84. Feature stability

This single table inventories every feature Pepsi implements and records the current evidence for each feature’s stability. The first three columns are hand-maintained in contrib/feature-registry.tsv; the last three are merged in from anonymous, opt-in usage telemetry (see pepsi-telemetry).

  • Automated test — whether, and how, the feature is covered by an automated test: U (a unit / in-process cargo test), I (an integration test — a tests/*.sh live-pipeline script or a pepsi-test-stages end-to-end test), I/U (both), or - (no automated test yet).

  • Manual — whether the feature has additionally been verified by hand (yes/no).

  • Deployments — number of real-world deployments that have reported having the feature enabled.

  • Uses — number of times the feature has actually been exercised in the field.

  • Stability — a tier derived from the last two columns:

    • stable — deployments ≥ 100 and total uses ≥ 100000

    • used — deployments ≥ 10 and total uses ≥ 1000

    • experimental — otherwise

A feature marked (*) after its name is not instrumented for telemetry — it is a passive protocol capability, a universal facility, or a short-lived CLI that exits before a usage count could be flushed — so its Deployments, Uses and Stability cells are shown as — (no count can be measured for it).

The counts below come from https://telemetry.pepsi.taler.net/telemetry/report. An instrumented feature with no count in it reads 0 / 0 / experimental: no reporting deployment has exercised it since its telemetry daemon last started. The collector does not authenticate submissions, so read the counts as an indication, not a measurement. No feature has yet been through a dedicated by-hand test pass (Manual = no throughout).

Report generated: 2026-09-28T23:22:26Z

Feature stability

Feature (RFC)

Automated test

Manual

Deployments

Uses

Stability

SMTP server core (RFC 5321)

I/U

no

1

141

experimental

STARTTLS (RFC 3207)

I/U

no

1

830

experimental

Implicit TLS / submissions port (RFC 8314)

U

no

0

0

experimental

CHUNKING / BDAT (RFC 3030)

I/U

no

1

18

experimental

SIZE declaration and enforcement (RFC 1870)

I/U

no

1

129

experimental

PIPELINING (RFC 2920)

I/U

no

1

111

experimental

ENHANCEDSTATUSCODES (RFC 2034) (*)

U

no

—

—

—

Received trace header (RFC 5321, RFC 3848)

I/U

no

1

141

experimental

Connection / overload limiting

I/U

no

0

0

experimental

8BITMIME (RFC 6152)

I/U

no

1

43

experimental

SMTPUTF8 (RFC 6531)

I/U

no

1

8

experimental

Per-hop 8-bit / UTF-8 downgrade (RFC 2045, RFC 2047)

I/U

no

0

0

experimental

Delivery Status Notifications (RFC 3461, RFC 3463, RFC 3464)

I/U

no

1

88

experimental

SMTP AUTH (inbound) (RFC 4954)

U

no

1

16

experimental

Message submission / MSA (RFC 6409)

U

no

1

17

experimental

Client authentication (MYNETWORKS / TLS client cert)

I/U

no

0

0

experimental

SPF (RFC 7208)

U

no

1

140

experimental

DKIM verification (RFC 6376, RFC 8463)

I/U

no

1

91

experimental

DMARC (RFC 7489)

U

no

1

95

experimental

iprev / FCrDNS (RFC 8601)

U

no

1

140

experimental

Authentication-Results header (RFC 8601)

U

no

1

141

experimental

ARC seal and verify (RFC 8617)

I/U

no

1

124

experimental

Sender Rewriting Scheme (SRS)

I/U

no

0

0

experimental

Outbound DKIM signing (RFC 6376, RFC 8463)

I/U

no

1

23

experimental

Direct-to-MX relay (RFC 5321)

I/U

no

1

53

experimental

Null MX handling (RFC 7505)

U

no

0

0

experimental

MTA-STS (RFC 8461)

U

no

1

4

experimental

Mail client autoconfiguration (config-v1.1.xml) (draft-ietf-mailmaint-autoconfig)

U

no

0

0

experimental

TLS server-identity verification (RFC 6125)

U

no

1

53

experimental

Smarthost relay (RFC 5321)

I/U

no

0

0

experimental

Smarthost SASL mechanisms (RFC 4954, RFC 4616, RFC 5802, RFC 7628)

U

no

0

0

experimental

DANE / TLSA (RFC 7672)

U

no

0

0

experimental

SMTP TLS Reporting (TLSRPT) (RFC 8460)

I/U

no

1

43

experimental

Maildir local delivery

I/U

no

1

119

experimental

Mailbox quota enforcement (Maildir++ / quotactl)

I/U

no

0

0

experimental

Mailbox quota CLI and reconciliation (pepsi-quota) (*)

