MDaemon Release Notes
MDaemon Server v18.0 Release Notes
MDaemon 18.0.2 - June 12, 2018
 Hosted email options with MDaemon Private Cloud are now available. To learn more, please visit:
CHANGES AND NEW FEATURES
-  MDaemon Connector has been updated to version 5.5.2.
-  The MDaemon GUI does not display the toolbar at startup after it has been
closed. Select Windows | Reset Toolbar to get it back.
-  Webmail - Added address validation to the default reply-to address field
in Options | Compose
-  fix to LookOut and WorldClient themes - Cannot use dot (.) in folder names
-  fix to MDaemon-Statistics database grows boundlessly due to Message Log
parsing feature and causes high processor usage in Remote Admin
-  fix to MDRA - Dropbox - Using this dialog to add the App Key and App
Secret saves the data with a different salt each time
-  fix to Webmail - Dropbox - Cannot save email attachments to Dropbox
-  fix to MD UI issues with the Start Time column on the Sessions pane
-  fix to Active Webmail Sessions performance counter is not always updated
-  fix to truncated DNS response when doing reverse lookup may cause mail to be
-  fix to MDRA - Webmail sessions listed as "WorldClient" instead of
-  fix to Webmail - "permanently delete" notification not translated
-  fix to Webmail - Creating an event from a message changes & to &
-  fix to Webmail - Creating an event from an HTML message results in
styles showing up in the notes
-  fix to MDRA - Unable to edit a mailing list with a name that starts with
-  fix to LookOut theme - Long subject causes unexpected behavior when
forwarding as attachment
-  fix to LookOut theme - Vertical scroll bar is not reset when switching
to the next page of messages
-  fix to possible Webmail crash
-  fix to MDRA - Some default list outputs are not translated
-  fix to MDaemon server may hang while upgrading the statistics database
-  fix to Webmail - X-Mailer header in sent messages is "WorldClient"
-  fix to ActiveSync sessions not displaying in MD Configuration Session
-  fix to Webmail - PIM item attachments are not copied with the PIM item when it
is moved or copied to another folder
-  fix to Webmail - Cannot upload a picture to a contact
-  fix to MDRA - Multiple submission addresses can be added to the same
-  fix to Webmail - When common_contacts.json file contains null values,
autocomplete stops returning queries
-  fix to MDPGP --pgpk not always honoring disable checkbox and also fixing
a case-sensitivity issue
-  fix to Webmail - After setting a category on a message, sort order is
changed to category
-  fix to Webmail - Import EML with no subject results in an error message
but the message is still imported
-  fix to MDRA - possible high CPU usage
-  fix to Webmail - Removing the snooze from a categorized message also
removes the category, and adding a category to a message might cause the message
to be snoozed.
-  fix to MDRA - "Limit Simultaneous connections by IP to" can only be set
to zero or 1
-  fix to Dynamic Screening does not honor the setting "Ignore authentication
attempts using identical passwords"
-  fix to Content Filter may duplicate attachments extracted from winmail.dat
-  fix to missing client information on the ActiveSync wipe confirmation dialog
-  fix to calendar notes created on iPhone will not sync to server
-  fix to LookOut and WorldClient themes - the day view does not auto
scroll to 7 am in non side by side view
-  fix to "To address is missing" appears in "send note" content
filter rules created by MDRA
-  fix to meeting requests generated by MDaemon Webmail are not automatically
accepted by Exchange servers
-  fix to MDaemon adding Kaspersky URLs to \MDaemon\SecurityPlus\antivirus.ini
on a clean install
-  fix to Dynamic Screening may re-freeze an unfrozen account after a single
-  fix to ActiveSync changes to tasks are not synced to MDaemon Connector
-  fix to a user may be able to post to a mailing list when they do not have
rights to post
-  fix to old TarpitConnect.dat entries are not removed
-  fix to possible crash in MDAirSync.dll
-  fix to possible CFEngine.exe crash
MDaemon 18.0.1 - May 15, 2018
CHANGES AND NEW FEATURES
-  MDaemon Connector has been updated to version 5.5.1. Please see what changed in MDaemon Connector 5.5.1 here:
-  The "Registration Information" screens have been removed from the MDaemon
installer. The MDaemon GUI now asks for this information when it starts up for
the first time and whenever the registration key or major version number changes.
