84. Feature stability¶
This single table inventories every feature Pepsi implements and records the current evidence for each feature’s stability. The first three columns are hand-maintained in contrib/feature-registry.tsv; the last three are merged in from anonymous, opt-in usage telemetry (see pepsi-telemetry).
Automated test — whether, and how, the feature is covered by an automated test:
U(a unit / in-processcargo test),I(an integration test — atests/*.shlive-pipeline script or apepsi-test-stagesend-to-end test),I/U(both), or-(no automated test yet).Manual — whether the feature has additionally been verified by hand (
yes/no).Deployments — number of real-world deployments that have reported having the feature enabled.
Uses — number of times the feature has actually been exercised in the field.
Stability — a tier derived from the last two columns:
stable — deployments ≥ 100 and total uses ≥ 100000
used — deployments ≥ 10 and total uses ≥ 1000
experimental — otherwise
A feature marked (*) after its name is not instrumented for telemetry — it is a passive protocol capability, a universal facility, or a short-lived CLI that exits before a usage count could be flushed — so its Deployments, Uses and Stability cells are shown as — (no count can be measured for it).
The counts below come from
https://telemetry.pepsi.taler.net/telemetry/report. An instrumented feature with no
count in it reads 0 / 0 / experimental: no reporting deployment
has exercised it since its telemetry daemon last started. The collector does not
authenticate submissions, so read the counts as an indication, not a
measurement. No feature has yet been through a dedicated by-hand test
pass (Manual = no throughout).
Report generated: 2026-09-28T23:22:26Z
Feature (RFC) |
Automated test |
Manual |
Deployments |
Uses |
Stability |
|---|---|---|---|---|---|
SMTP server core (RFC 5321) |
I/U |
no |
1 |
141 |
experimental |
STARTTLS (RFC 3207) |
I/U |
no |
1 |
830 |
experimental |
Implicit TLS / submissions port (RFC 8314) |
U |
no |
0 |
0 |
experimental |
CHUNKING / BDAT (RFC 3030) |
I/U |
no |
1 |
18 |
experimental |
SIZE declaration and enforcement (RFC 1870) |
I/U |
no |
1 |
129 |
experimental |
PIPELINING (RFC 2920) |
I/U |
no |
1 |
111 |
experimental |
ENHANCEDSTATUSCODES (RFC 2034) (*) |
U |
no |
— |
— |
— |
Received trace header (RFC 5321, RFC 3848) |
I/U |
no |
1 |
141 |
experimental |
Connection / overload limiting |
I/U |
no |
0 |
0 |
experimental |
8BITMIME (RFC 6152) |
I/U |
no |
1 |
43 |
experimental |
SMTPUTF8 (RFC 6531) |
I/U |
no |
1 |
8 |
experimental |
Per-hop 8-bit / UTF-8 downgrade (RFC 2045, RFC 2047) |
I/U |
no |
0 |
0 |
experimental |
Delivery Status Notifications (RFC 3461, RFC 3463, RFC 3464) |
I/U |
no |
1 |
88 |
experimental |
SMTP AUTH (inbound) (RFC 4954) |
U |
no |
1 |
16 |
experimental |
Message submission / MSA (RFC 6409) |
U |
no |
1 |
17 |
experimental |
Client authentication (MYNETWORKS / TLS client cert) |
I/U |
no |
0 |
0 |
experimental |
SPF (RFC 7208) |
U |
no |
1 |
140 |
experimental |
DKIM verification (RFC 6376, RFC 8463) |
I/U |
no |
1 |
91 |
experimental |
DMARC (RFC 7489) |
U |
no |
1 |
95 |
experimental |
iprev / FCrDNS (RFC 8601) |
U |
no |
1 |
140 |
experimental |
Authentication-Results header (RFC 8601) |
U |
no |
1 |
141 |
experimental |
ARC seal and verify (RFC 8617) |
I/U |
no |
1 |
124 |
experimental |
Sender Rewriting Scheme (SRS) |
I/U |
no |
0 |
0 |
experimental |
Outbound DKIM signing (RFC 6376, RFC 8463) |
I/U |
no |
1 |
23 |
experimental |
Direct-to-MX relay (RFC 5321) |
I/U |
