Postfix mail server 3.11.0 has been released

After a year of development, a release of the new stable branch of the Postfix mail server — 3.12.0 — has been published. At the same time, it was announced that support for the Postfix 3.7 branch, released in early 2022, will cease. The project code is written in C and is distributed under the EPL 2.0 (Eclipse Public License) and IPL 1.0 (IBM Public License).

Postfix is one of the few projects that combines high security, reliability, and performance, which has been achieved through a multi-processing architecture that isolates individual handlers, as well as a strict code formatting policy and patch auditing. To protect against memory-related errors, the project uses protected versions of functions for memory allocation and deallocation, as well as a set of abstract wrapper functions for handling buffers (checking for buffer overflows and access to freed memory), file operations, output formatting, buffered input/output, and string manipulations (including capabilities for working with arbitrary-sized strings and automatic resizing of strings).

According to the final automated survey of about 500,000 mail servers (after July 2025, report publication will be discontinued), Postfix is used on 37.88% (up from 36.81% last year) of mail servers, Exim accounts for 55.59% (down from 56.61% last year), Sendmail — 3.55% (down from 3.60%), MailEnable — 1.81% (down from 1.82%), MDaemon — 0.40% (unchanged), Microsoft Exchange — 0.20% (up from 0.19%), and OpenSMTPD — 0.12% (up from 0.09%). servers Work has been done to simplify migration from hash: and btree: lookup tables to lmdb: or cdb: due to the discontinuation of BerkeleyDB libraries in some Linux distributions. To maintain compatibility with the Mailman toolkit, which launches the command postmap hash:/path/to/file when adding or removing mailing lists, Postfix has added support for automatically redirecting such commands to variants with supported database types.

Key innovations:

  • By default, connections to SMTP servers using TLS encryption are enabled. In the SMTP client settings, the smtp_tls_security_level parameter is set to 'may' if Postfix is built with TLS support. The 'may' value includes the use of TLS for servers that support encryption, but allows for fallback to unencrypted data transmission if the server does not support TLS.
  • By default, connections to SMTP servers using TLS encryption are enabled. In the SMTP client settings, the smtp_tls_security_level parameter is set to 'may' if Postfix is built with TLS support. The 'may' value allows the use of TLS for servers that support encryption but permits a fallback to sending data unencrypted if the server doesn't have TLS support.
  • ESMTP has implemented support for the 'REQUIRETLS' extension (RFC 8689), which allows the sender to request guaranteed TLS encryption throughout the message delivery path. In this mode, any SMTP and LMTP server involved in redirecting the email must support REQUIRETLS and strict authentication via DANE or STS, and when passing the message in a chain to other servers, also use REQUIRETLS.
  • TLS security level logging has been implemented, meaning that if the REQUIRETLS level is requested for message transmission, information about the use of REQUIRETLS will now be saved in the log.
  • The smtp_tls_enforce_sts_mx_patterns parameter has been added, enabling compatibility between the Postfix SMTP client and MTA-STS plugins (MTA Strict Transport Security) that require TLSRPT support for redirecting STS attributes. When this parameter is set, which is enabled by default, the Postfix SMTP client will connect to the MX server only if its name matches the pattern specified in the STS policies. Otherwise, the old behavior will be used — the ability to connect to MX servers based on MX records in DNS, provided the server certificate complies with the STS policies. The MTA-STS mechanism allows informing the client that established a connection via an unsecured channel about the possibility and parameters for establishing a secure TLS connection. Support for this parameter has also been added to the tools postfix-tlspol and postfix-mta-sts-resolver.
  • Support for encryption algorithms resistant to quantum computer attacks has been added, when compiled with OpenSSL 3.5 and newer releases.
  • 16 configuration parameters have been deprecated, for which a warning about their removal in a future release will now be logged. Among the deprecated parameters are 'virtual_maps', 'fallback_relay', 'postscreen_whitelist_interfaces', and 'smtpd_client_connection_limit_exceptions'.
  • Support for outputting data in JSON format has been added for the commands: 'postconf -j|-jM|-jF|-jP', 'postalias -jq|-js', 'postmap -jq|-js', and 'postmulti -jl'.
  • Error handling in Milter filters has been improved for messages received through long-established SMTP connections. The value of the #milter_default_action parameter has been changed from 'tempfail' to 'shutdown', which implies closing the connection with the client.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster