Skip to content

stalwart

v0.16.8 Feature

This release adds 2 notable features for engineering teams evaluating rollout.

Published 1mo Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

caldav carddav imap jmap mail pop3
+4 more
rust server smtp webdav

Affected surfaces

auth deps

Summary

AI summary

Updates https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md, OAuth, and MTA across a mixed release.

Changes in this release

Dependency Low

DNS updater upgraded to `dns-update-v0.5.1`.

DNS updater upgraded to `dns-update-v0.5.1`.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

MTA sub-addressing with external directories now returns `550 Mailbox not found`.

MTA sub-addressing with external directories now returns `550 Mailbox not found`.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Disabled aliases no longer receive messages in MTA.

Disabled aliases no longer receive messages in MTA.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

JMAP FileNode/get returns correct non‑stale state string.

JMAP FileNode/get returns correct non‑stale state string.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

Rate limiter no longer panics when periods under 1 second are used.

Rate limiter no longer panics when periods under 1 second are used.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Medium

CalDAV/CardDAV writes vanished tombstone for items deleted via JMAP.

CalDAV/CardDAV writes vanished tombstone for items deleted via JMAP.

Source: llm_adapter@2026-06-06

Confidence: high

Bugfix Low

Made `SieveSystemInterpreter.defaultReturnPath` and `MtaQueueQuota.match` optional expressions.

Made `SieveSystemInterpreter.defaultReturnPath` and `MtaQueueQuota.match` optional expressions.

Source: llm_adapter@2026-06-06

Confidence: high

Refactor Medium

OAuth access tokens use AES-256-GCM-SIV AEAD format with account name for proxy routing.

OAuth access tokens use AES-256-GCM-SIV AEAD format with account name for proxy routing.

Source: llm_adapter@2026-06-06

Confidence: high

Refactor Low

Added more internal TLDs to domain validation checks.

Added more internal TLDs to domain validation checks.

Source: llm_adapter@2026-06-06

Confidence: high

Full changelog

[0.16.8] - 2026-06-06

If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.

Added

Changed

  • OAuth: Rework access tokens to an AES-256-GCM-SIV AEAD format that carries the account name for proxy routing.
  • Added more internal TLDs to the domain validation.

Fixed

  • MTA:
    • Sub-addressing with external directories returns 550 Mailbox not found.
    • Disabled aliases continue receiving messages.
  • JMAP for File Storage: FileNode/get returns a stale state string.
  • Make SieveSystemInterpreter.defaultReturnPath and MtaQueueQuota.match optional expressions.
  • Rate limiter panics when periods under 1 second are used.
  • CalDAV/CardDAV: Calendar events, contacts, calendars and address books deleted via JMAP do not write a vanished tombstone.
  • DNS updater: bump to dns-update-v0.5.1.

Check binary attestation here

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track stalwart

Get notified when new releases ship.

Sign up free

About stalwart

All-in-one Mail & Collaboration server. Secure, scalable and fluent in every protocol (IMAP, JMAP, SMTP, CalDAV, CardDAV, WebDAV).

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]