no |
1 |
53 |
experimental |
Null MX handling (RFC 7505) |
U |
no |
0 |
0 |
experimental |
MTA-STS (RFC 8461) |
U |
no |
1 |
4 |
experimental |
Mail client autoconfiguration (config-v1.1.xml) (draft-ietf-mailmaint-autoconfig) |
U |
no |
0 |
0 |
experimental |
TLS server-identity verification (RFC 6125) |
U |
no |
1 |
53 |
experimental |
Smarthost relay (RFC 5321) |
I/U |
no |
0 |
0 |
experimental |
Smarthost SASL mechanisms (RFC 4954, RFC 4616, RFC 5802, RFC 7628) |
U |
no |
0 |
0 |
experimental |
DANE / TLSA (RFC 7672) |
U |
no |
0 |
0 |
experimental |
SMTP TLS Reporting (TLSRPT) (RFC 8460) |
I/U |
no |
1 |
43 |
experimental |
Maildir local delivery |
I/U |
no |
1 |
119 |
experimental |
Mailbox quota enforcement (Maildir++ / quotactl) |
I/U |
no |
0 |
0 |
experimental |
Mailbox quota CLI and reconciliation (pepsi-quota) (*) |
I |
no |
— |
— |
— |
LMTP local delivery + MDA Sieve (RFC 2033, RFC 5228) |
I/U |
no |
0 |
0 |
experimental |
~/.forward processing |
I/U |
no |
0 |
0 |
experimental |
Alias / virtual-map expansion |
I/U |
no |
1 |
119 |
experimental |
Milter mail-filter client (post-queue) |
I/U |
no |
0 |
0 |
experimental |
Pay-to-send anti-spam gate (GNU Taler) |
I/U |
no |
0 |
0 |
experimental |
Auto-pay wallet (GNU Taler) |
I/U |
no |
1 |
17 |
experimental |
Sender whitelist check |
I/U |
no |
0 |
0 |
experimental |
Auto-whitelist (outbound) |
I/U |
no |
1 |
17 |
experimental |
Language detection |
I/U |
no |
1 |
63 |
experimental |
Language blocking |
I/U |
no |
1 |
63 |
experimental |
Conditional branch stage |
U |
no |
1 |
141 |
experimental |
Edit-settings-by-email |
I/U |
no |
1 |
17 |
experimental |
Per-address settings overrides |
I/U |
no |
0 |
0 |
experimental |
Bounce generation (RFC 3464) |
I/U |
no |
1 |
7 |
experimental |
Discard sink |
no |
0 |
0 |
experimental |
|
Single-table queue and crash recovery |
I |
no |
0 |
0 |
experimental |
Pipelined worker pools and watchdog |
I |
no |
1 |
1 |
experimental |
Stage fusion |
I |
no |
1 |
17 |
experimental |
HTTP server (MTA-STS policy + metrics) (RFC 8461) |
I/U |
no |
0 |
0 |
experimental |
Prometheus metrics |
I |
no |
0 |
0 |
experimental |
Provisioning and DNS verification (*) |
I/U |
no |
— |
— |
— |
Migration from an existing MTA (Postfix/Exim/Sendmail/qmail/Stalwart) (*) |
U |
no |
— |
— |
— |
Queue operator CLI (pepsi-queue) (*) |
no |
— |
— |
— |
|
Health summary (pepsi-status) (*) |
U |
no |
— |
— |
— |
Language-detection diagnostics (pepsi-detect-language) (*) |
U |
no |
— |
— |
— |
Local submission socket (peer-credential auth) (RFC 6409) |
U |
no |
1 |
2 |
experimental |
Sendmail-compatible client (pepsi-sendmail) (*) |
I/U |
no |
— |
— |
— |
Whitelist CLI (pepsi-whitelist) (*) |
I |
no |
— |
— |
— |
Per-user whitelist namespaces (<login>/name) (*) |
I/U |
no |
— |
— |
— |
Whitelist import from a mailbox (mbox/Maildir) (*) |
I/U |
no |
— |
— |
— |
Whitelist import over IMAP (*) |
U |
no |
— |
— |
— |
Whitelist import via doveadm (*) |
U |
no |
— |
— |
— |
Whitelist wildcard proposals + hoster exclusion (*) |
I/U |
no |
— |
— |
— |
End-to-end key store (identities, peer keys, CA trust) (*) |
I/U |
no |
— |
— |
— |
Private keys AEAD-wrapped under a secrets.d KEK |
U |
no |
0 |
0 |
experimental |
Private-key column restricted to the pepsi-crypto role (*) |
I |
no |
— |
— |
— |
Key-store CLI (pepsi-keys) (*) |
I |
no |
— |
— |
— |
OpenPGP key generation (Ed25519 / RSA) |
U |
no |
0 |
0 |
experimental |
S/MIME certificate + CSR issuance (self-signed) |
U |
no |
0 |
0 |
experimental |
S/MIME single-certificate mode (CRYPTO_SMIME_SHARED_KEY) |