-  fix to possible Webmail crash when deleting meeting occurrences
-  fix to AntiVirus error message is logged at MDaemon startup on systems that
have never used AV
-  fix to SMTP MSA port may require STARTTLS even when STARTTLS is disabled
-  fix to Remote Administration text editor removes the first 3 characters of
signatures and administrator notes
-  fix to some MDaemon Connector features are not disabled when using an expired
MDaemon Connector registration key
-  fix to PGP related vulnerability as described at https://efail.de/
MDaemon 18.0.0 - April 17, 2018
 Alt-N Technologies has changed its name to MDaemon Technologies. WorldClient
is now MDaemon Webmail, WorldClient Instant Messenger is now MDaemon Instant Messenger,
SecurityPlus is now MDaemon Antivirus, and Outlook Connector is now MDaemon Connector.
 The MDaemon installer now includes MDaemon AntiVirus and MDaemon Connector, which
are licensed separately.
 The "From Header Modification" feature has changed. It operates as before
however the format of the final modified From data has changed from this format:
"Email -- Name" <Email> to this format: "Name (Email)" <Email>. This new
format is more readable/usable/sortable etc. If you would rather keep the
old format (your users may be used to it already) you can check a box at Ctrl+S|Screening|Hijack Detection|From Header Modification.
 A past installer reset the option "Ctrl+S|Sender Authentication|SMTP
Authentication|Authentication is always required when mail is sent from local
IPs" to disabled for upgraders. The installer has been changed to ignore
this setting. You must manually check that this option is set to your
desire. The default is for it to be checked (enabled) but you should check
to be sure it is set how you want.
 The following settings have had default values changed. Existing
installations should check to be sure the following settings are as desired:
Ctrl+S|Security Settings|SSL & TLS|MDaemon: Enable the dedicated SSL
ports... and SMTP server requires STARTTLS... options have had defaults changed
from disabled to enabled. Ctrl+S|Security Settings|Sender Authentication|DMARC
verification|Honor p=reject... has changed from disabled to enabled. Ctrl+S|
Security Settings|Sender Authentication|SPF Verification|User local address
in SMTP envelope...has changed from disabled to enabled. Ctrl+S|Security Settings|
Screening|IP Screen|Apply IP Screen to MSA connections has changed from disabled
to enabled. Ctrl+S|Security Settings|Screening|Host Screen|Drop connection after
EHLO has changed from disabled to enabled.
 Catalog functionality has been deprecated and removed from the UI.
 All Virtru related support has been removed from MDaemon Webmail. Old
encrypted messages can still be viewed in the Virtru Secure Reader.
 Previously when a message was sent to an alias, MDPGP would encrypt it using the
key for the actual email address. Now that same message won't be encrypted. To encrypt
it now requires a key for the alias.
MAJOR NEW FEATURES
Ctrl+S|SSL&TLS|DNSSEC allows you to request DNSSEC service from your DNS server(s).
When enabled, MDaemon sets the AD bit when making DNS queries and checks for it in
the answers. This may not work with all DNS server(s) (not sure) so you'll have to
try with yours. DNSSEC service is only applied to messages that meet your
criteria. DNSSEC service can be "requested" or "required" on a per-message basis. If "required" and DNS
results fail to include authenticated data then the message is bounced back to sender.
If "requested" then DNSSEC service is attempted but nothing happens if it fails.
Mail session logs will include a line at the top if DNSSEC service was used
and "DNSSEC" will appear next to secure data in the logs.
IMPORTANT: MDaemon is a non-validating stub-resolver. This means that it will request
authenticated data from DNS server(s) but it has no way to independently verify that
the data it gets from them is secure. However, if you know/trust your connection to
your DNS server(s) (for example, it runs on localhost or within a secure LAN or workplace) then you should use this as it will boost security.
DNSSEC lookups take more time and resource and I think less then 7% of domains have
currently deployed it. That is why this is not configured to apply to every
message delivery by
default. However, if you want that, you can force every email sent to use DNSSEC by adding
one line like "To *" into the configuration file (see Ctrl+S|SSL&TLS|DNSSEC).
 Email Snooze
MDaemon Webmail was updated to allow a user to snooze an email. When a message is snoozed
it will be hidden from the user for a designated period of time. To snooze a message,
right click on it and choose the "Snooze for..." option in the context menu.
