<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[hMailServer 6.2.23-alpha2: Thunderbird could not save a single Sent copy]]></title><description><![CDATA[<p dir="auto">This was an alpha. Everything in it shipped in 6.2.24. Nothing here should be installed today.</p>
<p dir="auto">Thunderbird 128 and later could not save a single Sent copy. Every message went out over SMTP and nothing was ever stored, with only a per-machine client setting as a workaround (#53). Two ways a sender could steer the anti-spam tests are also closed here.</p>
<p dir="auto"><strong>What the upgrade involved</strong></p>
<p dir="auto">This is an alpha because one of the fixes changes what a non-conforming client sees.</p>
<ul>
<li><strong>Relayed and fetched mail is now tested against a different address.</strong> The Received parser takes the last observed address before <code>by</code>, ignores values marked as HELO-supplied, and keeps a header whose host name is not a valid domain name. If you sit behind an incoming relay and have tuned scores around the old behaviour, expect verdicts to move.</li>
<li><strong><code>MAIL FROM</code> straight after a STARTTLS handshake with no fresh <code>EHLO</code> now gets <code>503 Bad sequence of commands</code></strong>, as RFC 3207 section 4.2 requires. If you have a home-grown submission script that skips the second EHLO, this is the release that tells you.</li>
</ul>
<p dir="auto"><strong>Changes</strong></p>
<ul>
<li>IMAP APPEND: once a client enables <code>UTF8=ACCEPT</code>, RFC 6855 lets it wrap the message as <code>UTF8 (~{n}</code> plus a closing <code>)</code>. The parser counted parentheses across the whole line and refused with <code>BAD APPEND Command requires at least 2 parameter</code> before reading a byte. The wrapper is now stripped ahead of the parser, including the non-synchronizing <code>~{n+}</code> form and later messages of a MULTIAPPEND.</li>
<li>Anti-spam bypass: the parser took the first bracketed value after <code>from</code>, which is the HELO literal the client chose, and skipped any header whose host name was not a valid domain (<code>my_pc</code>). DNSBL, SPF and the HELO-host test could be skipped entirely. Two <code>assert(0)</code> on sender-reachable input are gone with it.</li>
<li><code>RSET</code> before <code>EHLO</code> no longer opens a transaction on its own. That had let <code>MAIL FROM</code> through with an empty HELO host, skipping the OnHELO/OnEHLO events.</li>
<li>A PTR answer carrying the trailing dot (<code>1.0.0.127.in-addr.arpa.</code>) no longer empties the result. That had been failing open in the HELO and reverse-DNS spam tests.</li>
<li><code>hMailServer.exe</code> is built with <code>/guard:cf</code> in both configurations (#45).</li>
<li>An unattended install whose database step fails now fails, rather than showing a suppressible message box and exiting 0.</li>
</ul>
<p dir="auto">Known limitation: the weekly C++ CodeQL analysis has not run since late August. It targets a self-hosted runner that is no longer registered.</p>
<p dir="auto"><a href="https://www.progressiverobot.com/hmailserver-downloads/" rel="nofollow ugc">Full release notes, checksums and signatures</a></p>
]]></description><link>https://www.hmailserver.co.uk/topic/28172/hmailserver-6.2.23-alpha2-thunderbird-could-not-save-a-single-sent-copy</link><generator>RSS for Node</generator><lastBuildDate>Wed, 23 Sep 2026 03:27:33 GMT</lastBuildDate><atom:link href="https://www.hmailserver.co.uk/topic/28172.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 04 Sep 2026 17:45:14 GMT</pubDate><ttl>60</ttl></channel></rss>