Skip to content
CAI
Software that uses CAICheck a score

postalserver/postal

40.7

Weak · 26 September 2026

11.8k

lines of production code

Ruby

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Postal is an open-source mail transfer agent and administration platform designed for managing high-volume email delivery. It provides a web-based interface for configuring multi-tenant organizations, servers, domains, and IP pools, while handling the core SMTP and HTTP protocols for sending and receiving messages. The system includes robust features for tracking email engagement, managing spam filtering via external engines, and monitoring delivery health through detailed logs and metrics.

How it got here

2017 — Postal 3.3.7 scaffolding and architecture

46 changes.

This period established the foundational structure for Postal version 3.3.7, upgrading the core to Rails 7.1 and Ruby 3.4 while introducing a new v2 configuration system and OpenID Connect support. It implemented the initial database schema, including IP pool management and message tracking, and built out the comprehensive web administration interface for managing servers, organizations, and routing.

2021–2026 — Infrastructure refactoring and security hardening

24 changes.

This period focused on a comprehensive architectural overhaul of Postal's core mail processing components, including the SMTP server, client, and message dequeuer, to improve modularity, observability, and performance. Significant effort was dedicated to security hardening, implementing SSRF protection, SQL injection prevention, and XSS mitigations across the API and delivery pipelines. The work was supported by extensive test coverage expansion and the introduction of automated maintenance tasks and health monitoring utilities.

Features

Add HTTP endpoint and tracking domain configuration views

This change introduces the user interface for configuring HTTP endpoints and tracking domains within the server routing settings. Users can now create, edit, and manage HTTP endpoints to receive email data via webhooks, selecting options for encoding (JSON or form data), format, reply stripping, attachment inclusion, and timeout. Additionally, users can configure tracking domains to enable open and click tracking for outbound emails, with options to enable SSL, toggle tracking for loads and clicks, and exclude specific domains from tracking. The interface includes forms for inputting domain names and CNAME records, lists existing configurations with their status, and provides links to manage these resources.

_app/views/track\domains · high confidence

Add IP pool rule management views

Added the user interface for creating, editing, and listing IP pool rules, allowing administrators to define conditions based on recipient or sender addresses and assign specific IP pools for message delivery. The new views support both global rules and server-specific rules, with the index page displaying existing rules and indicating the default IP pool for unmatched traffic.

_app/views/ip\_pool\rules · high confidence

Add address endpoints to the routes UI

The Routes management interface now includes support for Address Endpoints. Users can create and edit routes that direct incoming mail to specific email addresses, in addition to existing HTTP and SMTP endpoints. The new form allows configuring the target address, selecting spam handling modes (Mark, Quarantine, Fail), and setting up multiple delivery endpoints. The list view and navigation header have been updated to reflect this capability.

app/views/routes · high confidence

Added application icon and UI icon set

The application now includes a primary icon (\icon.svg\) and a comprehensive set of SVG icons for the user interface, such as mail, search, user, and organization symbols, located in \app/assets/images/icons/\.

app/assets/images · high confidence

Added help documentation for sending and receiving email

New help pages have been added to guide users on configuring their mail server. The 'Sending E-Mail' page details SMTP connection settings (including hostname, port, and credentials) and HTTP API usage, while the 'Receiving E-Mail' page explains how to set up incoming routes and configure DNS MX records. These pages dynamically pull configuration values such as the default maximum delivery attempts and MX records from the system configuration.

app/views/help · high confidence

Added new email templates for account and server management notifications

The application now includes specific email templates for password resets, domain verification requests, and server status updates (including send limit warnings, limit exceedances, and suspensions), as well as a test message template. These templates utilize the new configuration system for sender details and provide users with clear instructions and links for managing their Postal account and mail server operations.

