69. Feature stability¶
This single table inventories every feature Pepsi implements and records the current evidence for each feature’s stability. The first three columns are hand-maintained in contrib/feature-registry.tsv; the last three are merged in from anonymous, opt-in usage telemetry (see pepsi-telemetry).
Automated test — whether, and how, the feature is covered by an automated test:
U(a unit / in-processcargo test),I(an integration test — atests/*.shlive-pipeline script or apepsi-test-stagesend-to-end test),I/U(both), or-(no automated test yet).Manual — whether the feature has additionally been verified by hand (
yes/no).Deployments — number of real-world deployments that have reported having the feature enabled.
Uses — number of times the feature has actually been exercised in the field.
Stability — a tier derived from the last two columns:
stable — deployments ≥ 100 and total uses ≥ 100000
used — deployments ≥ 10 and total uses ≥ 1000
experimental — otherwise
A feature marked (*) after its name is not instrumented for telemetry — it is a passive protocol capability, a universal facility, or a short-lived CLI that exits before a usage count could be flushed — so its Deployments, Uses and Stability cells are shown as — (no count can be measured for it).
Until telemetry has been collected the last three columns of every instrumented
feature read 0 / 0 / experimental, and no feature has yet been
through a dedicated by-hand test pass (Manual = no throughout).
Report generated: (not yet generated)
Feature (RFC) |
Automated test |
Manual |
Deployments |
Uses |
Stability |
|---|---|---|---|---|---|
SMTP server core (RFC 5321) |
I/U |
no |
0 |
0 |
experimental |
STARTTLS (RFC 3207) |
I/U |
no |
0 |
0 |
experimental |
Implicit TLS / submissions port (RFC 8314) |
U |
no |
0 |
0 |
experimental |
CHUNKING / BDAT (RFC 3030) |
I/U |
no |
0 |
0 |
experimental |
SIZE declaration and enforcement (RFC 1870) |
I/U |
no |
0 |
0 |
experimental |
PIPELINING (RFC 2920) |
I/U |
no |
0 |
0 |
experimental |
ENHANCEDSTATUSCODES (RFC 2034) (*) |
U |
no |
— |
— |
— |
Received trace header (RFC 5321, RFC 3848) |
I/U |
no |
0 |
0 |
experimental |
Connection / overload limiting |
I/U |
no |
0 |
0 |
experimental |
8BITMIME (RFC 6152) |
I/U |
no |
0 |
0 |
experimental |
SMTPUTF8 (RFC 6531) |
I/U |
no |
0 |
0 |
experimental |
Per-hop 8-bit / UTF-8 downgrade (RFC 2045, RFC 2047) |
I/U |
no |
0 |
0 |
experimental |
Delivery Status Notifications (RFC 3461, RFC 3463, RFC 3464) |
I/U |
no |
0 |
0 |
experimental |
SMTP AUTH (inbound) (RFC 4954) |
U |
no |
0 |
0 |
experimental |
Message submission / MSA (RFC 6409) |
U |
no |
0 |
0 |
experimental |
Client authentication (MYNETWORKS / TLS client cert) |
I/U |
no |
0 |
0 |
experimental |
SPF (RFC 7208) |
U |
no |
0 |
0 |
experimental |
DKIM verification (RFC 6376, RFC 8463) |
I/U |
no |
0 |
0 |
experimental |
DMARC (RFC 7489) |
U |
no |
0 |
0 |
experimental |
iprev / FCrDNS (RFC 8601) |
U |
no |
0 |
0 |
experimental |
Authentication-Results header (RFC 8601) |
U |
no |
0 |
0 |
experimental |
ARC seal and verify (RFC 8617) |
I/U |
no |
0 |
0 |
