v0.16.16

stalwartlabs/stalwartv0.16.16Aug 2, 2026by github-actions[bot]

AI Summary

Implements JMAP Email Delivery Push Notifications and allows Sieve scripts to access the Original Recipient (orcpt) during the DATA stage.

Key Highlights

  • JMAP Email Delivery Push Notifications support
  • Sieve scripts can now access orcpt during DATA stage
  • S3 accessKey can be read from environment variables or files
  • Branding fix for logo loading on login page

New Features

  • JMAP Email Delivery Push Notifications (draft)
  • Sieve scripts access to orcpt
  • S3 accessKey from environment or file
  • WebUI branding improvements

Full Release Notes

## [0.16.16] - 2026-08-02

If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions.

## Added
- JMAP Email Delivery Push Notifications ([draft-ietf-jmap-emailpush-03](https://datatracker.ietf.org/doc/draft-ietf-jmap-emailpush/))
- MTA: Allow System Sieve scripts to access `orcpt` during the `DATA` stage.

## Changed
- S3: `accessKey` can now be read from an environment variable or file.

## Fixed
- Meilisearch: Verify index existence using `GET` instead of creating a new task which times out on busy servers.
- Branding: Stalwart logo flashes before the per-tenant logo is loaded on the login page.
- Calendar: iMIP and alarm notification messages embed the default logo using bare `LF` line endings, producing a single 4247 octet line that strict SMTP relays reject with `line too long`.
- DMARC: Failure reports state `Identity-Alignment: none` when a mechanism authenticated successfully but against an identity that is not aligned with the `From` domain.
- Redis: Task and queue locks are never released after a worker dies, because failed lock attempts refresh the lock expiry.
- Recovery mode: Download WebUI if missing.
- Logging: The systemd journal tracer omits the parent span's fields.
- MTA: 
  - `BDAT` chunks sent without a valid `MAIL FROM` are answered with `552 5.3.4 Message too big for system` instead of `503 5.5.1`.
  - A `maxMessageSize` of `0` rejects every message with `552 5.3.4 Message too big for system` instead of disabling the size limit.
- Windows: Listeners bound to the unspecified IPv6 address (`[::]`), including all defaults, refuse IPv4 connections such as `127.0.0.1`, since `IPV6_V6ONLY` is enabled by default on Windows.


<hr />

### Check binary attestation [here](https://github.com/stalwartlabs/stalwart/attestations/38449267)