.. This file is part of PEPSI. Copyright (C) 2026 GNUnet e.V. PEPSI is free software; you can redistribute it and/or modify it under the terms of the GNU Affero General Public License as published by the Free Software Foundation; either version 3, or (at your option) any later version. GENERATED FILE -- do not edit by hand. Regenerate with contrib/update-feature-stability.sh, which merges the hand-maintained registry contrib/feature-registry.tsv with a pepsi-telemetry GET /telemetry/report. See docs/manual/extending.rst and docs/manual/programs/pepsi-telemetry.rst. ================= Feature stability ================= This single table inventories every feature Pepsi implements and records the current evidence for each feature's stability. The first three columns are hand-maintained in contrib/feature-registry.tsv; the last three are merged in from anonymous, opt-in usage telemetry (see :doc:`programs/pepsi-telemetry`). * **Automated test** — whether, and how, the feature is covered by an automated test: ``U`` (a unit / in-process ``cargo test``), ``I`` (an integration test — a ``tests/*.sh`` live-pipeline script or a ``pepsi-test-stages`` end-to-end test), ``I/U`` (both), or ``-`` (no automated test yet). * **Manual** — whether the feature has additionally been verified by hand (``yes``/``no``). * **Deployments** — number of real-world deployments that have reported having the feature enabled. * **Uses** — number of times the feature has actually been exercised in the field. * **Stability** — a tier derived from the last two columns: * **stable** — deployments ≥ 100 and total uses ≥ 100000 * **used** — deployments ≥ 10 and total uses ≥ 1000 * **experimental** — otherwise A feature marked **(*)** after its name is not instrumented for telemetry — it is a passive protocol capability, a universal facility, or a short-lived CLI that exits before a usage count could be flushed — so its **Deployments**, **Uses** and **Stability** cells are shown as — (no count can be measured for it). The counts below come from https://telemetry.pepsi.taler.net/telemetry/report. An instrumented feature with no count in it reads ``0`` / ``0`` / ``experimental``: no reporting deployment has exercised it since its telemetry daemon last started. The collector does not authenticate submissions, so read the counts as an indication, not a measurement. No feature has yet been through a dedicated by-hand test pass (**Manual** = ``no`` throughout). *Report generated:* 2026-09-28T23:22:26Z .. list-table:: Feature stability :header-rows: 1 :widths: 34 12 8 12 8 13 * - Feature (RFC) - Automated test - Manual - Deployments - Uses - Stability * - SMTP server core (RFC 5321) - I/U - no - 1 - 141 - experimental * - STARTTLS (RFC 3207) - I/U - no - 1 - 830 - experimental * - Implicit TLS / submissions port (RFC 8314) - U - no - 0 - 0 - experimental * - CHUNKING / BDAT (RFC 3030) - I/U - no - 1 - 18 - experimental * - SIZE declaration and enforcement (RFC 1870) - I/U - no - 1 - 129 - experimental * - PIPELINING (RFC 2920) - I/U - no - 1 - 111 - experimental * - ENHANCEDSTATUSCODES (RFC 2034) (*) - U - no - — - — - — * - Received trace header (RFC 5321, RFC 3848) - I/U - no - 1 - 141 - experimental * - Connection / overload limiting - I/U - no - 0 - 0 - experimental * - 8BITMIME (RFC 6152) - I/U - no - 1 - 43 - experimental * - SMTPUTF8 (RFC 6531) - I/U - no - 1 - 8 - experimental * - Per-hop 8-bit / UTF-8 downgrade (RFC 2045, RFC 2047) - I/U - no - 0 - 0 - experimental * - Delivery Status Notifications (RFC 3461, RFC 3463, RFC 3464) - I/U - no - 1 - 88 - experimental * - SMTP AUTH (inbound) (RFC 4954) - U - no - 1 - 16 - experimental * - Message submission / MSA (RFC 6409) - U - no - 1 - 17 - experimental * - Client authentication (MYNETWORKS / TLS client