experimental |
Sender Rewriting Scheme (SRS) (RFC 4648) |
I/U |
no |
0 |
0 |
experimental |
Outbound DKIM signing (RFC 6376, RFC 8463) |
I/U |
no |
0 |
0 |
experimental |
Direct-to-MX relay (RFC 5321) |
I/U |
no |
0 |
0 |
experimental |
Null MX handling (RFC 7505) |
U |
no |
0 |
0 |
experimental |
MTA-STS (RFC 8461) |
U |
no |
0 |
0 |
experimental |
Mail client autoconfiguration (config-v1.1.xml) (draft-ietf-mailmaint-autoconfig) |
U |
no |
0 |
0 |
experimental |
TLS server-identity verification (RFC 6125) |
U |
no |
0 |
0 |
experimental |
Smarthost relay (RFC 5321) |
I/U |
no |
0 |
0 |
experimental |
Smarthost SASL mechanisms (RFC 4954, RFC 4616, RFC 5802, RFC 7628) |
U |
no |
0 |
0 |
experimental |
DANE / TLSA (RFC 7672) |
U |
no |
0 |
0 |
experimental |
SMTP TLS Reporting (TLSRPT) (RFC 8460) |
I/U |
no |
0 |
0 |
experimental |
Maildir local delivery |
I/U |
no |
0 |
0 |
experimental |
LMTP local delivery + MDA Sieve (RFC 2033, RFC 5228) |
I/U |
no |
0 |
0 |
experimental |
~/.forward processing |
I/U |
no |
0 |
0 |
experimental |
Alias / virtual-map expansion |
I/U |
no |
0 |
0 |
experimental |
Milter mail-filter client (post-queue) |
I/U |
no |
0 |
0 |
experimental |
Pay-to-send anti-spam gate (GNU Taler) |
I/U |
no |
0 |
0 |
experimental |
Auto-pay wallet (GNU Taler) |
I/U |
no |
0 |
0 |
experimental |
Sender whitelist check |
I/U |
no |
0 |
0 |
experimental |
Auto-whitelist (outbound) |
I/U |
no |
0 |
0 |
experimental |
Language detection |
I/U |
no |
0 |
0 |
experimental |
Language blocking |
I/U |
no |
0 |
0 |
experimental |
Conditional branch stage |
U |
no |
0 |
0 |
experimental |
Edit-settings-by-email |
I/U |
no |
0 |
0 |
experimental |
Per-address settings overrides |
I/U |
no |
0 |
0 |
experimental |
Bounce generation (RFC 3464) |
I/U |
no |
0 |
0 |
experimental |
Discard sink |
no |
0 |
0 |
experimental |
|
Single-table queue and crash recovery |
I |
no |
0 |
0 |
experimental |
Pipelined worker pools and watchdog |
I |
no |
0 |
0 |
experimental |
Stage fusion |
I |
no |
0 |
0 |
experimental |
HTTP server (MTA-STS policy + metrics) (RFC 8461) |
I/U |
no |
0 |
0 |
experimental |
Prometheus metrics |
I |
no |
0 |
0 |
experimental |
Provisioning and DNS verification (*) |
I/U |
no |
— |
— |
— |
Migration from an existing MTA (Postfix/Exim/Sendmail/qmail/Stalwart) (*) |
U |
no |
— |
— |
— |
Queue operator CLI (pepsi-queue) (*) |
no |
— |
— |
— |
|
Health summary (pepsi-status) (*) |
U |
no |
— |
— |
— |
Language-detection diagnostics (pepsi-detect-language) (*) |
U |
no |
— |
— |
— |
Local submission socket (peer-credential auth) (RFC 6409) |
U |
no |
0 |
0 |
experimental |
Sendmail-compatible client (pepsi-sendmail) (*) |
I/U |
no |
— |
— |
— |
Whitelist CLI (pepsi-whitelist) (*) |
I |
no |
— |
— |
— |
Per-user whitelist namespaces (<login>/name) (*) |
I/U |
no |
— |
— |
— |
Whitelist import from a mailbox (mbox/Maildir) (*) |
I/U |
no |
— |
— |
— |
Whitelist import over IMAP (*) |
U |
no |
— |
— |
— |
Whitelist import via doveadm (*) |
U |
no |
— |
— |
— |
Whitelist wildcard proposals + hoster exclusion (*) |
I/U |
no |
— |
— |
— |
