← Back to home
Comparison · Comms

Dovecot vs mailcow

A side-by-side editorial comparison of Dovecot and mailcow — release velocity, themes, recent moves, and the top alternatives to consider.

Dovecot vs mailcow: at a glance

FeatureDovecotmailcow
SectorCommsComms
Velocity score0.05.0
Sparks · 30d00
Top themesmail server, imap, cve cadence, config rewritemail-server, self-hosted, security-updates, docker
Last editorial update12d ago1d ago
WebsiteVisit →Visit →

What is Dovecot?

Dovecot's 2.4 rewrite is still being paid for — twelve CVEs across two releases, two of them 2.4 regressions.

Dovecot 2.4 broke configuration compatibility outright in January 2025 and the line has been stabilizing ever since. The last two releases are dominated by security work: 2.4.3 shipped eight CVEs including SQL and LDAP injection when auth_username_chars is empty — both labelled v2.4 regressions — and 2.4.4 added four more, among them a fakeable CRAM channel binding and an incomplete earlier fix. Alongside that, 2.4.4 permanently drops root privileges in indexer-worker, quota-status and script-login before they serve requests.

Read the full Dovecot trajectory →

What is mailcow?

mailcow's release notes are almost entirely upstream security currency.

mailcow ships named seasonal releases with lettered revisions, and nearly every revision exists to pull in an upstream security fix - Redis, ClamAV, SOGo, Rspamd, nginx, unbound, Postfix. Revision B of the Mooly 2026 release updates Redis 7.4.10, ClamAV 1.4.6, and SOGo 5.12.10, adds minor web UI and nginx hardening, and removes a legacy DeltaChat sieve rule. The last release with genuinely new features was the March cut, which added forced 2FA, ACME DNS-01 challenges, and a passwordless autodiscover endpoint.

Read the full mailcow trajectory →

Dovecot vs mailcow: editorial side-by-side

D
Dovecot
COMMS
0.0

Dovecot's 2.4 rewrite is still being paid for — twelve CVEs across two releases, two of them 2.4 regressions.

◆ Current state

Dovecot 2.4 broke configuration compatibility outright in January 2025 and the line has been stabilizing ever since. The last two releases are dominated by security work: 2.4.3 shipped eight CVEs including SQL and LDAP injection when auth_username_chars is empty — both labelled v2.4 regressions — and 2.4.4 added four more, among them a fakeable CRAM channel binding and an incomplete earlier fix. Alongside that, 2.4.4 permanently drops root privileges in indexer-worker, quota-status and script-login before they serve requests.

◆ Where it's heading

The 2.4 line is a rewrite absorbing its own cost. Dependencies are being replaced rather than pinned — libicu swapped for an in-house unicode library, libpcre2 brought in for regular expressions — and the process model is being tightened, with permanent privilege drops and a reworked service_reuse_port that pre-creates one socket per process. IMAP4rev2 and UTF-8 mail remain behind build flags and config toggles, so the modern-protocol work is real but deliberately unshipped.

◆ Prediction

Expect the CVE cadence to keep tracking the areas the rewrite touched — auth escaping, IMAP parsing limits and the variable expansion introduced in 2.4 — rather than long-settled code. The experimental IMAP4rev2 and mail_utf8 flags are the obvious candidates to graduate once the security churn slows, though nothing in these entries sets a date.

M
mailcow
COMMS
5.0

mailcow's release notes are almost entirely upstream security currency.

◆ Current state

mailcow ships named seasonal releases with lettered revisions, and nearly every revision exists to pull in an upstream security fix - Redis, ClamAV, SOGo, Rspamd, nginx, unbound, Postfix. Revision B of the Mooly 2026 release updates Redis 7.4.10, ClamAV 1.4.6, and SOGo 5.12.10, adds minor web UI and nginx hardening, and removes a legacy DeltaChat sieve rule. The last release with genuinely new features was the March cut, which added forced 2FA, ACME DNS-01 challenges, and a passwordless autodiscover endpoint.

◆ Where it's heading

For a self-hosted mail stack that bundles a dozen upstream components, keeping current with their CVEs is the product, and mailcow has organized its release cadence around exactly that. The pattern is consistent: a named release with some feature content every few months, then lettered revisions that are pure security currency plus small web UI escaping and validation fixes. The web interface is where mailcow's own code gets hardened - HTML escaping in quarantine views and sieve editors recurs across several revisions.

◆ Prediction

Expect the next entry to be another lettered revision carrying upstream updates, with the next named release likely bundling whatever feature work has accumulated since March.

Alternatives to Dovecot and mailcow

Other Comms products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Dovecot or mailcow.

See all Dovecot alternatives → · See all mailcow alternatives →

Recent activity from Dovecot and mailcow

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 1d agomailcow🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision B
  2. 20d agomailcow🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision A
  3. 1mo agomailcow🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3
  4. 2mo agomailcowThird May revision: unbound CVE and nginx 1.30.2
  5. 3mo agomailcowSecond May revision: quarantine table HTML escaping
  6. 3mo agomailcowSOGo 5.12.8 covering four upstream security issues
  7. 3mo agoDovecotFour more CVEs, and root is dropped permanently
  8. 4mo agoDovecotEight CVEs, two of them 2.4 regressions
  9. 9mo agoDovecotlibicu replaced in-house; IMAP4rev2 lands experimental
  10. 1y agoDovecotFirst 2.4 patch, carrying the new signing key
  11. 1y agoDovecotDovecot v2.4.0
  12. 2y agoDovecotHeader limits imposed after CPU exhaustion CVEs

Frequently asked questions

What is the difference between Dovecot and mailcow?

They serve adjacent needs but don't currently overlap on shipped themes. mailcow is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Dovecot better than mailcow?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. mailcow is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Comms products to evaluate alongside.

What are the best alternatives to Dovecot?

Top Dovecot alternatives in Comms are ranked by recent ship velocity. Browse the "Dovecot alternatives" section above for the current picks, or visit /alternatives/dovecot for the full list with editorial commentary on each.

What are the best alternatives to mailcow?

Top mailcow alternatives in Comms are ranked by recent ship velocity. Browse the "mailcow alternatives" section above for the current picks, or visit /alternatives/mailcow for the full list with editorial commentary on each.