a Class C from IDS blocks does not blacklist .0.
  • Fixed: Calendar Auto-Clean can fail to remove older calendar entries.
  • Fixed: Content filter ordering is not saving nor is it being respected.
  • Fixed: Domain footers that include images are not working properly.
  • Fixed: eM Client generated Teams meeting invites are not sent (EWS)
  • Fixed: EWS logs are not being properly sanitized.
  • Fixed: Online Meeting logins can fail due to failed authentication "Refresh token not valid".
  • Fixed: Removing attachments in webmail does not actually remove them.
  • Fixed: Resetting a system administrator's password, using the steps in our KB article, can fail on a second try.
  • Fixed: Scheduled Emails show in the sent items folder with the compose time and not the sent time.
  • Fixed: Sessions from a whitelisted IP that bypasses SMTP authentication, that then authenticates with AUTH PLAIN, are incorrectly spam checked.
  • Fixed: SmarterMail inverts emojis when in Dark mode.
  • Fixed: System administrators with the username "new" act like the new system administrator button.
  • Fixed: The error that's displayed to blacklisted IP users when attempting to log in to webmail is incorrect.
  • Fixed: The Settings fields for IP Rotation can be set with incorrect values.
  • Fixed: Typos in the Docker README.md.
  • Fixed: Using CIDR block for system administrator IP restriction can generate errors/exception in Administrative logging.
  • Security: Hardened a few API calls.
  • Security: Hardened attachment tokens and 2FA endpoints.
  • Security: Hardened authenticated and non-authenticated SMTP sessions to avoid spoofing.
  • Security: Hardened RSS feeds and feed sanitation.
  • Security: Implemented TokenValidationService to consolidate rules-based token authentication.
  • Security: Improved memory and size efficiency to reduce potential for DoS attacks.
  • Security: Improved SMTP authentication to avoid spoofing.
  • Security: Modified IP Restrictions to avoid possible credential leaks.
  • Translations: Added a Catalan translation file.

Build 9560 (Mar 5, 2026)

  • Changed: Added error handling with eM Client XMPP server connections.
  • Changed: Added the ability to specify the port number to mach the other gateways for domain forwards.
  • Changed: Copyright text now conforms to other projects.
  • Changed: Gateway settings were refactored and modified for ease of use, understanding, and configuration.
  • Changed: Updated Froala to version 5.0.0.
  • Fixed: "From address must match authenticated address" when sender IP in auth bypass.
  • Fixed: [API] Integration APIs for eM Client not working when the account has 2FA enabled.
  • Fixed: [HA] [HUB] An incorrect message is displayed when removing the weight value in RBLs and URIBLs.
  • Fixed: [HA] [HUB] ClusterAdmin Logout of hub improvements to revoke refresh token.
  • Fixed: [HA] [HUB] Spam checks do not display correctly the first time saved and re-opened.
  • Fixed: [HA] Added action to force a node to failover immediately through the Hub.
  • Fixed: [HA] Adding a hub by hostname (instead of IP address) results in targetHub using 127.0.0.1 as its IP.
  • Fixed: [HA] Antispam Greylist Filters shows a blank entry when entering a letter in an IP address.
  • Fixed: [HA] Antispam Spam Checks do not save when values are too large or small.
  • Fixed: [HA] Antispam Spam Checks do not validate the weight with blank rule name.
  • Fixed: [HA] Detaching large domains (50,000+ users) from nodes results in a malformed timeout error toast.
  • Fixed: [HA] Network isolation of a hub could result in having more than one leader.
  • Fixed: [HA] Password resets fail to present password reset form.
  • Fixed: [HA] Suspend and Restore for hubs doesn't always work correctly.
  • Fixed: [HA] Toast notifications display "Action Succeeded" instead of "Success".
  • Fixed: A small memory leak when encrypting/decrypting strings.
  • Fixed: Adding a calendar resource to an appointment doesn't call the appropriate JS method.
  • Fixed: Admin accounts without impersonation rights are logged out when trying to create a new user or alias.
  • Fixed: An issue when converting from Windows to Linux.
  • Fixed: Dismissing a reminder for an appointment in Mac Calendar [EWS] clears the response data for all attendees.
  • Fixed: Entering a space to a new password results in broken error/validation message.
  • Fixed: Force Password Reset errors could hint at a user's existence on a server.
  • Fixed: Message ID is not added for authenticated messages that have no local deliveries.
  • Fixed: Modifying an existing system event action can duplicate it.
  • Fixed: Online Meeting ending time can be off in different time zones.
  • Fixed: Online Meetings between different networks does not always show video or audio.
  • Fixed: OnlyOffice WOPI access tokens occasionally rejected with 401 after an upgrade to Build 9546.
  • Fixed: Outlook on Mac [EWS] is not showing user availability.
  • Fixed: Sent message icon does not go away when an email is moved from Sent Items.
  • Fixed: SmarterMail occasionally attempts to access files on a detached domain.
  • Fixed: Some recipients are listed with the display address of an alias recipient in Outlook [MAPI].
  • Fixed: Turn servers are not functioning in rare circumstances.
  • Fixed: When adding comma-separated values to the IP blacklist from the interface can sometimes duplicate entries.
  • Fixed: When renaming a domain, the service needs to be restarted before the new name is displayed.
  • Fixed: When responding to a message sent from SmarterMail using MAPI, Outlook Mac [EWS] adds “On Behalf Of” in the generated header of the original email.
  • Fixed: When trying to accept a new proposed meeting time, the server can sometimes return a 500 code.
  • Fixed: XMPP over SSL fails on port 5223.
  • Efficiency: [HA] HubConnection more gracefully detects when the connection is closed by the hub.
  • Efficiency: Thread usage during nightly cleanup tasks improved to limit resource usage.
  • Security: Fixed a few obscure authentication bypass, privilege escalation, denial of service, and path traversal issues we found during our security audit.

