Skip to content

Haraka

Communication & Email

A highly scalable Node.js SMTP server with a modular plugin architecture for handling thousands of concurrent connections and delivering mail.

JavaScript Latest v3.3.2 · 6d ago Security brief →

Features

  • Modular plugin system exposing hooks like connect, helo, mail, rcpt, data, etc.
  • Built‑in strong spam protection via community plugins (DNSBLs, DKIM, SpamAssassin, rspamd).
  • Scalable outbound delivery engine that automatically queues relaying messages.

Recent releases

View all 10 releases →
Review required
v3.3.2 Security relevant
Dependencies

Dependency security bump

Review required
v3.3.1 Breaking risk
Auth Dependencies

@email-address removal + postel option + fetch exposure

Review required
v3.2.0 Breaking risk
Dependencies Breaking upgrade

address-rfc282 replacement

Review required
v3.1.6 Breaking risk
Dependencies Auth

Dependency removals

v3.1.5 Bug fix

Fixed SMTP forward queue hook to call next() after delivery.

Full changelog
  • fix(smtp_forward): update AUTH to match WHATWG URL API #3546
  • fix(smtp_forward): queue hook now calls next() after delivery
    — see haraka/message-stream#17
  • deps(all): bump versions to latest
  • test: refactor server, use smtp_client for all tests #3548
  • test runner is now node --test #3547
  • test(smtp_client, tls_socket, smtp_forward): 95% coverage #3546
  • ci: added explicit minimal permissions

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
5,600
Forks
707
Languages
JavaScript Shell HTML
Downloads/week
6,109 ↑31%
NPM Maintainers
4
Contributors
100

Install & Platforms

Install via
npm

Beta — feedback welcome: [email protected]