_app/views/app\mailer · high confidence

Added password reset flow and OIDC login support

Users can now reset forgotten passwords via a new two-step web form (request link and set new password) and log in using OpenID Connect if enabled. The login page displays an OIDC button and conditionally shows local email/password fields based on configuration, while the user settings page enforces current password verification for changes when local authentication is active.

app/views/sessions · high confidence

Admin UI for managing IP pools and addresses

Administrators can now create, edit, and delete IP pools via a new web interface. The IP pools index page lists existing pools and allows creation of new ones. The edit view displays assigned IPv4 and IPv6 addresses along with their hostnames and priority values, enabling users to manage which IP addresses are associated with each pool and in what order they are used for sending mail.

_app/views/ip\pools · high confidence

Admin UI for managing IP pools and addresses with priority-based selection

Administrators can now create and edit IP addresses within IP pools via a new web interface. The form allows setting IPv4/IPv6 addresses, hostnames, and a new priority field (defaulting to 100) that controls the likelihood of an IP being selected for sending messages, enabling features like gradual warm-up of new IPs.

_app/views/ip\addresses · high confidence

Admin interface for assigning IP pools to organizations

Administrators can now assign specific IP pools to an organization via a new dedicated view. The interface presents a list of available IP pools with checkboxes, allowing admins to select which pools the organization can use for sending mail. Non-admin users viewing this section will see a list of their assigned IP addresses (including IPv4, IPv6, and hostnames) or a message indicating no addresses are assigned yet.

_app/views/organization\_ip\pools · high confidence

Initial Rails environment configuration files added

The application now includes explicit configuration files for development, production, and test environments. These files establish the default behavior for code reloading, eager loading, caching, static asset serving, and logging specific to each environment, providing a standard baseline for the Rails application setup.

config/environments · high confidence

Initial UI component stylesheets added

The application now includes a comprehensive set of SCSS stylesheets for its UI components, covering layout structures (grid, sidebar, page content), navigation elements (nav bar, site header, footer), data presentation (various list views for messages, domains, credentials, webhooks, etc.), forms (login, field sets), and status indicators (errors, flash messages, server headers). This establishes the visual foundation for the admin dashboard and user interface.

app/assets/stylesheets/application/components · high confidence

Initial UI for managing address endpoints, SMTP endpoints, and webhooks

This change introduces the web interface views for configuring three new routing and notification features. Users can now create, edit, and delete Address Endpoints (external email addresses to deliver to) and SMTP Endpoints (external mail servers to forward to), with forms capturing necessary connection details like hostnames, ports, and SSL modes. Additionally, a complete Webhooks management interface is added, allowing users to configure webhook URLs, enable/disable them, select specific events to trigger notifications, and view a 10-day history of webhook delivery attempts with payload details.

_app/views/address\_endpoints, app/views/smtp\endpoints, app/views/webhooks · high confidence

Initial application scaffolding and asset structure

This commit establishes the foundational structure for the application, introducing the main SCSS entry point (\application.scss\) which configures global styles, imports vendor libraries (including Chartist for charting), and defines layout rules for main and sub-pages. It also adds a shared pagination partial (\\_message\_db\_pagination.html.haml\) for navigating paginated data, standard error pages (404, 422, 500), and placeholder directories for assets and logs.

(repo-wide) · high confidence

Initial database schema and migration definitions for message tracking

This change introduces the foundational database schema for the Postal message tracking system by adding 20 migration files to the \lib/postal/message\_db/migrations\ directory. These migrations establish the core tables required for tracking email activity, including \messages\, \deliveries\, \clicks\, \loads\, \links\, \spam\_checks\, \suppressions\, and \webhook\_requests\, alongside statistical tables (\live\_stats\, \stats\_hourly/daily/monthly/yearly\) and raw message size tracking. The schema includes specific columns for tracking metrics such as spam scores, threat details, bounce reasons, and endpoint associations, and concludes with a migration to convert the database character set to \utf8mb4\ to support full Unicode.