End-to-end key store (identities, peer keys, CA trust) (*) |
I/U |
no |
— |
— |
— |
Private keys AEAD-wrapped under a secrets.d KEK |
U |
no |
0 |
0 |
experimental |
Private-key column restricted to the pepsi-crypto role (*) |
I |
no |
— |
— |
— |
Key-store CLI (pepsi-keys) (*) |
I |
no |
— |
— |
— |
OpenPGP key generation (Ed25519 / RSA) |
U |
no |
0 |
0 |
experimental |
S/MIME certificate + CSR issuance (self-signed) |
U |
no |
0 |
0 |
experimental |
S/MIME single-certificate mode (CRYPTO_SMIME_SHARED_KEY) |
U |
no |
0 |
0 |
experimental |
Key discovery: WKD advanced (openpgpkey.<domain>) (draft-koch-openpgp-webkey-service) |
I/U |
no |
0 |
0 |
experimental |
Key discovery: WKD direct (draft-koch-openpgp-webkey-service) |
I/U |
no |
0 |
0 |
experimental |
Key discovery: DANE OPENPGPKEY / SMIMEA (RFC 7929, RFC 8162) |
U |
no |
0 |
0 |
experimental |
Key discovery: verifying key server (VKS/HKP) |
U |
no |
0 |
0 |
experimental |
Key discovery: LDAP directory (feature-gated) (RFC 4511) |
no |
0 |
0 |
experimental |
|
Key harvesting from inbound mail + Autocrypt |
U |
no |
0 |
0 |
experimental |
Key learning from Autocrypt-Gossip inside a decrypted message (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
Park-on-missing-key (asynchronous discovery) |
I/U |
no |
0 |
0 |
experimental |
Outbound end-to-end signing and encryption (pepsi-stage-encrypt) (RFC 3156, RFC 8551) |
U |
no |
0 |
0 |
experimental |
Outbound OpenPGP (PGP/MIME) encryption (RFC 3156, RFC 9580) |
U |
no |
0 |
0 |
experimental |
Outbound S/MIME (CMS) encryption (RFC 8551, RFC 5083) |
U |
no |
0 |
0 |
experimental |
Outbound end-to-end signature without encryption (RFC 3156, RFC 8551) |
U |
no |
0 |
0 |
experimental |
Per-recipient container downgrade (SEIPDv1 / CBC) (RFC 4880) |
no |
0 |
0 |
experimental |
|
Autocrypt key advertisement on outbound mail (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
Autocrypt key gossip: the other To/Cc recipients’ keys inside the ciphertext (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
Keyless recipient routed to the secure-link portal |
no |
0 |
0 |
experimental |
|
Secure-link fallback portal: store an unencryptable message |
I/U |
no |
0 |
0 |
experimental |
Secure-link portal endpoints served by pepsi-httpd |
I/U |
no |
0 |
0 |
experimental |
Secure-link message opened with the correct PIN |
I |
no |
0 |
0 |
experimental |
Secure-link PIN refused (lockout counter) |
I |
no |
0 |
0 |
experimental |
Reply composed through the secure-link portal |
I |
no |
0 |
0 |
experimental |
Secure-link second factor mailed to the sender |
U |
no |
0 |
0 |
experimental |
Secure-link second factor handed to a gateway command |
no |
0 |
0 |
experimental |
|
Secure-link with no second factor (link only, weaker) |
U |
no |
0 |
0 |
experimental |
Lazy identity creation on an explicit protection request |
no |
0 |
0 |
experimental |
|
Inbound end-to-end decryption and signature verification (pepsi-stage-decrypt) (RFC 3156, RFC 8551) |
U |
no |
0 |
0 |
experimental |
Inbound message actually decrypted (RFC 3156, RFC 8551) |
U |
no |
0 |
0 |
experimental |
