Skip to content

MailRadar 2026.09.8

Choose a tag to compare

@github-actions github-actions released this 16 Sep 18:39
· 57 commits to main since this release
v2026.09.8

Fixed

  • send: encryption with a key fetched from a keyserver failed because the key
    was never in the local keyring. The key is now imported into a throwaway
    temporary keyring, so the user's own keyring is left untouched.
  • send: if a GPG key is found but encryption fails, the report is no longer
    silently sent in plaintext. It is not sent, the report is printed for manual
    delivery and the command exits with code 1.
  • Total score could exceed 100 because the raw per-check maximums add up to
    more than 100. The raw score is now normalized to a 0-100 scale.
  • DMARC and BIMI tag values containing = were truncated.
  • An invalid DMARC pct value (non-numeric or outside 0-100) no longer crashes
    the analysis: it is reported as an issue and treated as 100 (RFC 7489 §6.3).
  • A non-UTF-8 TXT record no longer crashes the analysis.
  • batch: a domain that fails analysis no longer stops the whole run. It is
    reported and listed in a final "Failed" summary.
  • discover: the email regex matched look-alike domains (e.g. addresses at
    example.community or example.com.evil.org when discovering example.com).
  • discover: guessed role addresses (RFC 2142) are now shown separately as
    unverified candidates instead of being mixed with addresses found in public
    sources. They are skipped for domains that publish a null MX (RFC 7505).
  • discover: GPG lookups for discovered addresses now run in parallel and
    also cover the guessed candidates.

Security

  • DNS records, domain names, keyserver data and report text shown in the
    terminal are escaped, so Rich markup injected via DNS records or other
    external data is no longer interpreted.