Build 9546 (Feb 19, 2026)

  • Fixed: An issue with Outlook (IMAP) not properly syncing folders with names containing non-ASCII characters.
  • Fixed: An issue with the legacy SOAP API and obfuscation.

Build 9543 (Feb 16, 2026)

  • Fixed: IMAP clients sending large emails can trigger IDS blocks.
  • Fixed: Sending large emails via IMAP/SMTP clients results in an exception related to command length.

Build 9540 (Feb 13, 2026)

  • IMPORTANT: [SECURITY] Changed how the command-line is utilized across various areas.
  • Added: [HA] Trusted Senders are now synchronized across a split domain.
  • Added: SmarterMail codebase is now obfuscated.
  • Changed: [HA] [HUB] Improved handling of impersonate and manage node errors when pop-ups are blocked by a browser.
  • Fixed: [HA] [HUB] Impersonating from the accounts grid gives a 401 error.
  • Fixed: [HA] [HUB] When logging into a hub you will sometimes see a `Fetch Error` instead of the server health grid details.
  • Fixed: [HA] An issue where certificates can fail to renew for a cluster.
  • Fixed: [HA] An issue with TypeNameHandling.
  • Fixed: An EWS push notification issue.
  • Fixed: An issue where a user is logged out when opening the Reports area.
  • Fixed: An issue where authenticated users could have the server issue an HTTP request to an arbitrary URL.
  • Fixed: An upgrade from SmarterMail 15.x to latest fails to detect existing XML configuration files.
  • Fixed: Certain HTML messages Do not Render Correctly in Webmail.
  • Fixed: Checking 2FA code is not thread safe.
  • Fixed: External document servers (e.g., Collabora) fail to load files in email attachments but work for File Storage files.
  • Fixed: SmarterMail's EXAMINE implementation does not comply with RFCs (IMAP).
  • Fixed: SmarterMail's EXAMINE implementation for IMAP does not comply with RFCs.
  • Fixed: Successfully used 2fa tokens are not always cleared from memory correctly.
  • Fixed: Successfully used 2FA tokens are not always cleared from memory correctly.
  • Fixed: Users can get logged out of webmail intermittently.
  • Fixed: Using TAB to move cursor when composing new message in webmail is off.
  • Security: [HA] Fixed a potential JSON deserialization issue.
  • Security: Added access restrictions to a system with compromised RSA key.
  • Security: API access now follows the user whitelist/blacklist as well as System Administrator IP Restrictions for authentication.
  • Security: Hardened various protocols against complex memory exhaustion issues.
  • Security: Hardened various syncing protocols against complex entity expansion issues.

Build 9526 (Jan 30, 2026)

  • Changed: Revised restrictions for file and folder name validation.
  • Fixed: [API] Users may be able to be impersonated by system administrators who do not have impersonation permissions.
  • Fixed: [HA] Password Reset CAPTCHA now works as expected.
  • Fixed: [HA] Refresh token fails length validation.
  • Fixed: A system administrator's password cannot be reset if they have 2FA enabled.
  • Fixed: Administrative logs indicate a password was successfully reset even when the reset failed.
  • Fixed: Birthdate showing wrong date with UTC +01:00 in Outlook (EAS) on Android.
  • Fixed: Multipart/alternative e-mails not rendering HTML correctly.
  • Fixed: POP Timing Attack on APOP MD5 Hash Comparison.
  • Security: Fixed a BIMI SSRF vulnerability.
  • Security: Fixed a scenario where CAPTCHA might not expire within alloted time.
  • Security: Fixed an issue where EWS can be used to spoof email addresses despite AuthMatch being set to email address.
  • Security: Fixed some API endpoints that had improper security scope
  • Security: Hardened JWT tokens.
  • Security: Hardened password reset tokens.
  • Security: Hardened Simpleauthcontroller.
  • Security: Removed Command Line Action from Routing Rules.
  • Security: Resolved a cross site issue with MAPI requests.