U |
no |
0 |
0 |
experimental |
Key discovery: WKD advanced (openpgpkey.<domain>) (draft-koch-openpgp-webkey-service) |
I/U |
no |
0 |
0 |
experimental |
Key discovery: WKD direct (draft-koch-openpgp-webkey-service) |
I/U |
no |
0 |
0 |
experimental |
Key discovery: DANE OPENPGPKEY / SMIMEA (RFC 7929, RFC 8162) |
U |
no |
0 |
0 |
experimental |
Key discovery: verifying key server (VKS) |
U |
no |
0 |
0 |
experimental |
Key discovery: LDAP directory (feature-gated) (RFC 4511) |
U |
no |
0 |
0 |
experimental |
Key harvesting from inbound mail + Autocrypt |
U |
no |
0 |
0 |
experimental |
Key learning from Autocrypt-Gossip inside a decrypted message (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
Park-on-missing-key (asynchronous discovery) |
I/U |
no |
0 |
0 |
experimental |
Outbound end-to-end signing and encryption (pepsi-stage-encrypt) (RFC 3156, RFC 8551) |
I/U |
no |
0 |
0 |
experimental |
Outbound OpenPGP (PGP/MIME) encryption (RFC 3156, RFC 9580) |
U |
no |
0 |
0 |
experimental |
Outbound S/MIME (CMS) encryption (RFC 8551, RFC 5083) |
U |
no |
0 |
0 |
experimental |
Outbound end-to-end signature without encryption (RFC 3156, RFC 8551) |
U |
no |
0 |
0 |
experimental |
Per-recipient container downgrade (SEIPDv1 / CBC) (RFC 4880) |
U |
no |
0 |
0 |
experimental |
Autocrypt key advertisement on outbound mail (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
Autocrypt key gossip: the other To/Cc recipients’ keys inside the ciphertext (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
Keyless recipient routed to the secure-link portal |
I/U |
no |
0 |
0 |
experimental |
Secure-link fallback portal: store an unencryptable message |
I/U |
no |
0 |
0 |
experimental |
Secure-link portal endpoints served by pepsi-httpd |
I/U |
no |
0 |
0 |
experimental |
Secure-link message opened with the correct PIN |
I |
no |
0 |
0 |
experimental |
Secure-link PIN refused (lockout counter) |
I |
no |
0 |
0 |
experimental |
Reply composed through the secure-link portal |
I |
no |
0 |
0 |
experimental |
Secure-link second factor mailed to the sender |
U |
no |
0 |
0 |
experimental |
Secure-link second factor handed to a gateway command |
no |
0 |
0 |
experimental |
|
Secure-link with no second factor (link only, weaker) |
U |
no |
0 |
0 |
experimental |
Identity creation on request (an explicit protection request, or SIGN = always) |
I/U |
no |
0 |
0 |
experimental |
pEp preset: a key generated for a sender on first submission (ENABLE_PEP) |
I |
no |
0 |
0 |
experimental |
A user’s own (MUA) key registered from a submitted Autocrypt header or key file (Autocrypt Level 1) |
I |
no |
0 |
0 |
experimental |
Sender’s public key attached as a file (ATTACH_KEYS_AS_FILES) (RFC 3156) |
I/U |
no |
0 |
0 |
experimental |
Key self-service by e-mail (status, generate, register, publish, retire) |
I/U |
no |
0 |
0 |
experimental |
Inbound end-to-end decryption and signature verification (pepsi-stage-decrypt) (RFC 3156, RFC 8551) |
I/U |
no |
0 |
0 |
experimental |
Inbound message actually decrypted (RFC 3156, RFC 8551) |
U |
no |
0 |
0 |
experimental |
Inbound OpenPGP (PGP/MIME, inline) decryption (RFC 3156, RFC 9580) |
U |
no |
0 |
0 |
experimental |
Inbound S/MIME (CMS) decryption (RFC 8551, RFC 5083) |
U |
no |
0 |
0 |
experimental |
Inbound signature valid against a trusted key (RFC 3156, RFC 8551) |
U |
no |
0 |
0 |
experimental |
Inbound signature valid but the key is unanchored (TOFU) |
U |
no |
0 |
0 |
experimental |
Inbound signature that did not verify |
U |
no |
0 |
0 |
