<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[hMailServer 6.2.22-pre6: pre4 was withdrawn, a fresh install listened on nothing]]></title><description><![CDATA[<p dir="auto">This was the last pre-release in the 6.2.22 line. Everything in it shipped in 6.2.24. Nothing here should be installed today.</p>
<p dir="auto">pre4 was withdrawn. Its installer could not create its own database: two SQL statements were written on consecutive lines, the script parser splits commands on a blank line, and SQL Server Compact, which a default install uses, rejected the pair as one command. The install succeeded, the service started, and it listened on nothing. Anyone who ran a fresh pre4 install was affected. The <code>v6.2.22-pre4</code> tag still exists but has no release. Do not build from it.</p>
<p dir="auto"><strong>What the upgrade involved</strong></p>
<p dir="auto">This is pre-alpha. Nobody has run it on a production server, and the installer is smoke-tested on a throwaway CI runner only. Use a spare box. Upgrading from pre3 requires DBUpdater: the schema moves from 6019 to 6022 in three steps.</p>
<p dir="auto"><strong>DMARC, brought up to DMARCbis</strong></p>
<ul>
<li>The DNS tree walk (RFC 9989 §4.10) replaces the Public Suffix List for deciding organizational domain. Bounded at eight queries per domain, cached five minutes. <code>DmarcTreeWalkEnabled=0</code> keeps the list, which is also used whenever a lookup fails transiently.</li>
<li>The <code>np=</code> tag (RFC 9989 §5.5.4) is honoured, so the resolver now reports the RCODE to tell NXDOMAIN from NODATA.</li>
<li>Aggregate reports now emit the DKIM <code>&lt;selector&gt;</code> and SPF <code>&lt;scope&gt;</code> from RFC 7489, never sent before.</li>
</ul>
<p dir="auto"><strong>Algorithms</strong></p>
<ul>
<li>DKIM rsa-sha1 is refused (RFC 8301), on signing and verification. A domain configured to sign with it is signed rsa-sha256 instead and told so. <code>DkimAcceptSha1=1</code> restores both halves.</li>
<li>DKIM keys below 1024 bits are refused (RFC 8301 §3.2).</li>
<li>SPF void lookups are capped at two (RFC 7208 §4.6.4). <code>SpfVoidLookupLimit</code> to change or disable.</li>
</ul>
<p dir="auto"><strong>Certificates and delivery</strong></p>
<ul>
<li>ACME renewal begins two thirds through the certificate's lifetime with a one-day floor, instead of a fixed 30 days. ARI (RFC 9773) is consulted hourly and the CA's window wins when offered, clamped to a day before expiry.</li>
<li>A full mailbox is refused at RCPT with 452 4.2.2, ending the backscatter to forged envelope senders. <code>RejectFullMailboxAtRcpt=0</code> restores the old behaviour.</li>
<li><code>QuotaWarningPercent</code> (default 90, 0 disables) sends one notice per crossing. Schema 6022.</li>
</ul>
<p dir="auto"><strong>Operations</strong></p>
<ul>
<li>Per-domain outbound relay, discussion #31. Order is route, then the sending domain's relay, then the server-wide relayer. Schema 6021.</li>
<li>Queryable message trace, off by default. Schema 6020.</li>
<li><code>ArchiveRetentionDays</code> prunes ArchiveDir, 0 by default, <code>.eml</code> files only.</li>
</ul>
<p dir="auto">The DMARCbis aggregate-report namespace (RFC 9990) is not implemented. Reports remain the RFC 7489 form.</p>
<p dir="auto"><a href="https://www.progressiverobot.com/hmailserver-downloads/" rel="nofollow ugc">Full release notes, checksums and signatures</a></p>
]]></description><link>https://www.hmailserver.co.uk/topic/28182/hmailserver-6.2.22-pre6-pre4-was-withdrawn-a-fresh-install-listened-on-nothing</link><generator>RSS for Node</generator><lastBuildDate>Wed, 23 Sep 2026 03:27:15 GMT</lastBuildDate><atom:link href="https://www.hmailserver.co.uk/topic/28182.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 20 Aug 2026 23:03:32 GMT</pubDate><ttl>60</ttl></channel></rss>