mailcow

mailcow.email
mailcow

A mail server with everything you need (SMTP, IMAP, webmail, NextCloud support..) using Docker.

Open Source

mailcow Source Code

Author

mailcow

Description

mailcow: dockerized - 🐮 + 🐋 = 💕

#acme#clamav#docker#docker-compose#dovecot#groupware#hacktoberfest#imap#mail#mailcow#mailserver#olefy#postfix#rspamd#servercow#smtp#sogo

Homepage

https://mailcow.email

Repository

  • LicenseGPL-3.0
  • Created09 Dec 16
  • Primary languageJavaScript
  • Size50,077 KB
  • Stars13,316
  • Forks1,780
  • Watchers13,316

Language Usage

Language Usage

Project Health

  • Last commit10 days ago
  • Open issues502
  • Latest release2026-07

Recent Commits

  • FreddleSpl0it(18 Aug 26)

    Merge pull request #7427 from mailcow/staging Update 2026-07b

  • FreddleSpl0it(18 Aug 26)

    Merge pull request #7426 from mailcow/fix/web-hardening [Web] Minor hardening across web UI and nginx

  • FreddleSpl0it(18 Aug 26)

    [Web] Minor hardening across web UI and nginx

  • FreddleSpl0it(18 Aug 26)

    Merge pull request #7425 from mailcow/feat/redis-7.4.10 [Redis] Update to 7.4.10

  • FreddleSpl0it(18 Aug 26)

    [Redis] Update to 7.4.10

  • FreddleSpl0it(17 Aug 26)

    Merge pull request #7423 from mailcow/fix/7418 [Dovecot] Remove legacy DeltaChat auto-filing sieve rule

  • FreddleSpl0it(17 Aug 26)

    [Dovecot] Remove legacy DeltaChat auto-filing sieve rule

  • FreddleSpl0it(17 Aug 26)

    Merge pull request #7422 from mailcow/feat/sogo-5.12.10 [SOGo] Update to 5.12.10

  • FreddleSpl0it(17 Aug 26)

    [SOGo] Update to 5.12.10

  • FreddleSpl0it(13 Aug 26)

    Merge pull request #7415 from mailcow/feat/clamd-1.4.6 [Clamd] Update to 1.4.6

  • FreddleSpl0it(13 Aug 26)

    [Clamd] Update to 1.4.6

  • FreddleSpl0it(05 Aug 26)

    Merge pull request #7393 from mailcow/staging update README.md sponsors

  • milkmaker(04 Aug 26)

    Translations update from Weblate (#7400) * [Web] Updated lang.si-si.json Co-authored-by: Matjaž Tekavec <[email protected]> Co-authored-by: milkmaker <[email protected]> * [Web] Updated lang.pt-br.json Co-authored-by: André Glazastov <[email protected]> --------- Co-authored-by: Matjaž Tekavec <[email protected]> Co-authored-by: André Glazastov <[email protected]>

  • milkmaker(04 Aug 26)

    update postscreen_access.cidr (#7394)

  • Maximal Benedikt(30 Jul 26)

    Merge pull request #7392 from mailcow/update-sponsoring update README.md sponsors

  • MaximalBenedikt(30 Jul 26)

    update README.md sponsors

  • FreddleSpl0it(30 Jul 26)

    Merge pull request #7391 from mailcow/staging Update 2026-07a

  • FreddleSpl0it(30 Jul 26)

    Merge pull request #7390 from mailcow/fix/6859 [ACME] Skip mta-sts certificate request when MTA-STS is not active for a domain

  • FreddleSpl0it(30 Jul 26)

    [ACME] Skip mta-sts certificate request when MTA-STS is not active for a domain

  • FreddleSpl0it(30 Jul 26)

    Merge pull request #7389 from mailcow/fix/default-mbox-template [Web] Create default mailbox template with eas and dav access

  • FreddleSpl0it(30 Jul 26)

    Merge pull request #7388 from mailcow/fix/7329 [Web] Move mailcow update check to server side

  • FreddleSpl0it(30 Jul 26)

    Merge pull request #7387 from mailcow/fix/mfk25 Hardening mailcow

  • FreddleSpl0it(30 Jul 26)

    Merge pull request #7386 from mailcow/feat/rspamd-4.1.4 [Rspamd] update to 4.1.4

  • FreddleSpl0it(30 Jul 26)

    [Nginx] Set image tag to 1.30.4-1

  • FreddleSpl0it(30 Jul 26)

    [Rspamd] update to 4.1.4

  • FreddleSpl0it(30 Jul 26)