cert) - I/U - no - 0 - 0 - experimental * - SPF (RFC 7208) - U - no - 1 - 140 - experimental * - DKIM verification (RFC 6376, RFC 8463) - I/U - no - 1 - 91 - experimental * - DMARC (RFC 7489) - U - no - 1 - 95 - experimental * - iprev / FCrDNS (RFC 8601) - U - no - 1 - 140 - experimental * - Authentication-Results header (RFC 8601) - U - no - 1 - 141 - experimental * - ARC seal and verify (RFC 8617) - I/U - no - 1 - 124 - experimental * - Sender Rewriting Scheme (SRS) - I/U - no - 0 - 0 - experimental * - Outbound DKIM signing (RFC 6376, RFC 8463) - I/U - no - 1 - 23 - experimental * - Direct-to-MX relay (RFC 5321) - I/U - no - 1 - 53 - experimental * - Null MX handling (RFC 7505) - U - no - 0 - 0 - experimental * - MTA-STS (RFC 8461) - U - no - 1 - 4 - experimental * - Mail client autoconfiguration (config-v1.1.xml) (draft-ietf-mailmaint-autoconfig) - U - no - 0 - 0 - experimental * - TLS server-identity verification (RFC 6125) - U - no - 1 - 53 - experimental * - Smarthost relay (RFC 5321) - I/U - no - 0 - 0 - experimental * - Smarthost SASL mechanisms (RFC 4954, RFC 4616, RFC 5802, RFC 7628) - U - no - 0 - 0 - experimental * - DANE / TLSA (RFC 7672) - U - no - 0 - 0 - experimental * - SMTP TLS Reporting (TLSRPT) (RFC 8460) - I/U - no - 1 - 43 - experimental * - Maildir local delivery - I/U - no - 1 - 119 - experimental * - Mailbox quota enforcement (Maildir++ / quotactl) - I/U - no - 0 - 0 - experimental * - Mailbox quota CLI and reconciliation (pepsi-quota) (*) - I - no - — - — - — * - LMTP local delivery + MDA Sieve (RFC 2033, RFC 5228) - I/U - no - 0 - 0 - experimental * - ~/.forward processing - I/U - no - 0 - 0 - experimental * - Alias / virtual-map expansion - I/U - no - 1 - 119 - experimental * - Milter mail-filter client (post-queue) - I/U - no - 0 - 0 - experimental * - Pay-to-send anti-spam gate (GNU Taler) - I/U - no - 0 - 0 - experimental * - Auto-pay wallet (GNU Taler) - I/U - no - 1 - 17 - experimental * - Sender whitelist check - I/U - no - 0 - 0 - experimental * - Auto-whitelist (outbound) - I/U - no - 1 - 17 - experimental * - Language detection - I/U - no - 1 - 63 - experimental * - Language blocking - I/U - no - 1 - 63 - experimental * - Conditional branch stage - U - no - 1 - 141 - experimental * - Edit-settings-by-email - I/U - no - 1 - 17 - experimental * - Per-address settings overrides - I/U - no - 0 - 0 - experimental * - Bounce generation (RFC 3464) - I/U - no - 1 - 7 - experimental * - Discard sink - - - no - 0 - 0 - experimental * - Single-table queue and crash recovery - I - no - 0 - 0 - experimental * - Pipelined worker pools and watchdog - I - no - 1 - 1 - experimental * - Stage fusion - I - no - 1 - 17 - experimental * - HTTP server (MTA-STS policy + metrics) (RFC 8461) - I/U - no - 0 - 0 - experimental * - Prometheus metrics - I - no - 0 - 0 - experimental * - Provisioning and DNS verification (*) - I/U - no - — - — - — * - Migration from an existing MTA (Postfix/Exim/Sendmail/qmail/Stalwart) (*) - U - no - — - — - — * - Queue operator CLI (pepsi-queue) (*) - - - no - — - — - — * - Health summary (pepsi-status) (*) - U - no - — - — - — * - Language-detection diagnostics (pepsi-detect-language) (*) - U - no - — - — - — * - Local submission socket (peer-credential auth) (RFC 6409) - U - no - 1 - 2 - experimental * - Sendmail-compatible client (pepsi-sendmail) (*) - I/U - no - — - — - — * - Whitelist CLI (pepsi-whitelist) (*) - I - no - — - — - — * - Per-user whitelist namespaces (/name) (*) - I/U - no - — - — - — * - Whitelist import from a mailbox (mbox/Maildir) (*) - I/U - no - — - — - — * - Whitelist import over IMAP (*) - U - no - — - — - — * - Whitelist import via doveadm (*) - U - no - — - — - — * - Whitelist wildcard proposals + hoster exclusion (*) - I/U - no - — - — - — * - End-to-end key store (identities, peer keys, CA trust) (*) - I/U - no - — - — - — * - Private keys AEAD-wrapped under a secrets.d KEK - U - no - 0 - 0 - experimental * - Private-key column restricted to the pepsi-crypto role (*) - I - no - — - — - — * - Key-store CLI (pepsi-keys) (*) - I - no - — - — - — * - OpenPGP key generation (Ed25519 / RSA) - U - no - 0 - 0 - experimental * - S/MIME certificate + CSR issuance (self-signed) - U - no - 0 - 0 - experimental * - S/MIME single-certificate mode (CRYPTO_SMIME_SHARED_KEY) - U - no - 0 - 0 - experimental * - Key discovery: WKD advanced (openpgpkey.) (draft-koch-openpgp-webkey-service) - I/U - no - 0 - 0 - experimental * - Key discovery: WKD direct (draft-koch-openpgp-webkey-service) - I/U - no - 0 - 0 - experimental * - Key discovery: DANE OPENPGPKEY / SMIMEA (RFC 7929, RFC 8162) - U - no - 0 - 0 - experimental * - Key discovery: verifying key server (VKS) - U - no - 0 - 0 - experimental * - Key discovery: LDAP directory (feature-gated) (RFC 4511) - U - no - 0 - 0 - experimental * - Key harvesting from inbound mail + Autocrypt - U - no - 0 - 0 - experimental * - Key learning from Autocrypt-Gossip inside a decrypted message (Autocrypt Level 1) - U - no - 0 - 0 - experimental * - Park-on-missing-key (asynchronous discovery) - I/U - no - 0 - 0 - experimental * - Outbound end-to-end signing and encryption (pepsi-stage-encrypt) (RFC 3156, RFC 8551) - I/U - no - 0 - 0 - experimental * - Outbound OpenPGP (PGP/MIME) encryption (RFC 3156, RFC 9580) - U - no - 0 - 0 - experimental * - Outbound S/MIME (CMS) encryption (RFC 8551, RFC 5083) - U - no - 0 - 0 - experimental * - Outbound end-to-end signature without encryption (RFC 3156, RFC 8551) - U - no - 0 - 0 - experimental * - Per-recipient container downgrade (SEIPDv1 / CBC) (RFC 4880) - U - no - 0 - 0 - experimental * - Autocrypt key advertisement on outbound mail (Autocrypt Level 1) - U - no - 0 - 0 - experimental * - Autocrypt key gossip: the other To/Cc recipients' keys inside the ciphertext (Autocrypt Level 1) - U - no - 0 - 0 - experimental * - Keyless recipient routed to the secure-link portal - I/U - no - 0 - 0 - experimental * - Secure-link fallback portal: store an unencryptable message - I/U - no - 0 - 0 - experimental * - Secure-link portal endpoints served by pepsi-httpd - I/U - no - 0 - 0 - experimental * - Secure-link message opened with the correct PIN - I - no - 0 - 0 - experimental * - Secure-link PIN refused (lockout counter) - I - no - 0 - 0 - experimental * - Reply composed through the secure-link portal - I - no - 0 - 0 - experimental * - Secure-link second factor mailed to the sender - U - no - 0 - 0 - experimental * - Secure-link second factor handed to a gateway command - - - no - 0 - 0 - experimental * - Secure-link with no second factor (link only, weaker) - U - no - 0 - 0 - experimental * - Identity creation on request (an explicit protection request, or SIGN = always) - I/U - no - 0 - 0 - experimental * - pEp preset: a key generated for a sender on first submission (ENABLE_PEP) - I - no - 0 - 0 - experimental * - A user's own (MUA) key registered from a submitted Autocrypt header or key file (Autocrypt Level 1) - I - no - 0 - 0 - experimental * - Sender's public key attached as a file (ATTACH_KEYS_AS_FILES) (RFC 3156) - I/U - no - 0 - 0 - experimental * - Key self-service by e-mail (status, generate, register, publish, retire) - I/U - no - 0 - 0 - experimental * - Inbound end-to-end decryption and signature verification (pepsi-stage-decrypt) (RFC 3156, RFC 8551) - I/U - no - 0 - 0 - experimental * - Inbound message actually decrypted (RFC 3156, RFC 8551) - U - no - 0 - 0 - experimental * - Inbound OpenPGP (PGP/MIME, inline) decryption (RFC 3156, RFC 9580) - U - no - 0 - 0 - experimental * - Inbound S/MIME (CMS) decryption (RFC 8551, RFC 5083) - U - no - 0 - 0 - experimental * - Inbound signature valid against a trusted key (RFC 3156, RFC 8551) - U - no - 0 - 0 - experimental * - Inbound signature valid but the key is unanchored (TOFU) - U - no - 0 - 0 - experimental * - Inbound signature that did not verify - U - no - 0 - 0 - experimental * - Inbound ciphertext this host could not open - U - no - 0 - 0 - experimental * - Inbound OpenPGP plaintext over the decompression cap - U - no - 0 - 0 - experimental * - Autocrypt key learning from inbound mail (Autocrypt Level 1) - I/U - no - 0 - 0 - experimental * - Keys learnt inline from an inbound message (Autocrypt Level 1) - U - no - 0 - 0 - experimental * - Re-verification using a certificate found in the plaintext - - - no - 0 - 0 - experimental * - Third parties' keys learnt from a decrypted message's gossip fields (Autocrypt Level 1) - U - no - 0 - 0 - experimental * - A correspondent's Autocrypt key replaced by a newer one (audited, users notified) (Autocrypt Level 1) - I/U - no - 0 - 0 - experimental * - A newer Autocrypt key refused because the stored one is alive (ACCEPT_ROTATION = expired) - I/U - no - 0 - 0 - experimental * - Inbound crypto failure routed to a quarantine stage - U - no - 0 - 0 - experimental * - Inbound crypto failure bounced - U - no - 0 - 0 - experimental * - Inbound mail encrypted to a user's own (MUA) key passed through unopened (RFC 3156, RFC 8551) - I - no - 0 - 0 - experimental * - Decrypted inbound mail re-encrypted to the recipient's own (MUA) key for storage (pepsi-stage-reencrypt) (RFC 3156, RFC 8551) - I/U - no - 0 - 0 - experimental * - Storage re-encryption to an OpenPGP MUA key (RFC 3156, RFC 9580) - I/U - no - 0 - 0 - experimental * - Storage re-encryption to an S/MIME MUA key (RFC 8551, RFC 5083) - U - no - 0 - 0 - experimental * - Decrypted mail filed in plaintext: the recipient has no MUA key (ON_NO_CLIENT_KEY = plaintext) - I - no - 0 - 0 - experimental * - A recipient's MUA key that could not be sealed to - - - no - 0 - 0 - experimental * - Decrypted mail refused for want of an MUA key (ON_NO_CLIENT_KEY = bounce) (RFC 3463) - I - no - 0 - 0 - experimental * - Proof recorded that a correspondent holds our key (stops the key file) - I/U - no - 0 - 0 - experimental * - Key publication: Web Key Directory endpoints (draft-koch-openpgp-webkey-service) - I/U - no - 0 - 0 - experimental * - Key publication: key-server upload + verification retry (*) - U - no - — - — - — * - Key publication: auto-confirm the key server's verification mail - U - no - 0 - 0 - experimental * - Recipient-domain routing to a next hop (pepsi-stage-route) - I/U - no - 0 - 0 - experimental * - Outlook add-in served by pepsi-httpd (manifest + task pane) - U - no - 0 - 0 - experimental * - Per-next-hop IP address family selection (ADDRESS_FAMILY) - U - no - 0 - 0 - experimental * - Settings CLI (pepsi-settings) (*) - I/U - no - — - — - — * - Configuration in the database (scope chain + hot reload) - I/U - no - 0 - 0 - experimental * - Config CLI (pepsi-config) (*) - I - no - — - — - — * - Encrypted configuration export/import (*) - U - no - — - — - — * - Failure bouncer (pepsi-failure-bouncer) - - - no - 0 - 0 - experimental * - Smarthost OAuth token-refresh helper (*) - U - no - — - — - — * - Structured logging (*) - U - no - — - — - — * - Feature telemetry (*) - U - no - — - — - — * - Administrative REST API (/api/v1) - I/U - no - 0 - 0 - experimental * - Administration web console (/ui) - U - no - 0 - 0 - experimental * - Setup interview driven from the web console - U - no - 0 - 0 - experimental * - Secure-link messages browsed from the web console - U - no - 0 - 0 - experimental * - Correspondent key imported through the API (POST /api/v1/peers) - I - no - 0 - 0 - experimental * - Discovery lookup queued through the API (POST /api/v1/peers/discover) - I - no - 0 - 0 - experimental * - Administrative audit log - U - no - 0 - 0 - experimental * - Opt-in per-message log ([pepsi] MAIL_LOG) - U - no - 0 - 0 - experimental * - Browser-driven setup (/api/v1/setup + pepsi-setup apply) - U - no - 0 - 0 - experimental * - Non-interactive wizard (pepsi-setup --answers) - U - no - 0 - 0 - experimental * - Vacation / out-of-office auto-reply (RFC 3834) - I/U - no - 0 - 0 - experimental * - Confirm-to-send challenge for unknown senders (pepsi-stage-secretary) (RFC 3834) - I/U - no - 0 - 0 - experimental * - Mailing lists: domains, lists, members, owners, bans (pepsi-list) (*) - I/U - no - — - — - — * - Mailing-list archive storage (hash-partitioned, full-text + trigram) (*) - I/U - no - — - — - — * - Mailing-list routing (pepsi-stage-list) - I/U - no - 0 - 0 - experimental * - Mailing-list posting: moderation chain, handler pipeline and fan-out (pepsi-stage-list-post) - I/U - no - 0 - 0 - experimental * - Mailing-list per-member delivery: one-click unsubscribe, decoration (pepsi-stage-list-deliver) - I/U - no - 0 - 0 - experimental * - Mailing-list e-mail commands: join, leave, confirm and the subscription workflows (pepsi-stage-list-command) - I/U - no - 0 - 0 - experimental * - Mailing-list bounce processing: VERP attribution, 17 detectors, scoring (pepsi-stage-list-bounce) - I/U - no - 0 - 0 - experimental * - Mailing-list archive: ingest, threading, the two search mechanisms, purge and export (pepsi-archive) (*) - I/U - no - — - — - — * - The GNU Mailman 3 REST API (/3.0/ and /3.1/) -- upstream 3.3.10, gated on mailmanclient and Postorius's own suites - I/U - no - 0 - 0 - experimental * - The public mailing-list web interface: index, subscribe/unsubscribe forms, archive browsing and search - I/U - no - 0 - 0 - experimental * - RFC 8058 one-click unsubscribe (List-Unsubscribe-Post), honoured whatever the unsubscription policy says (RFC 8058) - I/U - no - 0 - 0 - experimental * - Member accounts on the public list site: registration, address verification, passwords and password reset, and the member's own subscription pages - I/U - no - 0 - 0 - experimental * - The list owner and moderator console: held messages, subscription requests, the generated settings screens, the roster, bans and header matches -- authorised by a roster query, not by an operator account - I/U - no - 0 - 0 - experimental * - Importing a running GNU Mailman 3 site over its own REST API: domains, lists, users, addresses, members, bans and header matches - I/U - no - 0 - 0 - experimental * - Importing a Mailman 2.1 site from its config.pck files, with upstream's own attribute mapping and a pickle reader that constructs nothing - I/U - no - 0 - 0 - experimental * - Importing an mbox archive, with the cleanarch repairs in the reader and an automatic thread rebuild - I/U - no - 0 - 0 - experimental * - The cutover invitation mailing: a rate, a resume and a per-domain dry run - I/U - no - 0 - 0 - experimental * - Both digest formats: MIME multipart/digest and RFC 1153 plain, with the volume/number rule and a periodic timer (RFC 1153) - I/U - no - 0 - 0 - experimental * - The posting-address autoresponder, including respond_and_discard (RFC 3834) - I/U - no - 0 - 0 - experimental * - Discarding held messages past max_days_to_hold -- an attribute that is inert in GNU Mailman 3 - I/U - no - 0 - 0 - experimental * - The 28 GNU Mailman notice templates in all ten shipped languages, with the placeholder audit that catches a translated placeholder name (*) - U - no - — - — - — * - The public list and archive pages in English, German and French, chosen from Accept-Language in q-order before any database access (*) - I/U - no - — - — - —