Then choose how long you wish to snooze the message for. The "Choose a date and time"
option is only available for browsers that support the date and time inputs. Hidden messages
can be viewed in LookOut theme by clicking the "View Snoozed Messages" icon in
the toolbar and WorldClient theme by choosing "view snoozed" from the view drop
down menu in the toolbar. This feature is on by default. To turn off the feature, go to
Options | Personalize, and find the Inbox Settings. Uncheck the "Enable Message Snooze" box.
There are no snooze controls in Lite and Mobile theme, but snoozed messages are
 Public Calendars
In MDaemon Webmail users can publish a calendar to a publicly accessible link. Users have the
option to password protect the calendar. To disable this globally, change the value of
[Default:Settings] EnablePublicCalendars to No. To disable it on a per user basis, add
CanPublishCalendars=No to a user's User.ini file. To publish a calendar, in LookOut or
WorldClient theme, go to Options | Folders and click the "Share Folder" button next
to the calendar you wish to publish. In the dialog, open the Public Access tab and if desired,
fill in the display name or require a password, then click the "Publish Calendar" button.
A confirm dialog will show up to tell the user what is about to happen. After clicking OK,
an alert will display the new URL where the calendar is available. There will also be a link
displayed on the page once the calendar has been published. To unpublish the calendar, click the
"Unpublish Calendar" button. To change the password or the display name, click the
 Remember Me
A "Remember Me" option has been added to the logon page of MDaemon Webmail.
This feature is disabled by default. The default expiration is 30 days, and the
maximum expiration setting is 365 days. It can be enabled in the MDRA GUI under Main->Webmail Settings->Settings. Users can
check the "Remember Me" option on the logon page to be remembered on a specific
device. Then if they have a bookmark with any of three View URL variables set (View=Main,
View=Logon, or View=List) (or no View URL variable set), the user will be automatically logged
in. Two Factor Authentication (2FA) is separate and will still be required when the 2FA remember
me token expires.
 "Remember Me" was also added to the Remote Administration logon page.
This feature is disabled by default. The default expiration is 30 days, and the
maximum expiration setting is 365 days. It can be enabled in the MDRA GUI under
Main->Remote Admin Settings->Settings. Users can check the "Remember Me" option
on the logon page to be remembered on a specific device. Two Factor
Authentication (2FA) is separate and will still be required when the 2FA remember me token expires.
 Exempt Known ActiveSync Devices from Location Screening
An option has been added to allow a previously known ActiveSync device to bypass location screening.
Administrators can enable this option to allow users to continue to access their account via ActiveSync from
a location that is configured to block authentication attempts. In order to exempt the device it
must have connected and authenticated using ActiveSync within the time frame configured to remove
inactive clients. To exempt a device go to Setup / Mobile Device Management / Clients, select the client
and click Settings, then check the box for Exempt from Location Screening.
You can also choose to Whitelist the address the client is connecting from. This can be used to allow other clients
that might be connecting from the same IP address to also bypass location screening.
CHANGES AND NEW FEATURES
-  Added ability to specify which protocols use Location Screening.
-  LookOut and WorldClient themes - Added PIM attachments for Contacts, Tasks, and Notes
-  IP and Host Screening UI previously shared controls at the bottom of
their configuration screens but now the items related to IP Screening will be on
the IP Screening screen and the Host Screening on the Host Screening screen (can
I say screen one more time).
-  MD Webmail - Added options to decide how to handle the original message when replying
or forwarding on the Options | Compose page under "Replying and Forwarding". The options are as follows: Do not include, Attach, Include,
Include and Indent, Prefix. The option "Do not include" is unavailabe when
forwarding a message. For plain text messages the user can configure their own
prefix up to 4 characters long. A space will be included after the 4 characters.
-  MD Webmail- Added the ability to customize the attribution of original
messages in replies and forwards on the Options | Compose page under "Replying
and Forwarding". The options are as follows: None, Include From, Date, To, and
Subject lines from original message, Custom format (plain-text only). Custom
format has two required macros, %SENTDATEANDTIME% and %SENDER%. If either macro
is not used, then MD Webmail will default to the second option.
-  MD Webmail- increased the length of the private ical feed token found
in the Folder Share and Calendar Export views. The token will only increase in
length if it has yet to be created, or the user resets it.