Build 9518 (Jan 22, 2026)

  • IMPORTANT: Critical security fixes. It is strongly recommended that all users update to this release.
  • Changed: Online Meetings need to support Authenticated Users' timezone IDs.
  • Changed: Redesigned the Diagnostics area, making it an actual page for system administrators, and including additional information.
  • Fixed: [HA] Translation error when blacklisting an IDS block.
  • Fixed: Blocked Domains modal has title "Blocked Senders".
  • Fixed: Mailing Lists do not validate the throttling card when adjusting Outbound Throttling.
  • Fixed: Newly created users can generate 'password encrypted is null' errors.

Build 9511 (Jan 15, 2026)

  • IMPORTANT: Critical security fixes.
  • Changed: "Block files without an extension" on Extension Blacklist for Uploads now includes email attachments.
  • Changed: About/checkup page now restricted to authorized (local network) IPs.
  • Changed: Update the "Someone muted you." toast in Online Meetings.
  • Removed: [API] System Admin -> CreatePrimarySystemAdmin.
  • Removed: [API] ValidateRemoteInstances as an API endpoint.
  • Fixed: [HA] Error proxying secure TCP sessions to the nodes.
  • Fixed: [HA] Unable to export whitelists from the security tab.
  • Fixed: Clicking on a task from the Calendar view opens a new task window instead of the task details.
  • Fixed: Creating a scheduled meeting that schedules an Online Meeting shows the Online Meeting start date with the UTC offset.
  • Fixed: It's possible to delete File Storage root folder which breaks File Storage.
  • Fixed: MailService.dll is being flagged as a false positive with VirusTotal.
  • Fixed: The REST API isn't setting a catch-all value when retrieving domain details for gateways.
  • Fixed: When a domain administrator changes a user's password, the administrator's 2FA application passwords are reset instead of the user's.

Build 9504 (Jan 8, 2026)

  • Added: Feature to prevent file uploads with no file extensions.
  • Changed: Added additional default file extensions to the Extension Blacklist for Uploads setting.
  • Changed: Redesigned file uploads across SmarterMail.
  • Changed: Updated and improved API documentation.
  • Fixed: [HA] [HUB] QC cluster failover shows Standby Node twice when activating.
  • Fixed: [HA] [HUB] Routing Rules and Gateways pages don't point to the proper Help pages.
  • Fixed: [HA] [HUB] The 'Notification Interval' values in Hub Notifications configuration area should be plural.
  • Fixed: [HA] ClamAV error message does not display correctly.
  • Fixed: [HA] ClamAV Setting Timeout Seconds does not reach the maximum value before giving an error.
  • Fixed: [HA] Profile image will not appear in the GAL.
  • Fixed: Client-side rules in Outlook are not being applied on message arrival.
  • Fixed: Content filter stores encoded folder names instead of Unicode folder names.
  • Fixed: Disposable Addresses added to Inbox are showing "undefined" for the folder name.
  • Fixed: Disposable Addresses for Drafts, Sent Items, and Scheduled folders don't display any buttons.
  • Fixed: Enable VRFY/EXPN notification text has a misspelling.
  • Fixed: Exception thrown when generating bounce message for specific sender email.
  • Fixed: File Storage URL is not changed with the update of the URL setting under the General option.
  • Fixed: Forwarding or replying to an external message from Outlook (MAPI) doesn't include the sender's email in the header for original message header.
  • Fixed: Image previews do not display properly in webmail chat.
  • Fixed: Importing Spam Settings (spamConfig.json) does not restore all the previous settings.
  • Fixed: MAIL FROM command (SMTP) accepting non-compliant addresses in some cases.
  • Fixed: Message count displays incorrectly when using French language in webmail.
  • Fixed: No validation when exceeding user throttling messages or bandwidth.
  • Fixed: Routing Rules initial selection of "Enable wildcards" fails to save on first save.
  • Fixed: Signatures do not display None or Domain options despite using them.
  • Fixed: Throttling logic is using the wrong settings to determine throttle action.
  • Fixed: Translation Error in File Storage for All Files.
  • Fixed: Turkish character rendering in the Move dialog is broken.
  • Fixed: Webmail isn't setting the correct font when composing a new message.
There are no release notes that match your search criteria.