← Back to home
Comparison · Comms

Maddy vs mailcow

A side-by-side editorial comparison of Maddy and mailcow — release velocity, themes, recent moves, and the top alternatives to consider.

Shared themes:mail-serverself-hosted

Maddy vs mailcow: at a glance

FeatureMaddymailcow
SectorCommsComms
Velocity score0.05.0
Sparks · 30d00
Top themesmail-server, self-hosted, golang, zero-downtime-reloadmail-server, self-hosted, cve-response, xss-hardening
Last editorial update1h ago2h ago
WebsiteVisit →Visit →

What is Maddy?

A one-binary mail server learning to behave like production infrastructure.

maddy is an all-in-one SMTP and IMAP server written in Go, aimed at people who want a working mail host without assembling Postfix, Dovecot and a policy daemon themselves. The 0.9 line moved quickly — 0.9.0 through 0.9.5 between late March and late May — with the sequence following a recognisable shape: a feature release, an immediate patch for a broken integration, a security release, then cleanup. Configuration is directive-based, and much of the changelog concerns the behaviour of individual modules like auth.ldap, check.rspamd and check.dnsbl.

Read the full Maddy trajectory →

What is mailcow?

Six releases, and every one of them is a security update in some form.

mailcow ships on a monthly tag with lettered revisions, and this window contains no release that isn't security-driven. The May line ran to three revisions in two weeks — an unnamed fix with a CVE identifier withheld until later, SOGo 5.12.8 covering four upstream issues, an unbound CVE, HTML escaping added to the quarantine table, sieve filter editor and queue manager. July brought Rspamd 4.1.0 and later 4.1.4, nginx 1.30.3 and a CVE fix, Postfix moved off bookworm, and a release described only as hardening.

Read the full mailcow trajectory →

Maddy vs mailcow: editorial side-by-side

M
Maddy
COMMS
0.0

A one-binary mail server learning to behave like production infrastructure.

◆ Current state

maddy is an all-in-one SMTP and IMAP server written in Go, aimed at people who want a working mail host without assembling Postfix, Dovecot and a policy daemon themselves. The 0.9 line moved quickly — 0.9.0 through 0.9.5 between late March and late May — with the sequence following a recognisable shape: a feature release, an immediate patch for a broken integration, a security release, then cleanup. Configuration is directive-based, and much of the changelog concerns the behaviour of individual modules like auth.ldap, check.rspamd and check.dnsbl.

◆ Where it's heading

The project is systematically removing the compromises that made early versions convenient. Obsolete SASL LOGIN was disabled by default, the STARTTLS plaintext fallback was dropped, the maddyctl symlink behaviour and the implicit run command were deleted after four years of deprecation warnings, and libdns providers that have not kept up with 1.x are being cut. Running the other way is operational maturity: no-downtime config reload, queue-length metrics, OpenMetrics fixes, systemd readiness reporting, and SLSA build attestations on release artifacts. This is a project moving from hobbyist-friendly to operator-friendly, and accepting breakage to get there.

◆ Prediction

0.10.0 is already scoped by the deprecations announced in 0.9.1 — expect the flagged libdns providers to be removed and gandi to require Bearer tokens. Given the 0.9.x pattern, a feature release followed quickly by an integration fix is the likely shape.

M
mailcow
COMMS
5.0

Six releases, and every one of them is a security update in some form.

◆ Current state

mailcow ships on a monthly tag with lettered revisions, and this window contains no release that isn't security-driven. The May line ran to three revisions in two weeks — an unnamed fix with a CVE identifier withheld until later, SOGo 5.12.8 covering four upstream issues, an unbound CVE, HTML escaping added to the quarantine table, sieve filter editor and queue manager. July brought Rspamd 4.1.0 and later 4.1.4, nginx 1.30.3 and a CVE fix, Postfix moved off bookworm, and a release described only as hardening.

◆ Where it's heading

Two distinct pressures are visible. One is upstream: mailcow bundles Postfix, Rspamd, SOGo, nginx, unbound and Dovecot, so every one of their advisories becomes a mailcow release, and the base image migration from bookworm to trixie is that same maintenance surfacing at the OS layer. The other is the project's own web UI, where output escaping is being retrofitted view by view — quarantine table, sieve editor, queue manager, quarantine overview — which reads as a systematic pass rather than isolated reports. Earlier releases in the feed show where feature work went when it happened: forced 2FA, ACME DNS-01 challenges, and admin controls over EAS and DAV access.

◆ Prediction

Expect the monthly-plus-revisions rhythm to continue with upstream component bumps driving most of it, and the web UI escaping pass to reach the remaining admin views.

Alternatives to Maddy and mailcow

Other Comms products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Maddy or mailcow.

See all Maddy alternatives → · See all mailcow alternatives →

Recent activity from Maddy and mailcow

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 2d agomailcow🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision A
  2. 19d agomailcow🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3
  3. 2mo agomailcowThird May revision: unbound CVE and nginx 1.30.2
  4. 2mo agoMaddymaddy 0.9.5 fixes nested pipeline logging and systemd reload reporting
  5. 2mo agomailcowSecond May revision: quarantine table HTML escaping
  6. 2mo agomailcowSOGo 5.12.8 covering four upstream security issues
  7. 2mo agomailcowMay base release: undisclosed CVE plus web UI escaping
  8. 3mo agoMaddymaddy 0.9.4 removes the maddyctl symlink and implicit run command
  9. 3mo agoMaddymaddy 0.9.3 patches an LDAP injection flaw in auth.ldap
  10. 4mo agoMaddymaddy 0.9.2 fixes an rspamd panic on unspecified tls_client
  11. 4mo agoMaddymaddy 0.9.1 flags libdns providers for removal in 0.10.0
  12. 4mo agoMaddymaddy 0.9.0 adds no-downtime configuration reloading

Frequently asked questions

What is the difference between Maddy and mailcow?

Both compete on the same themes — mail-server, self-hosted — within Comms. mailcow is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Maddy better than mailcow?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. mailcow is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Comms products to evaluate alongside.

What are the best alternatives to Maddy?

Top Maddy alternatives in Comms are ranked by recent ship velocity. Browse the "Maddy alternatives" section above for the current picks, or visit /alternatives/maddy for the full list with editorial commentary on each.

What are the best alternatives to mailcow?

Top mailcow alternatives in Comms are ranked by recent ship velocity. Browse the "mailcow alternatives" section above for the current picks, or visit /alternatives/mailcow for the full list with editorial commentary on each.