_lib/postal/message\db/migrations · high confidence

Initial frontend asset bundle with interactive UI components

This change introduces the core JavaScript assets for the application, establishing the baseline user interface behavior. It includes vendor libraries (Chartist 0.9.8 for data visualization and jQuery Multibox for input handling) and application-specific CoffeeScript modules. Key user-facing features include AJAX-driven form submissions with flash message handling, a searchable dropdown component with keyboard navigation, a mail volume graph visualization, and credential input toggling that specifically supports SMTP-IP authentication modes.

app/assets/javascripts · high confidence

Initial global stylesheet foundation added

The application now includes a new set of global SCSS files that establish the base visual layer. This adds font definitions for 'Droid Sans Mono' and 'Source Sans Pro' (with various weights), a CSS reset to normalize browser defaults, utility classes for spacing and colors, and shared variables and mixins for consistent styling across the UI.

app/assets/stylesheets/application/global · high confidence

Initial implementation of the credentials management UI

This change introduces the user interface for managing server credentials, including the list view (index), the form for creating or editing credentials (new/edit), and the associated partials. The interface allows users to define credentials by type (such as SMTP), assign a friendly name, and manage authentication keys. It also supports configuring message holding behavior for specific credentials and displays usage statistics, such as the last time a credential was used.

app/views/credentials · high confidence

Initial organization management interface

This change introduces the core user interface for managing organizations, including views for listing, creating, editing, and deleting organizations. The navigation bar dynamically hides IP-related links when IP pools are unavailable and restricts the 'Delete Organization' action to administrators only. The deletion flow requires explicit confirmation by entering the organization's name to prevent accidental data loss.

app/views/organizations · high confidence

Initial release of the application layout templates

This change introduces the foundational view layouts for the application. The main layout (application.html.haml) establishes the site header with navigation for organizations, users, and settings, conditionally displays IP Pools for admins when enabled, and includes a footer with links to documentation and discussions along with the Postal version. A secondary layout (sub.html.haml) is also added for sub-pages, providing a simplified structure with a main content box.

app/views/layouts · high confidence

Initial repository structure and configuration for Postal 3.3.7

This change establishes the foundational project files for Postal version 3.3.7, including the Dockerfile (based on Ruby 3.4.6-slim-bookworm), docker-compose.yml for local development with MariaDB, and standard configuration files like .rubocop.yml, .gitignore, and .dockerignore. It also introduces the MIT License, SECURITY.md policy, and release-please configuration to automate changelog and versioning, alongside documentation files (README, CONTRIBUTING) and the initial CHANGELOG.md reflecting the 3.3.7 release.

(repo-wide) · high confidence

Initial server management UI with IP pool assignment and privacy controls

This change introduces the complete web interface for managing mail servers, including creation, editing, and deletion. Administrators can now assign IP pools to servers for outbound delivery when IP pools are enabled, and configure advanced settings such as privacy mode (to hide client IP/hostname in Received headers), SMTP data logging, and outbound spam thresholds. The UI also provides controls for message retention, send limits, and spam handling thresholds.

app/views/servers · high confidence

Initial web administration interface for server and organization management

This change introduces the foundational web controllers for the Postal administration interface, enabling users to manage organizations, servers, domains, IP pools, and message routing. Key capabilities include creating and configuring servers with IP pool assignments, verifying domain ownership via DNS or email, managing SMTP and HTTP endpoints, and sending test messages. The implementation also establishes the core authentication flow, supporting both local password login and OpenID Connect (OIDC), along with session management and user administration.

app/controllers · high confidence

Introduce background scheduled task framework for automated maintenance

A new background work process has been added to handle routine maintenance tasks automatically. This includes permanently removing deleted organizations and servers, checking DNS records for domains, cleaning up Authie sessions, expiring held messages, enforcing message retention policies (by days or size), pruning suppression lists and webhook requests, sending send-limit notifications, and removing queued messages with stale locks. These tasks run on defined schedules (e.g., every 15 minutes, at 3 AM) to keep the system clean and consistent without manual intervention.

