Released September 2026


What's new?

  • Read-only administrator role: Administrators can now be created as read-only at any tier. A read-only admin sees the full interface and all reporting but cannot make changes. In the UI, you will now see a "Read-only" option on Add/Edit Administrator, a "Read Only" column in the Administrators table, and a persistent banner when logged in as a read-only admin.

  • DMARC bypass by sender domain: DMARC checks can be bypassed for a sender domain as well as by IP, at MSP, Customer and Domain tiers, in the UI, and in the REST API. IPv6 addresses are now accepted for IP bypass entries.

  • History and Quarantine date filters use your local day: Today, Yesterday, Last 7/30 Days, and custom ranges are now built from the browser's local calendar day rather than the UTC day. "Today" refreshes as the day changes. Users outside UTC will see evening mail under "Today", whereas previously it dropped out after the UTC rollover. The message viewer Details tab also shows local time, matching the lists.

  • Improved spam detection: Additional real-time blocklist (RBL) and URI blocklist (URIBL) checks are now active.
  • UI improvements:

    • Consistent table layout and controls across Attachment Filters, Two-Factor Authentication settings, Anti-Spoof, Policy (User and Domain), Users and Archive Reports.
    • Edit Customer and 2FA settings open in a modal instead of a separate page.

    • Updated import template for DMARC entries.

Bug fixes

  • Mail flow and filtering
    • User policy now correctly takes precedence over domain policy for pass-and-tag.
    • Mixed-case allow and block list entries now match.
    • An allow-list entry now bypasses Anti-Spoof, and allowing a message from History adds the sender to the recipient's allow list.
    • Fixed remote servers rejecting the appliance's TLS certificate.
    • Geoblocking "Include Subdomains" exemptions now match intermediate subdomains.


  • Anti-Spoof, SPF and DMARC
    • Fixed two cases where Display Name Spoofing missed a protected name: names that only matched approximately (fuzzy-name matching), and messages carrying two addresses in the From header, where the display-name and SPF checks were evaluated against the wrong address.
    • Domain Anti-Spoofing exceptions added by hostname now take effect. Previously only exceptions entered as an IP address worked, so mail from a trusted third-party sender (for example a mailing or CRM platform sending on the customer's behalf) that was exempted by hostname was still flagged as spoofed.
    • Enabling Domain Anti-Spoofing for multiple domains no longer errors.
    • SPF and DKIM bypass entries no longer override DMARC.
    • Consistent DMARC quarantine behaviour, and authentication headers are now written to DMARC-quarantined mail.


  • Link Lock
    • Performance improvements when rewriting emails containing a large number of URLs.
    • Fixed allow-list entries with a path being defeated by trailing characters, and exempted URLs still reported as "unable to verify".
    • Fixed rewriting breaking URLs, adding a trailing dot after decoding, mishandling international/Unicode characters, and missing known URL-scheme bypass payloads.
    • Fixed Link Lock rewriting URLs embedded inside PDF attachments, which corrupted the PDF so it would not open. PDF content is no longer rewritten.
    • Fixed images not displaying in emails processed by Link Lock, because the image source URLs had been rewritten.
    • Teams calendar "Join" buttons work again.
    • Link Lock no longer applied for customers with no Link Lock-enabled domains; domain admins see only the selected domain's policy.


  • Quarantine, History and Reports
    • Fixed release/forward failures for virus emails at Customer level.
    • Releasing or allowing a quarantined message no longer adds a second, misleading History entry for the re-delivered copy.


  • Pattern, content and attachment filters
    • Fixed pattern filters with more than one rule failing to save with a Header validation error, even when none of the rules matched on a header.


  • Administration UI
    • Fixed column sorting in the following tables: Administrators, DMARC exemptions, allow/block lists, Geoblocking rules and exemptions, Link Lock exemptions, Pattern Filters and Reports. Headers now toggle between ascending and descending only.


Security fixes

  • This release resolves a number of security issues found by internal review and testing, including: 
    • SQL injection in quarantine/history search sorting; 
    • SQL-injection hardening across configuration pages; 
    • path traversal in upload filenames; 
    • an over-permissive localhost authentication guard; 
    • a cross-tier pattern-filter leak;
    • stored XSS in HTML sanitisation; 
    • a missing Strict-Transport-Security header. 
  • DMARC quarantine no longer relies on an internal header to drop the original copy of a message. Previously, a sender could set that header on their own mail and have it accepted and then discarded without a bounce or a history entry.
  • Operating-system packages (including PostgreSQL and OpenSSH) and third-party libraries were updated.