I

no

—

—

—

LMTP local delivery + MDA Sieve (RFC 2033, RFC 5228)

I/U

no

0

0

experimental

~/.forward processing

I/U

no

0

0

experimental

Alias / virtual-map expansion

I/U

no

1

119

experimental

Milter mail-filter client (post-queue)

I/U

no

0

0

experimental

Pay-to-send anti-spam gate (GNU Taler)

I/U

no

0

0

experimental

Auto-pay wallet (GNU Taler)

I/U

no

1

17

experimental

Sender whitelist check

I/U

no

0

0

experimental

Auto-whitelist (outbound)

I/U

no

1

17

experimental

Language detection

I/U

no

1

63

experimental

Language blocking

I/U

no

1

63

experimental

Conditional branch stage

U

no

1

141

experimental

Edit-settings-by-email

I/U

no

1

17

experimental

Per-address settings overrides

I/U

no

0

0

experimental

Bounce generation (RFC 3464)

I/U

no

1

7

experimental

Discard sink

no

0

0

experimental

Single-table queue and crash recovery

I

no

0

0

experimental

Pipelined worker pools and watchdog

I

no

1

1

experimental

Stage fusion

I

no

1

17

experimental

HTTP server (MTA-STS policy + metrics) (RFC 8461)

I/U

no

0

0

experimental

Prometheus metrics

I

no

0

0

experimental

Provisioning and DNS verification (*)

I/U

no

—

—

—

Migration from an existing MTA (Postfix/Exim/Sendmail/qmail/Stalwart) (*)

U

no

—

—

—

Queue operator CLI (pepsi-queue) (*)

no

—

—

—

Health summary (pepsi-status) (*)

U

no

—

—

—

Language-detection diagnostics (pepsi-detect-language) (*)

U

no

—

—

—

Local submission socket (peer-credential auth) (RFC 6409)

U

no

1

2

experimental

Sendmail-compatible client (pepsi-sendmail) (*)

I/U

no

—

—

—

Whitelist CLI (pepsi-whitelist) (*)

I

no

—

—

—

Per-user whitelist namespaces (<login>/name) (*)

I/U

no

—

—

—

Whitelist import from a mailbox (mbox/Maildir) (*)

I/U

no

—

—

—

Whitelist import over IMAP (*)

U

no

—

—

—

Whitelist import via doveadm (*)

U

no

—

—

—

Whitelist wildcard proposals + hoster exclusion (*)

I/U

no

—

—

—

End-to-end key store (identities, peer keys, CA trust) (*)

I/U

no

—

—

—

Private keys AEAD-wrapped under a secrets.d KEK

U

no

0

0

experimental

Private-key column restricted to the pepsi-crypto role (*)

I

no

—

—

—

Key-store CLI (pepsi-keys) (*)

I

no

—

—

—

OpenPGP key generation (Ed25519 / RSA)

U

no

0

0

experimental

S/MIME certificate + CSR issuance (self-signed)

U

no

0

0

experimental

S/MIME single-certificate mode (CRYPTO_SMIME_SHARED_KEY)

U

no

0

0

experimental

Key discovery: WKD advanced (openpgpkey.<domain>) (draft-koch-openpgp-webkey-service)

I/U

no

0

0

experimental

Key discovery: WKD direct (draft-koch-openpgp-webkey-service)

I/U

no

0

0

experimental

Key discovery: DANE OPENPGPKEY / SMIMEA (RFC 7929, RFC 8162)

U

no

0

0

experimental

Key discovery: verifying key server (VKS)

U

no

0

0

experimental

Key discovery: LDAP directory (feature-gated) (RFC 4511)

U

no

0

0

experimental

Key harvesting from inbound mail + Autocrypt

U

no

0

0

experimental

Key learning from Autocrypt-Gossip inside a decrypted message (Autocrypt Level 1)

U

no

0

0

experimental

Park-on-missing-key (asynchronous discovery)

I/U

no

0

0

experimental

Outbound end-to-end signing and encryption (pepsi-stage-encrypt) (RFC 3156, RFC 8551)

I/U

no

0

0

experimental

Outbound OpenPGP (PGP/MIME) encryption (RFC 3156, RFC 9580)

U

no

0

0

experimental

Outbound S/MIME (CMS) encryption (RFC 8551, RFC 5083)

U

no

0

0

experimental

Outbound end-to-end signature without encryption (RFC 3156, RFC 8551)

U

no

0

0

experimental

Per-recipient container downgrade (SEIPDv1 / CBC) (RFC 4880)

U

no

0

0

experimental

Autocrypt key advertisement on outbound mail (Autocrypt Level 1)

