<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[hMailServer 6.2.22-pre2: DMARC aggregate reports (rua) are now sent, not just consumed]]></title><description><![CDATA[<p dir="auto">This was the second pre-release in the 6.2.22 line. Everything in it shipped in 6.2.24. Nothing here should be installed today.</p>
<p dir="auto">hMailServer has consumed DMARC policy for years and produced nothing for the domains whose mail it receives. This pre-release adds DMARC aggregate reporting (rua, RFC 7489). Every evaluation is aggregated per UTC day and per policy domain, passes included, and the Appendix C XML is mailed to the addresses a domain asks for with <code>rua=</code>. It stays inert until DmarcRptFromAddress is set.</p>
<p dir="auto"><strong>What the upgrade involved</strong></p>
<p dir="auto">The database schema moves to 6015. Upgrading from pre1 requires DBUpdater. Known limitations: FETCH BINARY on a composite section returns an empty literal, so BINARY[], multipart and message/rfc822 sections come back empty (leaf parts are correct). DMARC report data lives in memory, so a restart before the daily send loses that day's statistics.</p>
<p dir="auto"><strong>Reporting</strong></p>
<ul>
<li>RFC 7489 §7.1 external-destination verification is enforced. A rua target outside the policy domain's own organizational domain is used only when <code>&lt;policy-domain&gt;._report._dmarc.&lt;target-domain&gt;</code> says it wants the reports.</li>
<li>Forensic (ruf) reports are deliberately not implemented.</li>
<li><code>Utilities.SendTlsRptReports(IncludeCurrentDay)</code> and its twin <code>SendDmarcReports</code> send what has been collected so far, not just days that are over. Both refuse, statistics preserved, when the From address is unset.</li>
</ul>
<p dir="auto"><strong>Authentication</strong></p>
<ul>
<li><code>AccountLockoutThreshold</code> counts failures by the name being guessed at, so a distributed attack that never crosses any single IP's auto-ban threshold is still caught. Off by default, enforced on every path including SCRAM. A locked name gets the ordinary invalid-credentials reply, and that refusal is kept out of the per-IP auto-ban.</li>
<li>POP3 AUTH-RESP-CODE (RFC 3206): credential failures carry <code>[AUTH]</code>, a failed inbox load carries <code>[SYS/TEMP]</code>. A transient database problem made scheduled clients nag for a password that was never wrong.</li>
</ul>
<p dir="auto"><strong>Anti-virus</strong></p>
<p dir="auto">A scan that could not run was delivered with one line in the error log, indistinguishable from a clean scan. <code>AVFailAction</code> 0 (the default) keeps today's behaviour. 1 holds the message, re-attempts it and returns it to the sender rather than delivering it unscanned.</p>
<p dir="auto"><strong>IMAP</strong></p>
<p dir="auto">BINARY (RFC 3516) decodes a part's Content-Transfer-Encoding server-side, and APPEND accepts the literal8 (<code>~{n}</code>) form. OBJECTID (RFC 8474): EMAILID follows a message through copies, MAILBOXID survives RENAME, THREADID is answered NIL.</p>
<p dir="auto"><strong>Fixes</strong></p>
<p dir="auto"><code>/Test</code> no longer terminates on an unhandled exception when the machine has no network or a third party's DNS breaks. An idle server stops in about half a second rather than up to two. Nine settings reachable only by editing the ini now have Control Panel fields.</p>
<p dir="auto"><a href="https://www.progressiverobot.com/hmailserver-downloads/" rel="nofollow ugc">Full release notes, checksums and signatures</a></p>
]]></description><link>https://www.hmailserver.co.uk/topic/28174/hmailserver-6.2.22-pre2-dmarc-aggregate-reports-rua-are-now-sent-not-just-consumed</link><generator>RSS for Node</generator><lastBuildDate>Wed, 23 Sep 2026 03:27:33 GMT</lastBuildDate><atom:link href="https://www.hmailserver.co.uk/topic/28174.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 18 Aug 2026 01:46:47 GMT</pubDate><ttl>60</ttl></channel></rss>