experimental |
Inbound ciphertext this host could not open |
U |
no |
0 |
0 |
experimental |
Inbound OpenPGP plaintext over the decompression cap |
U |
no |
0 |
0 |
experimental |
Autocrypt key learning from inbound mail (Autocrypt Level 1) |
I/U |
no |
0 |
0 |
experimental |
Keys learnt inline from an inbound message (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
Re-verification using a certificate found in the plaintext |
no |
0 |
0 |
experimental |
|
Third parties’ keys learnt from a decrypted message’s gossip fields (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
A correspondent’s Autocrypt key replaced by a newer one (audited, users notified) (Autocrypt Level 1) |
I/U |
no |
0 |
0 |
experimental |
A newer Autocrypt key refused because the stored one is alive (ACCEPT_ROTATION = expired) |
I/U |
no |
0 |
0 |
experimental |
Inbound crypto failure routed to a quarantine stage |
U |
no |
0 |
0 |
experimental |
Inbound crypto failure bounced |
U |
no |
0 |
0 |
experimental |
Inbound mail encrypted to a user’s own (MUA) key passed through unopened (RFC 3156, RFC 8551) |
I |
no |
0 |
0 |
experimental |
Decrypted inbound mail re-encrypted to the recipient’s own (MUA) key for storage (pepsi-stage-reencrypt) (RFC 3156, RFC 8551) |
I/U |
no |
0 |
0 |
experimental |
Storage re-encryption to an OpenPGP MUA key (RFC 3156, RFC 9580) |
I/U |
no |
0 |
0 |
experimental |
Storage re-encryption to an S/MIME MUA key (RFC 8551, RFC 5083) |
U |
no |
0 |
0 |
experimental |
Decrypted mail filed in plaintext: the recipient has no MUA key (ON_NO_CLIENT_KEY = plaintext) |
I |
no |
0 |
0 |
experimental |
A recipient’s MUA key that could not be sealed to |
no |
0 |
0 |
experimental |
|
Decrypted mail refused for want of an MUA key (ON_NO_CLIENT_KEY = bounce) (RFC 3463) |
I |
no |
0 |
0 |
experimental |
Proof recorded that a correspondent holds our key (stops the key file) |
I/U |
no |
0 |
0 |
experimental |
Key publication: Web Key Directory endpoints (draft-koch-openpgp-webkey-service) |
I/U |
no |
0 |
0 |
experimental |
Key publication: key-server upload + verification retry (*) |
U |
no |
— |
— |
— |
Key publication: auto-confirm the key server’s verification mail |
U |
no |
0 |
0 |
experimental |
Recipient-domain routing to a next hop (pepsi-stage-route) |
I/U |
no |
0 |
0 |
experimental |
Outlook add-in served by pepsi-httpd (manifest + task pane) |
U |
no |
0 |
0 |
experimental |
Per-next-hop IP address family selection (ADDRESS_FAMILY) |
U |
no |
0 |
0 |
experimental |
Settings CLI (pepsi-settings) (*) |
I/U |
no |
— |
— |
— |
Configuration in the database (scope chain + hot reload) |
I/U |
no |
0 |
0 |
experimental |
Config CLI (pepsi-config) (*) |
I |
no |
— |
— |
— |
Encrypted configuration export/import (*) |
U |
no |
— |
— |
— |
Failure bouncer (pepsi-failure-bouncer) |
no |
0 |
0 |
experimental |
|
Smarthost OAuth token-refresh helper (*) |
U |
no |
— |
— |
— |
Structured logging (*) |
U |
no |
— |
— |
— |
Feature telemetry (*) |
U |
no |
— |
— |
— |
Administrative REST API (/api/v1) |
I/U |
no |
0 |
0 |
experimental |
Administration web console (/ui) |
U |
no |
0 |
0 |
experimental |
Setup interview driven from the web console |
U |
no |
0 |
0 |
experimental |
Secure-link messages browsed from the web console |
U |
no |
0 |
0 |
experimental |
Correspondent key imported through the API (POST /api/v1/peers) |
I |
no |
0 |
0 |
experimental |
Discovery lookup queued through the API (POST /api/v1/peers/discover) |
I |
no |
0 |
0 |
experimental |
Administrative audit log |
U |
no |
0 |
0 |
experimental |