_app/scheduled\tasks · high confidence

Introduction of new data models for routing, IP management, and credentials

This change introduces a comprehensive set of new database models to support advanced routing, IP pool management, and authentication. Key additions include \AdditionalRouteEndpoint\ and \Route\ to enable complex routing configurations with multiple endpoints, \IPAddress\ and \IPPool\ models to manage IP address assignment with priority-based selection, and \Credential\ to support SMTP, API, and IP-based authentication methods. The update also adds \BounceMessage\ for handling delivery failure notifications, \IncomingMessagePrototype\ and \OutgoingMessagePrototype\ for processing email payloads, and \Organization\/\OrganizationUser\ models to establish multi-tenant isolation. These models form the structural foundation for the new configuration system and IP pool features.

app/models · high confidence

Introduction of new email notification templates and mailer configuration

Users will now receive specific automated emails for account and server events, including domain ownership verification, password resets, and notifications when a mail server approaches or exceeds its send limit, or is suspended. A new test message capability has also been added to allow SMTP connection testing. These changes are powered by a new mailer structure that dynamically sets the sender address based on the current SMTP configuration.

app/mailers · high confidence

New CLI scripts for administration, testing, and monitoring

A suite of new command-line scripts has been added to the \script/\ directory to streamline operational tasks. Administrators can now easily create an initial admin user (\make\_user.rb\), generate self-signed TLS certificates for SMTP encryption (\generate\_tls\_certificate.rb\), and retrieve the default DKIM DNS record (\default\_dkim\_record.rb\). For testing and debugging, the update includes \test\_app\_smtp.rb\ to verify SMTP connectivity, \send\_html\_email.rb\ for sending sample HTML messages, and \insert-bounce.rb\ to simulate bounce events. Operational visibility is improved with \queue\_size.rb\ to check the pending message count, while \smtp\_server.rb\ and \worker.rb\ serve as entry points for their respective background processes, integrating with the new health server for monitoring.

script · high confidence

New Rake tasks for configuration documentation and message database management

This change introduces new Rake tasks in the \lib/tasks\ directory to support configuration management and database operations. The \postal:update\ task provides a unified entry point for database migrations, automatically choosing between \db:migrate\ and \db:schema:load\ based on the presence of schema migrations. The \postal:migrate\_message\_databases\ task allows administrators to run migrations on all message databases across servers. Additionally, new tasks \postal:generate\_config\_docs\ and \postal:generate\_helm\_env\_vars\ enable the generation of configuration documentation in Markdown and YAML formats, as well as Helm environment variable exports, using the Konfig library. An \auto\_annotate\_models\ task is also added for development environments to automatically annotate Rails models.

lib/tasks · high confidence

New UI element styles for buttons, inputs, and spam range sliders

This change introduces a new set of SCSS styles for core UI components in the application's elements directory. It defines visual styles for buttons (including variants like positive, neutral, danger, and dark, plus a spinning state), input fields (with focus, disabled, and danger states), labels (color-coded for server status, message status, and credential types), and a custom-styled spam range slider with specific track and thumb styling for WebKit, Firefox, and IE. These styles provide the visual foundation for interactive elements such as forms, status indicators, and spam filtering controls.

app/assets/stylesheets/application/elements · high confidence

New domain management interface with DNS and email verification options

The Domains section now features a complete set of views for adding, verifying, and configuring domains. Users can add new domains and choose between DNS TXT record verification or email code verification (with the latter option hidden for admin users). The domain list displays real-time status checks for SPF, DKIM, MX, and Return Path records, while the setup page provides specific instructions and record values for configuring DNS to ensure proper email delivery.

app/views/domains · high confidence

New message inspectors for ClamAV, Rspamd, and SpamAssassin

Postal now includes dedicated message inspector classes for ClamAV, Rspamd, and SpamAssassin, allowing administrators to configure these specific spam and virus scanning engines. The Clamav inspector connects via TCP to scan raw messages and reports threats or timeouts. The Rspamd inspector sends messages to the /checkv2 HTTP endpoint, parsing symbol scores and descriptions into detailed spam checks, with special handling for outgoing mail to disable certain checks. The SpamAssassin inspector communicates via the SPAMC protocol, parsing rule scores and applying configurable exclusions based on whether the mail is incoming or outgoing.

