← Back to home
Comparison · Comms

mailcow vs Rspamd

A side-by-side editorial comparison of mailcow and Rspamd — release velocity, themes, recent moves, and the top alternatives to consider.

mailcow vs Rspamd: at a glance

FeaturemailcowRspamd
SectorCommsComms
Velocity score5.05.0
Sparks · 30d00
Top themesmail-server, self-hosted, security-updates, dockerspam filtering, input hardening, fuzzy matching, pdf extraction
Last editorial update1d ago2d ago
WebsiteVisit →Visit →

What is mailcow?

mailcow's release notes are almost entirely upstream security currency.

mailcow ships named seasonal releases with lettered revisions, and nearly every revision exists to pull in an upstream security fix - Redis, ClamAV, SOGo, Rspamd, nginx, unbound, Postfix. Revision B of the Mooly 2026 release updates Redis 7.4.10, ClamAV 1.4.6, and SOGo 5.12.10, adds minor web UI and nginx hardening, and removes a legacy DeltaChat sieve rule. The last release with genuinely new features was the March cut, which added forced 2FA, ACME DNS-01 challenges, and a passwordless autodiscover endpoint.

Read the full mailcow trajectory →

What is Rspamd?

Rspamd closed a file-read hole any TCP client could reach, and taught the PDF parser to read fonts.

Rspamd's 4.1.x line is running two tracks at once: extending the neural and fuzzy subsystems it rebuilt earlier in the cycle, and auditing its own attack surface. 4.1.5 continues both — fuzzy storages now receive sender authentication facts over encrypted rules, the PDF parser decodes text through font encodings and ToUnicode CMaps, and the protocol gates File, Path and Shm message sources that any TCP client could previously use to have arbitrary files parsed. That gate ships as an opt-out now and an opt-in later.

Read the full Rspamd trajectory →

mailcow vs Rspamd: editorial side-by-side

M
mailcow
COMMS
5.0

mailcow's release notes are almost entirely upstream security currency.

◆ Current state

mailcow ships named seasonal releases with lettered revisions, and nearly every revision exists to pull in an upstream security fix - Redis, ClamAV, SOGo, Rspamd, nginx, unbound, Postfix. Revision B of the Mooly 2026 release updates Redis 7.4.10, ClamAV 1.4.6, and SOGo 5.12.10, adds minor web UI and nginx hardening, and removes a legacy DeltaChat sieve rule. The last release with genuinely new features was the March cut, which added forced 2FA, ACME DNS-01 challenges, and a passwordless autodiscover endpoint.

◆ Where it's heading

For a self-hosted mail stack that bundles a dozen upstream components, keeping current with their CVEs is the product, and mailcow has organized its release cadence around exactly that. The pattern is consistent: a named release with some feature content every few months, then lettered revisions that are pure security currency plus small web UI escaping and validation fixes. The web interface is where mailcow's own code gets hardened - HTML escaping in quarantine views and sieve editors recurs across several revisions.

◆ Prediction

Expect the next entry to be another lettered revision carrying upstream updates, with the next named release likely bundling whatever feature work has accumulated since March.

R
Rspamd
COMMS
5.0

Rspamd closed a file-read hole any TCP client could reach, and taught the PDF parser to read fonts.

◆ Current state

Rspamd's 4.1.x line is running two tracks at once: extending the neural and fuzzy subsystems it rebuilt earlier in the cycle, and auditing its own attack surface. 4.1.5 continues both — fuzzy storages now receive sender authentication facts over encrypted rules, the PDF parser decodes text through font encodings and ToUnicode CMaps, and the protocol gates File, Path and Shm message sources that any TCP client could previously use to have arbitrary files parsed. That gate ships as an opt-out now and an opt-in later.

◆ Where it's heading

Every release in this window has carried at least one security fix in the same class: a controller accepting any password on a malformed hash, a DKIM out-of-bounds read, MIME recursion depth, and now unauthenticated file reads. The project is systematically walking its own input paths rather than reacting to individual reports. Alongside it, the fuzzy subsystem keeps gaining structure — diagnostics, persisted shingle sets, and now shared sender reputation signals — turning what was a hash-match check into a scored, introspectable component.

◆ Prediction

The stated plan to flip allow_file_and_shm_inputs to false in the next major release makes that the visible breaking change to prepare for. Expect the fuzzy work to keep consolidating, since sharing SPF, DKIM and DMARC state with storages sets up cross-sender scoring that the current per-hash matching cannot express.

Alternatives to mailcow and Rspamd

Other Comms products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either mailcow or Rspamd.

See all mailcow alternatives → · See all Rspamd alternatives →

Recent activity from mailcow and Rspamd

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 1d agomailcow🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision B
  2. 4d agoRspamdCloses an arbitrary file read reachable by any TCP client
  3. 20d agomailcow🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision A
  4. 21d agoRspamdController accepted any password on a malformed hash
  5. 24d agoRspamdFuzzy diagnostics API, and jQuery dropped from the WebUI
  6. 28d agoRspamdStatic embedding neural provider and composite Lua conditions
  7. 1mo agomailcow🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3
  8. 2mo agoRspamdPluggable neural feature and architecture registries
  9. 2mo agoRspamdLoad-aware upstream selection and chain-aware URL resolution
  10. 2mo agomailcowThird May revision: unbound CVE and nginx 1.30.2
  11. 3mo agomailcowSecond May revision: quarantine table HTML escaping
  12. 3mo agomailcowSOGo 5.12.8 covering four upstream security issues

Frequently asked questions

What is the difference between mailcow and Rspamd?

They serve adjacent needs but don't currently overlap on shipped themes. mailcow and Rspamd are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is mailcow better than Rspamd?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. mailcow and Rspamd are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Comms products to evaluate alongside.

What are the best alternatives to mailcow?

Top mailcow alternatives in Comms are ranked by recent ship velocity. Browse the "mailcow alternatives" section above for the current picks, or visit /alternatives/mailcow for the full list with editorial commentary on each.

What are the best alternatives to Rspamd?

Top Rspamd alternatives in Comms are ranked by recent ship velocity. Browse the "Rspamd alternatives" section above for the current picks, or visit /alternatives/rspamd for the full list with editorial commentary on each.