Opt-in per-message log ([pepsi] MAIL_LOG) |
U |
no |
0 |
0 |
experimental |
Browser-driven setup (/api/v1/setup + pepsi-setup apply) |
U |
no |
0 |
0 |
experimental |
Non-interactive wizard (pepsi-setup –answers) |
U |
no |
0 |
0 |
experimental |
Vacation / out-of-office auto-reply (RFC 3834) |
I/U |
no |
0 |
0 |
experimental |
Confirm-to-send challenge for unknown senders (pepsi-stage-secretary) (RFC 3834) |
I/U |
no |
0 |
0 |
experimental |
Mailing lists: domains, lists, members, owners, bans (pepsi-list) (*) |
I/U |
no |
— |
— |
— |
Mailing-list archive storage (hash-partitioned, full-text + trigram) (*) |
I/U |
no |
— |
— |
— |
Mailing-list routing (pepsi-stage-list) |
I/U |
no |
0 |
0 |
experimental |
Mailing-list posting: moderation chain, handler pipeline and fan-out (pepsi-stage-list-post) |
I/U |
no |
0 |
0 |
experimental |
Mailing-list per-member delivery: one-click unsubscribe, decoration (pepsi-stage-list-deliver) |
I/U |
no |
0 |
0 |
experimental |
Mailing-list e-mail commands: join, leave, confirm and the subscription workflows (pepsi-stage-list-command) |
I/U |
no |
0 |
0 |
experimental |
Mailing-list bounce processing: VERP attribution, 17 detectors, scoring (pepsi-stage-list-bounce) |
I/U |
no |
0 |
0 |
experimental |
Mailing-list archive: ingest, threading, the two search mechanisms, purge and export (pepsi-archive) (*) |
I/U |
no |
— |
— |
— |
The GNU Mailman 3 REST API (/3.0/ and /3.1/) – upstream 3.3.10, gated on mailmanclient and Postorius’s own suites |
I/U |
no |
0 |
0 |
experimental |
The public mailing-list web interface: index, subscribe/unsubscribe forms, archive browsing and search |
I/U |
no |
0 |
0 |
experimental |
RFC 8058 one-click unsubscribe (List-Unsubscribe-Post), honoured whatever the unsubscription policy says (RFC 8058) |
I/U |
no |
0 |
0 |
experimental |
Member accounts on the public list site: registration, address verification, passwords and password reset, and the member’s own subscription pages |
I/U |
no |
0 |
0 |
experimental |
The list owner and moderator console: held messages, subscription requests, the generated settings screens, the roster, bans and header matches – authorised by a roster query, not by an operator account |
I/U |
no |
0 |
0 |
experimental |
Importing a running GNU Mailman 3 site over its own REST API: domains, lists, users, addresses, members, bans and header matches |
I/U |
no |
0 |
0 |
experimental |
Importing a Mailman 2.1 site from its config.pck files, with upstream’s own attribute mapping and a pickle reader that constructs nothing |
I/U |
no |
0 |
0 |
experimental |
Importing an mbox archive, with the cleanarch repairs in the reader and an automatic thread rebuild |
I/U |
no |
0 |
0 |
experimental |
The cutover invitation mailing: a rate, a resume and a per-domain dry run |
I/U |
no |
0 |
0 |
experimental |
Both digest formats: MIME multipart/digest and RFC 1153 plain, with the volume/number rule and a periodic timer (RFC 1153) |
I/U |
no |
0 |
0 |
experimental |
The posting-address autoresponder, including respond_and_discard (RFC 3834) |
I/U |
no |
0 |
0 |
experimental |
Discarding held messages past max_days_to_hold – an attribute that is inert in GNU Mailman 3 |
I/U |
no |
0 |
0 |
experimental |
The 28 GNU Mailman notice templates in all ten shipped languages, with the placeholder audit that catches a translated placeholder name (*) |
U |
no |
— |
— |
— |
The public list and archive pages in English, German and French, chosen from Accept-Language in q-order before any database access (*) |
I/U |
no |
— |
— |
— |