_lib/postal/message\inspectors · high confidence

New message management interface with delivery tracking and suppression list

This change introduces a comprehensive set of views for managing email messages within the Postal application. Users can now view detailed message properties, including spam status, tags, and transport security. The interface provides granular delivery tracking, showing individual delivery attempts with timestamps, status, and technical error details, along with options to retry, release, or cancel holds on messages. A new 'Suppressions' view allows administrators to manage addresses that have been automatically added to the suppression list due to delivery failures, displaying the reason for suppression and expiration time. Additionally, the update includes views for inspecting message headers, attachments, and plain/HTML bodies, as well as a dedicated activity log showing clicks and opens.

app/views/messages · high confidence

New model concerns for authentication, DNS checks, locking, and soft deletes

This change introduces a new \app/models/concerns\ directory containing several reusable modules that enhance model capabilities. \HasAuthentication\ adds secure password handling, validation, and OIDC-aware password reset logic. \HasDNSChecks\ implements automated verification for SPF, DKIM, MX, and return-path records, including webhook notifications for failures. \HasLocking\ provides mechanisms for item locking, unlocking, and exponential backoff retry logic. \HasMessage\ facilitates loading associated message data from a message database. \HasSoftDestroy\ adds soft-delete functionality with scopes for deleted and present records. \HasUUID\ ensures unique UUID generation and parameterized URLs.

app/models/concerns · high confidence

New user management interface with OpenID Connect support

The application introduces a new user management interface (views for listing, adding, and editing users) that supports OpenID Connect (OIDC). When OIDC is enabled, the user creation form displays guidance that the email address must match the identity provider and allows for optional local password setup for users who have not yet logged in via OIDC. The user list view now displays tags indicating whether a user is an admin, uses OIDC, or is pending OIDC authentication.

app/views/users · high confidence

New utility modules for health monitoring, metrics, and user creation

This change introduces three new utility components to the application. The \HealthServer\ provides a standalone HTTP server (using Rackup/WEBrick) that exposes \/health\ for status checks and \/metrics\ for Prometheus data, with robust hostname resolution and logging. The \HasPrometheusMetrics\ module offers helper methods to register and observe Prometheus counters and histograms, facilitating metrics collection across the codebase. Additionally, the \UserCreator\ module provides a CLI-based tool for creating new Postal users, streamlining the initial admin setup process.

app/util · high confidence

Security

Escaped HTML in delivery details and select options to prevent injection

The application helper now escapes user-supplied values in delivery details and select options to prevent HTML injection. In \format\_delivery\_details\, text is sanitized via \h()\ before being processed, ensuring that any embedded HTML is rendered as text rather than executed. Similarly, \domain\_options\_for\_select\, \endpoint\_options\_for\_select\, and \postal\_version\_string\ now use \h()\ to escape domain names, endpoint descriptions, addresses, and mode labels when generating HTML options, mitigating cross-site scripting risks in form inputs.

app/helpers · high confidence

SSRF protection for outbound HTTP requests

Outbound webhook and HTTP endpoint requests are now guarded against Server-Side Request Forgery (SSRF). The system resolves destination hosts and blocks connections to private, loopback, link-local, multicast, and other reserved IP ranges (including cloud metadata endpoints) by default. Administrators can permit specific destinations by adding hostnames or IP/CIDR ranges to the \postal.allowed\_request\_destinations\ configuration option.