Inbound OpenPGP (PGP/MIME, inline) decryption (RFC 3156, RFC 9580) |
U |
no |
0 |
0 |
experimental |
Inbound S/MIME (CMS) decryption (RFC 8551, RFC 5083) |
U |
no |
0 |
0 |
experimental |
Inbound signature valid against a trusted key (RFC 3156, RFC 8551) |
U |
no |
0 |
0 |
experimental |
Inbound signature valid but the key is unanchored (TOFU) |
U |
no |
0 |
0 |
experimental |
Inbound signature that did not verify |
U |
no |
0 |
0 |
experimental |
Inbound ciphertext this host could not open |
U |
no |
0 |
0 |
experimental |
Inbound OpenPGP plaintext over the decompression cap |
no |
0 |
0 |
experimental |
|
Autocrypt key learning from inbound mail (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
Keys learnt inline from an inbound message (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
Re-verification using a certificate found in the plaintext |
no |
0 |
0 |
experimental |
|
Third parties’ keys learnt from a decrypted message’s gossip fields (Autocrypt Level 1) |
U |
no |
0 |
0 |
experimental |
Inbound crypto failure routed to a quarantine stage |
U |
no |
0 |
0 |
experimental |
Inbound crypto failure bounced |
U |
no |
0 |
0 |
experimental |
Key publication: Web Key Directory endpoints (draft-koch-openpgp-webkey-service) |
I/U |
no |
0 |
0 |
experimental |
Key publication: key-server upload + verification retry (*) |
U |
no |
— |
— |
— |
Key publication: auto-confirm the key server’s verification mail |
U |
no |
0 |
0 |
experimental |
Recipient-domain routing to a next hop (pepsi-stage-route) |
I/U |
no |
0 |
0 |
experimental |
Outlook add-in served by pepsi-httpd (manifest + task pane) |
U |
no |
0 |
0 |
experimental |
Per-next-hop IP address family selection (ADDRESS_FAMILY) |
U |
no |
0 |
0 |
experimental |
Settings CLI (pepsi-settings) (*) |
I/U |
no |
— |
— |
— |
Configuration in the database (scope chain + hot reload) |
I/U |
no |
0 |
0 |
experimental |
Config CLI (pepsi-config) (*) |
I |
no |
— |
— |
— |
Encrypted configuration export/import (*) |
U |
no |
— |
— |
— |
Failure bouncer (pepsi-failure-bouncer) |
no |
0 |
0 |
experimental |
|
Smarthost OAuth token-refresh helper (*) |
U |
no |
— |
— |
— |
Structured logging (*) |
U |
no |
— |
— |
— |
Feature telemetry (*) |
U |
no |
— |
— |
— |
Administrative REST API (/api/v1) |
I/U |
no |
0 |
0 |
experimental |
Administration web console (/ui) |
U |
no |
0 |
0 |
experimental |
Setup interview driven from the web console |
U |
no |
0 |
0 |
experimental |
Secure-link messages browsed from the web console |
U |
no |
0 |
0 |
experimental |
Correspondent key imported through the API (POST /api/v1/peers) |
I |
no |
0 |
0 |
experimental |
Discovery lookup queued through the API (POST /api/v1/peers/discover) |
I |
no |
0 |
0 |
experimental |
Administrative audit log |
U |
no |
0 |
0 |
experimental |
Opt-in per-message log ([pepsi] MAIL_LOG) |
U |
no |
0 |
0 |
experimental |
Browser-driven setup (/api/v1/setup + pepsi-setup apply) |
U |
no |
0 |
0 |
experimental |
Non-interactive wizard (pepsi-setup –answers) |
U |
no |
0 |
0 |
experimental |
Vacation / out-of-office auto-reply (RFC 3834) |
I/U |
no |
0 |
0 |
experimental |