U

no

0

0

experimental

Autocrypt key gossip: the other To/Cc recipients’ keys inside the ciphertext (Autocrypt Level 1)

U

no

0

0

experimental

Keyless recipient routed to the secure-link portal

I/U

no

0

0

experimental

Secure-link fallback portal: store an unencryptable message

I/U

no

0

0

experimental

Secure-link portal endpoints served by pepsi-httpd

I/U

no

0

0

experimental

Secure-link message opened with the correct PIN

I

no

0

0

experimental

Secure-link PIN refused (lockout counter)

I

no

0

0

experimental

Reply composed through the secure-link portal

I

no

0

0

experimental

Secure-link second factor mailed to the sender

U

no

0

0

experimental

Secure-link second factor handed to a gateway command

no

0

0

experimental

Secure-link with no second factor (link only, weaker)

U

no

0

0

experimental

Identity creation on request (an explicit protection request, or SIGN = always)

I/U

no

0

0

experimental

pEp preset: a key generated for a sender on first submission (ENABLE_PEP)

I

no

0

0

experimental

A user’s own (MUA) key registered from a submitted Autocrypt header or key file (Autocrypt Level 1)

I

no

0

0

experimental

Sender’s public key attached as a file (ATTACH_KEYS_AS_FILES) (RFC 3156)

I/U

no

0

0

experimental

Key self-service by e-mail (status, generate, register, publish, retire)

I/U

no

0

0

experimental

Inbound end-to-end decryption and signature verification (pepsi-stage-decrypt) (RFC 3156, RFC 8551)

I/U

no

0

0

experimental

Inbound message actually decrypted (RFC 3156, RFC 8551)

U

no

0

0

experimental

Inbound OpenPGP (PGP/MIME, inline) decryption (RFC 3156, RFC 9580)

U

no

0

0

experimental

Inbound S/MIME (CMS) decryption (RFC 8551, RFC 5083)

U

no

0

0

experimental

Inbound signature valid against a trusted key (RFC 3156, RFC 8551)

U

no

0

0

experimental

Inbound signature valid but the key is unanchored (TOFU)

U

no

0

0

experimental

Inbound signature that did not verify

U

no

0

0

experimental

Inbound ciphertext this host could not open

U

no

0

0

experimental

Inbound OpenPGP plaintext over the decompression cap

U

no

0

0

experimental

Autocrypt key learning from inbound mail (Autocrypt Level 1)

I/U

no

0

0

experimental

Keys learnt inline from an inbound message (Autocrypt Level 1)

U

no

0

0

experimental

Re-verification using a certificate found in the plaintext

no

0

0

experimental

Third parties’ keys learnt from a decrypted message’s gossip fields (Autocrypt Level 1)

U

no

0

0

experimental

A correspondent’s Autocrypt key replaced by a newer one (audited, users notified) (Autocrypt Level 1)

I/U

no

0

0

experimental

A newer Autocrypt key refused because the stored one is alive (ACCEPT_ROTATION = expired)

I/U

no

0

0

experimental

Inbound crypto failure routed to a quarantine stage

U

no

0

0

experimental

Inbound crypto failure bounced

U

no

0

0

experimental

Inbound mail encrypted to a user’s own (MUA) key passed through unopened (RFC 3156, RFC 8551)

I

no

0

0

experimental

Decrypted inbound mail re-encrypted to the recipient’s own (MUA) key for storage (pepsi-stage-reencrypt) (RFC 3156, RFC 8551)

I/U

no

0

0

experimental

Storage re-encryption to an OpenPGP MUA key (RFC 3156, RFC 9580)

I/U

no

0

0

experimental

Storage re-encryption to an S/MIME MUA key (RFC 8551, RFC 5083)

U

no

0

0

experimental

Decrypted mail filed in plaintext: the recipient has no MUA key (ON_NO_CLIENT_KEY = plaintext)

I

no

0

0

experimental

A recipient’s MUA key that could not be sealed to

no

0

0

experimental

Decrypted mail refused for want of an MUA key (ON_NO_CLIENT_KEY = bounce) (RFC 3463)

I

no

0

0

experimental

Proof recorded that a correspondent holds our key (stops the key file)

I/U

no

0

0

experimental

Key publication: Web Key Directory endpoints (draft-koch-openpgp-webkey-service)

I/U

no

0

0

experimental

Key publication: key-server upload + verification retry (*)

U

no

—

—

—

Key publication: auto-confirm the key server’s verification mail

U

no

0

0

experimental

Recipient-domain routing to a next hop (pepsi-stage-route)

I/U

no

0

0

experimental

Outlook add-in served by pepsi-httpd (manifest + task pane)