lib/postal/http · high confidence

Behavioural changes

Add CI support scripts for Docker image generation and health checks

The Docker directory now includes a signing key and a wait-for.sh script to support CI workflows. The signing key enables image signing during the build process, while the wait-for.sh utility allows containers to block startup until specific HTTP or TCP dependencies are available, improving reliability in test environments.

docker · high confidence

Added asset pipeline manifest configuration

A new manifest file has been added to configure the asset pipeline, explicitly linking the application's JavaScript, CSS, and image assets to ensure they are correctly compiled and served.

app/assets/config · high confidence

Added migration waiter and refactored email tracking middleware

The application now includes a MigrationWaiter component that can delay process startup until all database migrations are complete, configurable via the new configuration system to support clustered deployments. Additionally, email tracking functionality has been consolidated into a new TrackingMiddleware class, which handles open tracking via pixel images and click tracking via redirects, replacing previous inline implementations.

lib · high confidence

Application initialization and configuration overhaul

This change introduces a comprehensive set of new configuration initializers that modernize the application's startup behavior and security posture. Key updates include enabling OpenID Connect (OIDC) authentication via the new omniauth initializer, enforcing stricter Content Security Policies and HTTP permissions policies, and configuring trusted proxies for accurate IP detection. The session cookie key has been renamed to \_postal\_session, and the application now supports configurable SMTP settings for outgoing mail, including specific handling for Windows-1258 encoding and connection reliability. Additionally, the system now waits for database migrations to complete before starting, utilizes a new logging structure for request and email events, and adopts Rails 7.0 framework defaults to improve security and compatibility.

config/initializers · high confidence

Database schema updated to Rails 7.0 with new IP pool and session structures

The database schema has been regenerated for Rails 7.0, introducing several structural changes. New tables include \ip\_pools\, \ip\_pool\_rules\, \organization\_ip\_pools\, and \ip\_addresses\ (with priority support), enabling IP address management and assignment. The \authie\_sessions\ table has been expanded with fields for two-factor authentication tracking (\two\_factored\_at\, \two\_factored\_ip\, \skip\_two\_factor\) and country-based login data. Additionally, the \organizations\ table now links to an \ip\_pool\_id\, and the \queued\_messages\ table tracks the specific \ip\_address\_id\ used. The initial seed file has been cleared.

db · high confidence

Database schema updates for privacy, OIDC, and background processing

This release introduces several database schema changes to support new features and improve security. A \privacy\_mode\ boolean is added to the \servers\ table, allowing administrators to toggle privacy settings. OpenID Connect support is enabled by adding \oidc\_uid\ and \oidc\_issuer\ columns to the \users\ table. Session tracking is enhanced with country fields (\login\_ip\_country\, etc.) on \authie\_sessions\ and a \skip\_two\_factor\ flag. Additionally, a new \worker\_roles\ table is created to manage background work processes, and \ip\_addresses\ gain a \priority\ column for assignment control.

db/migrate · high confidence

Introduces bin/postal as the unified command-line entrypoint

The application now uses a new \bin/postal\ script to manage core operations, replacing previous methods for running servers and performing setup. This single entrypoint handles starting the web, SMTP, and worker processes, as well as executing administrative tasks such as initializing the database, upgrading the schema, creating admin users, and testing SMTP connectivity. Standard Rails binstubs for \rails\, \rake\, and \rspec\ are also added to ensure consistent execution environments.

bin · high confidence

New configuration system and OpenID Connect support

The application introduces a new configuration system that centralizes settings via the Postal::Config module, replacing previous defaults and file-based approaches. This change enables OpenID Connect (OIDC) authentication, which is conditionally enabled via configuration and exposes the /auth/oidc/callback route when active. Additionally, the database configuration now explicitly sets reconnect: true for MySQL connections, and the Puma server configuration supports binding via the PORT environment variable while reading thread counts from the new config system.

config · high confidence

New message database abstraction layer

The message database access layer has been rewritten with a new set of classes, introducing a custom connection pool that automatically retries and discards failed MySQL connections, and a provisioner that creates message databases using the utf8mb4 character set. The new architecture includes dedicated classes for managing message deliveries (with output and details truncated to 250 characters), click and load tracking, live statistics, and a suppression list with automatic removal, providing a more robust and structured way to interact with the message storage.