-  MDRA - Made the "No Results" box in Message Search grey so that it does
not look like a button
-  MDRA - Moved the "Edit Mailing List Admins" button to the "Mailing List
Subscription Manager Options" section under Main -> Remote Admin Settings
-  MDRA - Increased the height of the Gateway Manager Settings window
login without clicking the checkbox.
message that will appear to Webmail and Remote Admin users which they must agree to
before the services can be used.
login without clicking the checkbox.
-  MDRA - Added button to set the settings on a page to the "Recommended"
settings. So far, only some security related pages have this button.
-  MD Webmail - Added an option to increase/decrease the spacing between
lines in the Compose view's HTML editor
-  MDRA - Added ability for Message Search to return messages that were not
accepted after the DATA command by searching the From and/or Recipients fields.
-  MD Webmail - Added better logging information for session failures when
debug level logging is enabled
-  MD Webmail - Added MDaemon PGP options to the Compose view for
WorldClient and LookOut themes
-  MD Webmail - Added the Country to Login History in Options | Security
-  MDRA - Added a Last Accessed column under the Main | Accounts settings
-  MD Webmail - The "UserCategories.js file has malformed data" message
will only be displayed when the data returned from the server is not in an array
-  MDRA - Added SSL & HTTPS views for RA and Webmail under Main | Webmail
Settings and Main | Remote Admin Settings.
-  MDRA - Added the SSL & TLS views from the MDaemon GUI under Security |
Security Settings | SSL & TLS. STARTTLS White List and STARTTLS List are buttons
located under the Security | SSL & TLS | MDaemon link.
-  MDRA - Added more filtering options to the Account list. Added the
Groups column to the filter column options. Display ActiveSync, Outlook
Connector, IMAP Access, POP Access, Over Quota, Near Quota, Frozen, Disabled,
and/or Active accounts.
-  MDRA - Improved filter ability. If no wildcards are included by the user,
the filter term is treated as though it were surrounded by wildcards. So "test"
would be treated as "*test*".
-  MD Webmail - Added an automatic feature to the auto complete
functionality that will display the three most commonly used contacts related to
the search string at the top of the list. Auto complete is used in multiple
views, and the feature is active wherever auto complete is used.
-  MDPC/MDRA - Added the Web Services tab for domain administrators when
editing user accounts other than their own. The "...edit quota settings" option
is disabled for domain administrators.
-  MDPC/MDRA - Added the Security->Screening->Sender
Blacklist and Recipient Blacklist views for domain admins. Additional options,
"Check message headers for blacklisted addresses", and "Notify blacklisted
senders that their message was refused" on the Sender Blacklist view are not
available for domain admins because they are not domain specific options.
-  MDRA - Users are now prevented from setting the Webmail List Refresh
Time to anything less than 1
-  MD Webmail - Added workaround to a bogus vulnerability detected by PCI
-  MD Webmail - Added an option for signed messages with p7s and p7b
attachments to import the S/MIME public certificate to the sender's contact
-  LookOut and WorldClient themes - Added an option to include a custom
image/icon with each custom link. After the CustomButtonLink1 entry, add
CustomButtonImage1=filename.extension. Place filename.extension in the
MDaemon\WorldClient\HTML\All\Images directory in order for it to be used. The
expected image size is 32x32. It will be automatically resized, so the original
image should also be 32x32 for the sake of aesthetics.
-  MD Webmail - changed the autocomplete feature to include domain name
matches with contact email addresses
-  MD Webmail - Added autocomplete="off" to the "Verify Pairing" field for
the Two Factor Authentication setup
-  MD Webmail - Updated the Voice Recorder error message for the cases
where microphone permission is off or the user is not using HTTPS
-  LookOut, WorldClient, and Mobile themes - Added speech synthesis to the
message views. Users can click the "Read Message" button to listen to the
message. Only supported in the latest Chrome and Firefox.
-  MDRA - Added the options to Allow or Require Two Factor Authentication
to the user Web Services page
-  MD Webmail - Added phone number links to all themes in the contact list
view to allow users to click on the phone number to make a call
-  MDRA - Added Learn Spam and Learn Non-Spam buttons to all Queues. The
buttons copy the selected messages into the Bayesian Spam and Non-Spam folders
-  MDRA - Added the Max Records field to Reports that are using bar graphs.