U

no

0

0

experimental

Per-next-hop IP address family selection (ADDRESS_FAMILY)

U

no

0

0

experimental

Settings CLI (pepsi-settings) (*)

I/U

no

—

—

—

Configuration in the database (scope chain + hot reload)

I/U

no

0

0

experimental

Config CLI (pepsi-config) (*)

I

no

—

—

—

Encrypted configuration export/import (*)

U

no

—

—

—

Failure bouncer (pepsi-failure-bouncer)

no

0

0

experimental

Smarthost OAuth token-refresh helper (*)

U

no

—

—

—

Structured logging (*)

U

no

—

—

—

Feature telemetry (*)

U

no

—

—

—

Administrative REST API (/api/v1)

I/U

no

0

0

experimental

Administration web console (/ui)

U

no

0

0

experimental

Setup interview driven from the web console

U

no

0

0

experimental

Secure-link messages browsed from the web console

U

no

0

0

experimental

Correspondent key imported through the API (POST /api/v1/peers)

I

no

0

0

experimental

Discovery lookup queued through the API (POST /api/v1/peers/discover)

I

no

0

0

experimental

Administrative audit log

U

no

0

0

experimental

Opt-in per-message log ([pepsi] MAIL_LOG)

U

no

0

0

experimental

Browser-driven setup (/api/v1/setup + pepsi-setup apply)

U

no

0

0

experimental

Non-interactive wizard (pepsi-setup –answers)

U

no

0

0

experimental

Vacation / out-of-office auto-reply (RFC 3834)

I/U

no

0

0

experimental

Confirm-to-send challenge for unknown senders (pepsi-stage-secretary) (RFC 3834)

I/U

no

0

0

experimental

Mailing lists: domains, lists, members, owners, bans (pepsi-list) (*)

I/U

no

—

—

—

Mailing-list archive storage (hash-partitioned, full-text + trigram) (*)

I/U

no

—

—

—

Mailing-list routing (pepsi-stage-list)

I/U

no

0

0

experimental

Mailing-list posting: moderation chain, handler pipeline and fan-out (pepsi-stage-list-post)

I/U

no

0

0

experimental

Mailing-list per-member delivery: one-click unsubscribe, decoration (pepsi-stage-list-deliver)

I/U

no

0

0

experimental

Mailing-list e-mail commands: join, leave, confirm and the subscription workflows (pepsi-stage-list-command)

I/U

no

0

0

experimental

Mailing-list bounce processing: VERP attribution, 17 detectors, scoring (pepsi-stage-list-bounce)

I/U

no

0

0

experimental

Mailing-list archive: ingest, threading, the two search mechanisms, purge and export (pepsi-archive) (*)

I/U

no

—

—

—

The GNU Mailman 3 REST API (/3.0/ and /3.1/) – upstream 3.3.10, gated on mailmanclient and Postorius’s own suites

I/U

no

0

0

experimental

The public mailing-list web interface: index, subscribe/unsubscribe forms, archive browsing and search

I/U

no

0

0

experimental

RFC 8058 one-click unsubscribe (List-Unsubscribe-Post), honoured whatever the unsubscription policy says (RFC 8058)

I/U

no

0

0

experimental

Member accounts on the public list site: registration, address verification, passwords and password reset, and the member’s own subscription pages

I/U

no

0

0

experimental

The list owner and moderator console: held messages, subscription requests, the generated settings screens, the roster, bans and header matches – authorised by a roster query, not by an operator account

I/U

no

0

0

experimental

Importing a running GNU Mailman 3 site over its own REST API: domains, lists, users, addresses, members, bans and header matches

I/U

no

0

0

experimental

Importing a Mailman 2.1 site from its config.pck files, with upstream’s own attribute mapping and a pickle reader that constructs nothing

I/U

no

0

0

experimental

Importing an mbox archive, with the cleanarch repairs in the reader and an automatic thread rebuild

I/U

no

0

0

experimental

The cutover invitation mailing: a rate, a resume and a per-domain dry run

I/U

no

0

0

experimental

Both digest formats: MIME multipart/digest and RFC 1153 plain, with the volume/number rule and a periodic timer (RFC 1153)

I/U

no

0

0

experimental

The posting-address autoresponder, including respond_and_discard (RFC 3834)

I/U

no

0

0

experimental

Discarding held messages past max_days_to_hold – an attribute that is inert in GNU Mailman 3

I/U

no

0

0

experimental

The 28 GNU Mailman notice templates in all ten shipped languages, with the placeholder audit that catches a translated placeholder name (*)

U

no

—

—

—

The public list and archive pages in English, German and French, chosen from Accept-Language in q-order before any database access (*)

I/U

no

—

—

—