← Back to home
Comparison · Comms

Rspamd vs Dovecot

A side-by-side editorial comparison of Rspamd and Dovecot — release velocity, themes, recent moves, and the top alternatives to consider.

Rspamd vs Dovecot: at a glance

FeatureRspamdDovecot
SectorCommsComms
Velocity score5.00.0
Sparks · 30d00
Top themesspam filtering, neural registries, fuzzy matching, resource boundingmail server, imap, cve cadence, config rewrite
Last editorial update2h ago1d ago
WebsiteVisit →Visit →

What is Rspamd?

Rspamd is rebuilding its neural filter into a pluggable framework — and just fixed a controller that accepted any password.

The 4.1.x series has moved fast on two fronts. The neural plugin gained pluggable feature-provider and ANN-architecture registries, multi-head attention pooling, slice and concat graph transforms, and a static_embed provider running a WordPiece subword tokenizer over a static embedding matrix. Separately the fuzzy subsystem got structured match results with a diagnostics API, Redis-persisted shingle sets and per-hash introspection. 4.1.4 in July fixed a critical controller bug where a malformed password hash caused it to fail open and accept any password, alongside a set of PCRE2 leaks and unbounded-match conditions in the regexp engine.

Read the full Rspamd trajectory →

What is Dovecot?

Dovecot's 2.4 rewrite is still being paid for — twelve CVEs across two releases, two of them 2.4 regressions.

Dovecot 2.4 broke configuration compatibility outright in January 2025 and the line has been stabilizing ever since. The last two releases are dominated by security work: 2.4.3 shipped eight CVEs including SQL and LDAP injection when auth_username_chars is empty — both labelled v2.4 regressions — and 2.4.4 added four more, among them a fakeable CRAM channel binding and an incomplete earlier fix. Alongside that, 2.4.4 permanently drops root privileges in indexer-worker, quota-status and script-login before they serve requests.

Read the full Dovecot trajectory →

Rspamd vs Dovecot: editorial side-by-side

R
Rspamd
COMMS
5.0

Rspamd is rebuilding its neural filter into a pluggable framework — and just fixed a controller that accepted any password.

◆ Current state

The 4.1.x series has moved fast on two fronts. The neural plugin gained pluggable feature-provider and ANN-architecture registries, multi-head attention pooling, slice and concat graph transforms, and a static_embed provider running a WordPiece subword tokenizer over a static embedding matrix. Separately the fuzzy subsystem got structured match results with a diagnostics API, Redis-persisted shingle sets and per-hash introspection. 4.1.4 in July fixed a critical controller bug where a malformed password hash caused it to fail open and accept any password, alongside a set of PCRE2 leaks and unbounded-match conditions in the regexp engine.

◆ Where it's heading

The neural work is the strategic thread: turning a fixed classifier into a registry where feature extraction and network architecture are both swappable is what lets learned filtering evolve without forking the daemon. Around it, the project is systematically bounding resource use under adversarial input — regexp heap limits, zip-bomb extraction caps, per-message word budgets, a Lua URL filter consulted twice per field instead of once per byte. The front end is being simplified in the opposite direction, with jQuery, Font Awesome and FooTable all removed outright.

◆ Prediction

The registries and the static embedding provider arrived one release apart, so the piece not yet visible in these notes is a shipped model that uses them. Whether Rspamd distributes one or leaves it to operators is not indicated here.

D
Dovecot
COMMS
0.0

Dovecot's 2.4 rewrite is still being paid for — twelve CVEs across two releases, two of them 2.4 regressions.

◆ Current state

Dovecot 2.4 broke configuration compatibility outright in January 2025 and the line has been stabilizing ever since. The last two releases are dominated by security work: 2.4.3 shipped eight CVEs including SQL and LDAP injection when auth_username_chars is empty — both labelled v2.4 regressions — and 2.4.4 added four more, among them a fakeable CRAM channel binding and an incomplete earlier fix. Alongside that, 2.4.4 permanently drops root privileges in indexer-worker, quota-status and script-login before they serve requests.

◆ Where it's heading

The 2.4 line is a rewrite absorbing its own cost. Dependencies are being replaced rather than pinned — libicu swapped for an in-house unicode library, libpcre2 brought in for regular expressions — and the process model is being tightened, with permanent privilege drops and a reworked service_reuse_port that pre-creates one socket per process. IMAP4rev2 and UTF-8 mail remain behind build flags and config toggles, so the modern-protocol work is real but deliberately unshipped.

◆ Prediction

Expect the CVE cadence to keep tracking the areas the rewrite touched — auth escaping, IMAP parsing limits and the variable expansion introduced in 2.4 — rather than long-settled code. The experimental IMAP4rev2 and mail_utf8 flags are the obvious candidates to graduate once the security churn slows, though nothing in these entries sets a date.

Alternatives to Rspamd and Dovecot

Other Comms products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Rspamd or Dovecot.

See all Rspamd alternatives → · See all Dovecot alternatives →

Recent activity from Rspamd and Dovecot

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 9d agoRspamdController accepted any password on a malformed hash
  2. 12d agoRspamdFuzzy diagnostics API, and jQuery dropped from the WebUI
  3. 16d agoRspamdStatic embedding neural provider and composite Lua conditions
  4. 1mo agoRspamdPluggable neural feature and architecture registries
  5. 2mo agoRspamdLoad-aware upstream selection and chain-aware URL resolution
  6. 2mo agoDovecotFour more CVEs, and root is dropped permanently
  7. 3mo agoDovecotEight CVEs, two of them 2.4 regressions
  8. 4mo agoRspamdProxy milter fd leak and ARC multi-hop parsing fixed
  9. 9mo agoDovecotlibicu replaced in-house; IMAP4rev2 lands experimental
  10. 1y agoDovecotFirst 2.4 patch, carrying the new signing key
  11. 1y agoDovecotDovecot v2.4.0
  12. 1y agoDovecotHeader limits imposed after CPU exhaustion CVEs

Frequently asked questions

What is the difference between Rspamd and Dovecot?

They serve adjacent needs but don't currently overlap on shipped themes. Rspamd is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Rspamd better than Dovecot?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Rspamd is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Comms products to evaluate alongside.

What are the best alternatives to Rspamd?

Top Rspamd alternatives in Comms are ranked by recent ship velocity. Browse the "Rspamd alternatives" section above for the current picks, or visit /alternatives/rspamd for the full list with editorial commentary on each.

What are the best alternatives to Dovecot?

Top Dovecot alternatives in Comms are ranked by recent ship velocity. Browse the "Dovecot alternatives" section above for the current picks, or visit /alternatives/dovecot for the full list with editorial commentary on each.