Maximum is no greater than 100 records for the views in question. Inbound
Email->Top Recipients, Top Recipients by Size; Outbound Email->Top
Senders, Top Senders by Size; Anti-Spam->Top Spam Scores, Top Recipients;
-  MDRA - Message Search - Added a message for the case that the user
either does not have permission to view the logs or the statistics database is
not enabled. If the statistics database is not enabled, a button will be present
that will take the user to the Logs->Log Settings->Statistics Log view.
-  Added a counter to show connections refused by location screening.
-  Changed dynamic screening notifications to go to global administrators by default
instead of the postmaster, to avoid problems when the postmaster alias is not set up.
-  MDLaunch /stop will try to forcibly terminate the MDaemon.exe process if it
has not stopped after two minutes.
-  The Content Filter can now extract files from inside of winmail.dat and turn
them into standard MIME message attachments. Enable this at Security | Content Filter
-  ActiveSync - Selected client Settings over-rides can now be applied to specific
device types and security groups. For example, one could ensure that all ActiveSync
connections with Outlook for Windows virtully merge their domain's Public Contacts into
the user's default contact folder, or enable location screening exemptions for ActiveSync
connections from members of a specific group.
-  ActiveSync does not encode the name in the From header if it contains only ASCII
-  Ctrl+S|SSL & TLS has a new screen called Let's Encrypt where you can
configure automation of a PowerShell script that requests and sets up free TLS
certificates from Let's Encrypt.
-  Updated ClamAV to version 0.99.4, and the 64-bit version of MDaemon now
uses 64-bit ClamAV.
-  LetsEncrypt will now clean up files older than 180 days from the Acme-Challenge
and MDaemon\PEM directories. Only .PFX files that have a file name beginning with the FQDN
configured in MDaemon are removed. The names of the files that are removed are logged in the
LetsEncrypt Log file.
-  The right click menu commands to white list and black list from the Queues screen
have been removed. Also, the Spam Filter White List and Black List screens now open in
read only mode until an "Advanced" button is clicked.
-  Added Antivirus mailbox scanning. Under Security->AntiVirus select
'Scan all mailboxes every n day(s)'. This allows for detecting of any
infected messages that may have passed through before virus definition updates
could be updated to detect them. Infected messages will be moved to the
quarantine folder with 'X-MDBadQueue-Reason' header added so that there will be
an explanation when viewed with MDaemon configuration screen. Messages that cannot be
scanned will not be quarantined.
-  fix to host name sometimes missing from SSL related logging
-  fix to DMARC contact email not accepting aliases to a subaddressed
-  fix to MD Webmail Compose page may take a very long time to load when
doing reply or forward on a large HTML message
-  fix to API not saving gateway configuration data in some cases
-  fix to MDRA - Public Folder Editor has old Alert message
-  fix to MDRA - Public Folders Access Control alert typo
-  fix to LookOut and WorldClient themes - PDF Viewer - If there are
non-breaking spaces ( ) in the name of the file, it will not load
-  fix to WorldClient theme - filters are not saved after being reordered
-  fix to WorldClient theme - Reply and forward flags are not updated
immediately after sending the message
-  fix to MD Webmail - Documents - Drag and drop of multiple files into
Documents folder results in only 1 file uploaded, no error message
-  fix to MD Webmail - French - When creating a folder called "Courrier" in
the root, the Inbox no longer displays messages
-  fix to MDRA - Active Sessions not showing MDaemon Webmail sessions
-  fix to CALDAV client may not display the last occurrence of recurring
event that occurs until a specific date
-  fix to if an attendee's email address is an alias, the attendee's
response status will not be recorded in the event
-  fix to potential crash in CalDAV server
-  fix to LookOut and WorldClient themes - Default Contacts View does not
apply to address book opened from the Compose view
-  fix to LookOut and WorldClient themes - When changing a category in a
shared folder, others do not see the change immediately
-  fix to MD Webmail - A meeting request attached to a message thread
displays the meeting information but not the message body
-  fix to MDRA - Deleting entry from ACL closes the dialog
-  fix to MDRA - German - When deleting an account, the confirmation box
cuts off the buttons
-  fix to WorldClient theme - Searching between two dates with more recent
date first gives results after more recent date
