Skip to content

v3.8.0

Latest

Choose a tag to compare

@maathimself maathimself released this 02 Oct 03:08

MailFlow v3.8.0

A security fix that everyone should install, backup and restore from Settings, automatic Cc and Bcc per account, and Korean. Thanks to @Monkey7539 for the security fix, the login-limit fix, backup and restore, and automatic Cc and Bcc; @GOODJINC for the Korean translation; and @fahadalisarwar1 and @Lewis8265 for the requests behind the two new features.

Security

  • One email could freeze the whole server (#541). A message with a specially crafted <style> block took MailFlow seconds to minutes to process, and the server answered nobody while it did. The message did not have to be opened: new mail is processed as it arrives, so anyone who could email a MailFlow user could do this. Processing such a message now takes milliseconds. Update as soon as you can.
  • Failed logins locked out every user behind Caddy (#540). Behind the bundled Caddy (the https profile), every visitor appeared to come from Caddy's address, so ten failed sign-ins from anyone blocked sign-in for all users for 15 minutes. Each visitor now has their own limit, and Login Activity shows their real address. See Upgrading for the compose file this needs.

New

  • Backup and restore (#526, closes #452). Settings → Administration → Backup (admins only) downloads a backup of the installation: users, email accounts, rules, contacts, settings, plugin data and antispam training. Include cached mail adds the local copy of every message; without it, mail is downloaded again from your mail servers after a restore. Restoring replaces everything on the server with the file's contents and restarts MailFlow. A backup restores only on a MailFlow version with the same database schema, and only on a server with the same ENCRYPTION_KEY. The file holds password hashes and pending invite links, so keep it somewhere safe. Behind your own reverse proxy, see the README's Backup and Restore section for the upload size and timeouts it needs.
  • Automatic Cc and Bcc (#527, closes #491). Settings → Accounts → Edit account has addresses to add automatically as Cc or Bcc to mail written from that account or its aliases, for example a Bcc to yourself. They appear in the composer as normal recipients you can remove before sending.
  • Korean (#520). The interface is now available in Korean.

Fixed

  • Opening Settings right after an update. A tab left open across a server update showed "error loading dynamically imported module" the first time it opened Settings, Contacts or the composer. It now reloads into the new version by itself, or says the page is running the previous version and offers Reload. This takes effect from this version onward.

Upgrading

ghcr.io/maathimself/mailflow-backend:latest points at 3.8.0, published for amd64 and arm64. Migration 0062 runs automatically on first start and is instant. After updating, reload any open MailFlow tabs.

If you use the pre-built images, docker compose pull does not update your compose files:

  • With Caddy (--profile https): download the new docker-compose.https.yml to get the login-limit fix.
  • Behind your own reverse proxy: you can now set TRUST_PROXY_HOPS=2 in .env, but only if MailFlow can be reached through nothing but that proxy (the README explains how). It takes effect only with the new docker-compose.ghcr.yml, saved as docker-compose.yml. Login Activity showing your visitors' addresses instead of the proxy's confirms it worked.