_lib/postal/message\db · high confidence

New v2 configuration system with environment variable support and legacy migration

Postal introduces a new configuration system (v2) that allows settings to be managed via environment variables and a structured YAML schema, replacing the previous flat configuration file format. The system automatically detects legacy v1 configuration files and maps them to the new schema while displaying a warning, ensuring a smooth transition. This change also adds support for configuring trusted proxies, SMTP relays, database connection pool sizes, and worker thread counts, alongside a new Helm configuration exporter for Kubernetes deployments.

lib/postal · high confidence

Refactored SMTP and HTTP senders with new base class and result handling

The sender components in app/senders have been restructured to use a new BaseSender abstract class, with specific implementations for SMTP and HTTP delivery. The SMTP sender now explicitly handles MX record resolution, including raising errors on timeout, and manages connection retries and error states (SoftFail/HardFail) via a new SendResult object. The HTTP sender supports configurable endpoints with JSON or form data payloads, rate-limit handling (429), and secure connection tracking. Both senders use SecureRandom for log IDs and provide detailed result reporting for delivery status.

app/senders · high confidence

Refactored SMTP delivery and DNS resolution infrastructure

The SMTP sending pipeline has been restructured into a new modular library under app/lib/smtp\_client, introducing dedicated classes for managing server endpoints, handling SSL/TLS modes (Auto, STARTTLS, TLS, None), and executing message delivery with automatic session retry on connection errors. DNS lookups are now centralized in a new DNSResolver library that supports A, AAAA, MX, and CNAME records, includes Punycode encoding for internationalized domain names, and enforces configurable timeouts that raise errors on MX lookup failures. Supporting utilities for DKIM header generation, received header creation, and reply thread separation have also been moved into this location to consolidate mail-processing logic.

app/lib · high confidence

Refactored message dequeuer with new processor architecture and batching support

The message dequeuer has been restructured into a modular pipeline using a base class and specific processors for initial, single, incoming, and outgoing messages. This change introduces configurable message batching (controlled by \Postal::Config.postal.batch\_queued\_messages?\) to process multiple related messages together, and adds a Prometheus metric (\postal\_message\_queue\_latency\) to track how long messages spend in the queue. The refactoring also centralizes sender management via a state object to improve connection handling and ensures proper cleanup of resources after processing.

_app/lib/message\dequeuer · high confidence

SMTP server refactored with proxy protocol support, IPv6 normalization, and Prometheus metrics

The SMTP server implementation has been moved to app/lib/smtp\_server and refactored to support the HAProxy PROXY protocol, allowing it to correctly identify client IPs when sitting behind a load balancer. The server now strips the ::ffff: prefix from IPv4-mapped IPv6 addresses to ensure consistent logging and identification. Additionally, Prometheus metrics have been added to track connection counts, TLS handshakes, and command usage, providing better observability into server performance and health.

_app/lib/smtp\server · high confidence

Worker process refactored with configurable threading and automatic connection pool scaling

The worker process has been restructured to support a configurable number of worker threads, allowing for better resource utilization under load. To prevent database connection exhaustion, the worker now automatically scales the ActiveRecord connection pool size to accommodate the configured thread count (specifically, ensuring the pool size is at least thread\_count + 3). This change is accompanied by the introduction of a new job-based architecture for processing queued messages and webhook requests, replacing the previous monolithic processing logic with distinct job classes that handle locking and execution.

app/lib/worker · high confidence

Fixes

Legacy API reimplementation without Moonrope dependency

The legacy API controllers have been rewritten to remove the unmaintained Moonrope framework dependency while preserving existing v1 API functionality. This change introduces a new BaseController that handles authentication via the X-Server-API-Key header and supports both JSON body and form-encoded parameter formats. The MessagesController now explicitly validates the \id\ parameter to prevent SQL injection by rejecting non-scalar inputs, and allows the \\_expansions\ parameter to be passed as \true\ to return all available expansion data. The SendController retains its message sending capabilities, including support for raw message submission.