    Merge pull request #7385 from mailcow/fix/cors [Web] harden CORS origin matching and add Vary: Origin

  • FreddleSpl0it(30 Jul 26)

    [Web] harden CORS origin matching and add Vary: Origin

  • FreddleSpl0it(28 Jul 26)

    Merge pull request #7333 from fallmo/fix/cors-settings-validation fix: cors allowed origins settings validation

  • FreddleSpl0it(28 Jul 26)

    Merge pull request #7358 from SYNLINQ/staging Fix nginx CVE-2026-42533

  • FreddleSpl0it(28 Jul 26)

    [Web] document sender_acl in get/mailbox API examples

mailcow Security

5.7/10

Repo Security Summary

Updated 17 Aug 26

  • Maintained10/10
  • Code-Review3/10
  • Security-Policy10/10
  • Dangerous-Workflow10/10
  • Token-Permissions0/10
  • CII-Best-Practices0/10
  • Binary-Artifacts10/10
  • License10/10
  • Signed-ReleasesN/A
  • Branch-ProtectionN/A
  • Fuzzing0/10
  • SAST0/10
  • Packaging10/10
  • Pinned-Dependencies0/10

Security Advisories (22)

  • lowPatched

    CVE-2026-40878Reflected Parameter Injection / Wrong-Context XSS Escaping in mailcow-dockerized Login Page

  • highPatchedCVSS 7.2

    CVE-2026-40871Second Order SQL Injection in quarantine category via API

  • criticalPatched

    CVE-2026-40872Stored XSS in autodiscover logs email address field

  • highPatched

    CVE-2026-40873Stored XSS in Quarantine attachment filenames

  • mediumPatched

    CVE-2026-40874Missing authorization on Forwarding Hosts delete action

  • highPatched

    CVE-2026-40875Stored XSS in user login history real_rip

  • criticalPatchedCVSS 9.1

    CVE-2025-53909SSTI in Quota and Quarantine Notification Template

  • highPatchedCVSS 7.1

    CVE-2025-25198Password reset poisoning

  • highPatchedCVSS 7

    CVE-2024-56529Session Fixation on mailcow web panel

  • lowPatchedCVSS 3.8

    CVE-2024-41960XSS Vulnerability via Relay Hosts Configuration

  • highPatchedCVSS 7.6

    CVE-2024-41959XSS Vulnerability via API Logs

  • mediumPatchedCVSS 6.6

    CVE-2024-41958Two-Factor Authentication (2FA) Bypass Vulnerability

  • mediumPatchedCVSS 6.8

    CVE-2024-31204XSS Vulnerability via Exception Handler

  • mediumPatchedCVSS 6.7

    CVE-2024-30270Path Traversal and Arbitrary Code Execution Vulnerability

  • highPatchedCVSS 8.8

    CVE-2024-24760Docker Container Exposure to Local Network

  • mediumPatchedCVSS 4.7

    CVE-2024-23824Pixel flood attack leads to Denial of Service in admin page

  • highPatchedCVSS 8.3

    CVE-2023-49077XSS Vulnerability in Quarantine UI Allows Unauthorized Access and Data Manipulation

  • highPatchedCVSS 8.8

    CVE-2023-34108Manipulation of Internal Dovecot Variables in mailcow via crafted Passwords

  • highPatched

    CVE-2023-26490Shell command injection via xoauth2 authentication in imapsync​

  • mediumPatched

    CVE-2022-39258Possible Phishing attacks through Swagger UI

  • criticalPatched

    CVE-2022-31138CVE-2022-31138: IMAPSYNC (Syncjobs) Debug Extended Rights (hidden options)

  • criticalPatched

    CVE-2022-31245CVE-2022-31245: IMAPSYNC (Syncjobs) Debug Extended Rights (pipemess)

mailcow Website

Website

mailcow: dockerized - Blog

The mailserver suite with the 'moo' – 🐮 + 🐋 = 💕 | Official Blog Page

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address185.199.110.153
  • Hostnamecdn-185-199-110-153.github.com
  • LocationFrancisco,Indiana,United States of America,NA
  • ISPGitHub Inc.
  • ASNAS54113

Associated Countries

  • DEDE
  • USUS

Safety Score

Website marked as safe

100%

Blacklist Check

mailcow.email was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

mailcow Reviews

More Mail Servers

About the Data: mailcow

Change History

Edit mailcow Data

You can edit mailcow's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external sources, a list of these can be found data documentation.

Origin Data

Modify Data

API

You can access mailcow's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/mailcow

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share mailcow

Help your friends compare Mail Servers, and pick privacy-respecting software and services.
Share mailcow and Awesome Privacy with your network!