Skip to content

MailRadar 2026.09.2

Choose a tag to compare

@github-actions github-actions released this 06 Sep 08:16
· 92 commits to main since this release
v2026.09.2

Added

  • report command: generates a ready-to-send email report in Italian or
    English (--lang it|en) comparing each check's current state with the
    recommended configuration. Sender details are set with --name, --role
    and --org (placeholders otherwise). --save writes the report to a file.
  • GPG public key lookup on keyservers (keys.openpgp.org, keyserver.ubuntu.com,
    pgp.mit.edu) for common contact addresses (security@, dpo@, admin@,
    postmaster@, privacy@). The result is shown as a GPG row in check and
    counts toward the score.
  • send command: analyzes a domain and delivers the report. With a GPG key it
    encrypts the report for the key owner. Without one, it sends in plaintext to
    common security contacts over SMTP (--smtp-host, --smtp-port,
    --smtp-user, --smtp-pass or MAILRADAR_SMTP_PASS, --from). Without
    SMTP settings it prints the report for manual copy-paste.
  • check verifies that the domain exists in DNS. If it does not, MailRadar
    scans common TLD variants and lets you pick one.
  • discover command: finds email addresses for a domain from website scraping
    (common contact and privacy pages, including subdomains found via crt.sh
    Certificate Transparency logs), DNS (SOA and TXT records), RDAP and common
    role addresses. It reports which addresses have a GPG public key; skip that
    check with --no-gpg.
  • Dockerfile and Docker image.
  • Release workflows: PyPI publishing, Docker Hub image and GitHub Release.
  • CI: CodeQL, SonarCloud, CodSpeed benchmarks, Trivy scanning and Dependabot.
    Dependencies pinned via uv.lock and a hash-locked requirements-ci.txt.
  • Mock-based tests for the checker, GPG and reporter modules.

Changed

  • README examples no longer reference third-party domains.
  • GPG keyserver lookups run in parallel and prefer the keys.openpgp.org VKS
    API, falling back to HKP. Before, domains with several candidate addresses
    could hit sequential timeouts.
  • CI split into dedicated workflows, with GitHub Actions pinned to commit SHAs.

Fixed

  • Report templates are rendered with an explicit Jinja2 autoescape policy
    (select_autoescape: enabled for HTML, disabled for the plain-text .j2
    email templates).

Security

  • GPG encryption no longer uses --trust-model always.
  • The keys.openpgp.org VKS endpoint is selected by parsing the keyserver
    hostname instead of a substring match on the URL.