_app/controllers/legacy\api · high confidence

Test coverage

Added comprehensive test coverage for the SMTP server client; Added model tests for Domain, Server, User, and QueuedMessage; Added request specs for message HTML rendering and login redirect validation; Added test coverage for Postal HTTP, configuration, message parsing, and signing components; Added test coverage for core library components; Added test coverage for message dequeuer and worker jobs; Added test coverage for the legacy API endpoints; Added test fixtures for DKIM signing and legacy configuration; Added test helpers and specs for message mocking and HTML escaping; Added tests for HTTP address guard validation; Added tests for SMTP client endpoint and server logic; Added tests for WebhookDeliveryService; Added tests for connection pool retry logic and SQL injection prevention; Added unit tests for SMTP sender connection logic; Initial test suite configuration; Initial test suite for core models and background tasks.

Dependencies

Upgrade to Rails 7.1.6 and Ruby 3.4

The application has been upgraded to Rails 7.1.6, requiring Ruby 3.4. This update brings modern Rails features and security improvements to the core framework. The dependency manifest also includes updates to key libraries such as Authie (v5.0), Haml (v6.3.0), and Puma, ensuring compatibility with the new Rails version and maintaining a secure, up-to-date runtime environment.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 39 → 41 (+2.1)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 96 → 93 (-2.7)
  • Architecture 96 → 85 (-11.0)
  • Maturity 52 → 45 (-7.7)
  • Readiness 14 → 57 (+42.3)
  • Security 48 → 57 (+8.6)
  • Domain Modelling 42 (new)
  • Accessibility 31 (new)

Resolved (31)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (11 lines × 2) (db/migrate/20170418200606_initial_schema.rb)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 11 more

New (108)

  • Client.data (cognitive 21) (app/lib/smtp_server/client.rb)
  • Client.data (cyclomatic 18) (app/lib/smtp_server/client.rb)
  • Client.rcpt_to (cognitive 43) (app/lib/smtp_server/client.rb)
  • Client.rcpt_to (cyclomatic 30) (app/lib/smtp_server/client.rb)
  • Concentrated knowledge decay
  • Critical CVE: [GHSA redacted] (Gemfile.lock)
  • Documentation: no usage examples (README.md)
  • DomainsController.verify (cognitive 20) (app/controllers/domains_controller.rb)
  • Duplicated block (11 lines × 2) (app/controllers/messages_controller.rb)
  • Duplicated block (7 lines × 3) (app/controllers/address_endpoints_controller.rb)
  • Duplicated block (9 lines × 2) (db/migrate/20170418200606_initial_schema.rb)
  • HTTP.request (cognitive 23) (lib/postal/http.rb)
  • HTTP.request (cyclomatic 18) (lib/postal/http.rb)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High CVE: [GHSA redacted] (Gemfile.lock)
  • High IaC: WD-COMPOSE-0002 (docker-compose.yml)
  • …and 88 more

Changes since last survey

  • 2 commits — 1 feature/other, 1 fixes

By area

  • doc/config — 1 commit
  • lib/postal — 1 commit

Notable commits

  • fix: fix: give each worker process a unique locker identity (#3628)
  • change: feat: add configurable Postal logger level defaulting to INFO (#3626)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

postalserver/postal was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ced77a3860c23779889aec8dacd2642f20d10cea — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d0929f7ac71f.