-  fix to MDRA - the Start / End Time field overlaps the Start / End Date drop-down box on the Autoresponder view
-  fix to WorldClient theme - Calendar View - The add folder icon is
displayed below on languages where the name is too long
-  Fix to MD Webmail - the message list may show spoofed FROM headers unless
View Sender is set to All
-  fix to Lite and Mobile themes - Carriage returns are missing in the body
when viewing a message
-  fix to MDRA - Invalid forwarding address reported when attempting to set
account to forward to multiple addresses
-  fix to WorldClient theme - The + to add a folder does not show a tooltip
when hovered over
-  fix to WorldClient theme - Some of the background color is not being
hidden when printing a calendar
-  fix to MD Health Check - if you click Analyze again after copying an
entry to the clipboard the application crashes
-  fix to possible MDaemon crash when processing messages from the local
-  fix to Webmail - When downloading a zip of files from a message with
multiple files of the same name, only the first file is included
-  fix to Webmail - Desktop Notifications are received, even though they
-  fix to WorldClient and LookOut themes - An extra message may be selected
after copying messages
-  fix to MD Webmail - might incorrectly display a sender is DKIM verified
-  fix to CalDAV - Unable to change date of single occurrence of recurring
-  fix to CalDAV - In Thunderbird/Lightning an all day recurring event
where a specific occurrence has been changed to occur on a different date is
not displayed correctly. The event is displayed on both the date the
occurrence has been changed to and the original date of the occurrence.
-  fix to Webmail - Slideshow - if an image is taller than the height of
the screen, the width will be set to the screen width
-  fix to corrupt text in translated Dynamic Screening emails
-  fix to ActiveSync - various changed occurrence entries cause Outlook to stop syncing the calendar
-  fix to IPs are still blocked by Dynamic Screening when Enable Authentication Failure Tracking is disabled
-  fix to possible MDaemon crash when generating a Dynamic Screening notifcation email
-  fix to possible MDaemon hang during shutdown
-  fix to ActiveSync - creating top-level folders in Outlook will also create same folder name under Inbox
-  fix to possible ActiveSync server crash when a client replies to a message
-  fix to ACL editor GUI may show extra character in Name field for anyone@domain entry
-  fix to ActiveSync - last occurrence of recurring event may be missing on iOS
-  fix to possible WorldClient.exe crash related to Dynamic Screening
-  fix to Chinese ActiveSync policy names are corrupt
-  fix to DAV server not properly enforcing dynamic and location screening
-  fix to XMPP server not using location screening
-  fix to Webmail - Cannot share a folder to a group
-  fix to Mobile theme - When sending to unknown user, no pop-up is
-  fix to LookOut theme - message preview does not block remote images
except in the Inbox
-  fix to Mobile theme - French - Unable to delete a calendar appointment
-  fix to specific messages locking the local queue with high CPU usage
-  fix to CALDAV: Report command with no date filter may not return all
-  fix to List-Unsubscribe header is not automatically added to mailing
list messages when "Honor '<List>-subscribe' and '<List>-unsubscribe' addresses"
-  fix to Webmail - Advanced Search - Searching for any text string in the
message body returns all messages in all folders in the user account in the
-  fix to CALDAV: Specific data in calendar XML database file causes
Thunderbird/Lightning to hang when synchronizing calendar
-  fix to $CALTXT$ macro is not replaced in calendar reminder email
messages if the length of the comments/body field of the event exceeds 1000
-  fix to Dynamic Blacklist GUI may not display all DSBlackList.dat entries
-  fix to recurring events from specific CalDAV clients are always saved as
all day events
-  fix to ActiveSync: Time of recurring events may shift on Android devices
by one hour after the start or end of daylight saving time
-  fix to MDRA - Any changes made to a global admin's ActiveSync Client
Settings are applied globally
-  fix to meeting responses may be sent from the wrong account
-  fix to MDPGP not properly using keys assigned to aliases
-  fix to when a 'GET' command is used with CalDAV, "private details" of
private calendar events are not filtered out
-  fix to possible MDaemon hang when the MDPGP option "Trade public keys
during SMTP mail sessions (MDaemon)" is enabled
-  fix to MDPGP not signing some messages when configured to do so
-  fix to CalDAV: Free/Busy lookups from Mac iCal calendar application
return no results
-  fix to MDaemon may send messages to the wrong smart host