NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1170 by repository stars
Last release 23 days ago
15 Sep 2026
Release timing varies
gaps range from 9 days to 9 months
Most releases are documented
notes for 11 of 13 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
65 releases · first in 2020
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
A reported vulnerability in this library, two more reachable from Verify through its dependencies, a crash reachable from AddDisposableDomains , and t…
A reported vulnerability in this library, two more reachable from Verify through its dependencies, a crash reachable from AddDisposableDomains, and the domain lists rebuilt from sources that had stopped being what they claimed. Requires Go 1.25.
Go 1.25 or newer is required. The versions of golang.org/x/net and golang.org/x/text that carry the fixes below require it. Supported versions are now the three most recent Go releases; CI covers all three.
YAHOO is gone. emailverifier.YAHOO no longer compiles. The Yahoo API verifier it selected had stopped working — Yahoo removed the endpoint it relied on — so EnableAPIVerifier(YAHOO) was returning success for a check that could not run. Remove the call; there is no replacement.
LookupError has an unexported field. It still compiles, but comparing a whole LookupError against a literal no longer matches. Compare Message, or use errors.Is/errors.As, which now reach the underlying error. This is the same change that fixes GHSA-c2j9-vjcj-qrjc below.
*LookupError (GHSA-c2j9-vjcj-qrjc) — ParseSMTPError could return a nil *LookupError for a non-nil input. Assigned to an error, that is a non-nil interface holding a nil pointer, and calling Error() on it panics. Affects <= 1.4.1; v1.5.0 is the first release carrying the fix, which had landed before the report arrived. (#202)golang.org/x/text infinite loop (GO-2026-5970) — reachable from Verify, CheckMX and CheckSMTP through idna.ToASCII. The argument is the address under test, so an address chosen by whoever is being verified could hang the goroutine verifying it. (#212)golang.org/x/net/idna accepting ASCII-only Punycode labels (GO-2026-5026) — same path. (#212)AddDisposableDomains racing the auto-update refresh. Calling it from another goroutine while EnableAutoUpdateDisposable()'s refresh was running was a fatal error: concurrent map iteration and map write — the process goes down and no recover catches it. (#211)EnableAutoUpdateDisposable() used to gut the disposable list. The baked-in list and the one fetched at runtime came from different upstreams sharing 28% of their entries, and the refresh deletes whatever the fetched list omits. The first refresh replaced most of the list; it is now a no-op. (#208)IsRoleAccount("cto") returned false. cto, ctos, cfo and cfos were added to the source list in December 2025 and the generated map was never rebuilt. (#205)IsFreeDomain("atlanticbb.net") returned false. The generated key carried a stray no-break space from an upstream entry. (#207)Verify discarded the SMTP result when the exchange failed partway. SMTP came back nil, which could not distinguish a host that never answered from one that answered and refused the sender. It is now kept, whether or not the check succeeded. (#201)Reachable was unknown for a domain whose MX lookup says no such host. It is no now, and Verify returns ErrNoSuchHost. (#139)Suggestion was empty for disposable domains, which returned early before the suggestion was computed. (#140)These change what the library answers without needing any change to your code. Counts are against v1.4.1; both lists also moved in commits that never reached a release, so the deltas are larger than any single change here.
IsDisposable: 121,862 domains to 75,258 — 40,392 added, 86,996 removed — the generated list now coming from the same source the runtime refresh fetches. Sampled, the removals are overwhelmingly domains that no longer resolve at all, and all 20 well-known throwaway services checked are still reported disposable. (#208)IsFreeDomain and SuggestDomain: 6,482 domains to 4,535 — 110 added, 2,057 removed. Two sources that carried throwaway domains under a free label are gone: one dropped in #169, which accounts for 2,009 of the removals, and the other, which had begun merging disposable blocklists into its own output, replaced here by the sources it aggregates. Of the additions, 96 are carrier and portal mailboxes recognised for the first time — docomo.ne.jp, ocn.ne.jp, kakao.com, chollian.net, aol.co.uk and proton.me among them — and the remaining 14 are providers the previous sources had missed, including duck.com, mailfence.com and zohomail.com. (#207, #169)hush.com, lavabit.com, mail2world.com, qmail.com, 4x4man.com, alphafrau.de. (#209)IsRoleAccount: 888 role names to 892, none removed. (#205)Resolver() sets a custom *net.Resolver for MX and SMTP host lookups. (#191)cmd/build_metadata/update.sh no longer publishes a truncated or empty list when a fetch fails, and refuses to publish when a list falls outside expected bounds. (#206)golangci-lint v2.13.2, actions/checkout v7, actions/setup-go v7, golangci-lint-action v9. (#212)go.mod requires the oldest of them, Go 1.25. The versions of golang.org/x/net and golang.org/x/text that fix GO-2026-5026 and GO-2026-5970 require it, and both were reachable from Verify, CheckMX and CheckSMTP through idna.ToASCII -- the second of them an infinite loop on caller-supplied input #212AddDisposableDomains no longer races the refresh that EnableAutoUpdateDisposable() schedules. Calling it from another goroutine while a refresh was running was a fatal error: concurrent map iteration and map write, which brings the process down and no recover can catch #211cmd/build_metadata/disposable_allowlist.txt, keeps real providers the upstream list misclassifies out of the disposable set -- currently hush.com, lavabit.com, mail2world.com, qmail.com, 4x4man.com and alphafrau.de. It applies to the generated list and to every EnableAutoUpdateDisposable() refresh, and since the free list is the free candidates minus the disposable one, these domains are now reported free rather than neither #209EnableAutoUpdateDisposable() fetches at runtime. The two had diverged, so enabling auto-update used to replace most of the baked-in list; it is now a no-op. IsDisposable gains 37679 domains and loses 96017, the vast majority of which no longer resolve #208IsFreeDomain and SuggestDomain no longer treat throwaway domains as free providers, 108 carrier and portal mailboxes are recognised, and IsFreeDomain("atlanticbb.net") works -- the generated key carried a stray no-break space #207IsRoleAccount recognises cto, ctos, cfo and cfos. They were added to the source list in December 2025 but the generated map was never rebuilt, so they returned false until now #205Resolver() #191Verify keeps the SMTP result when the exchange fails partway. SMTP used to come back nil, which could not distinguish a host that never answered from one that answered and refused the sender #201Reachable is no, not unknown, when the MX lookup fails with no such host, and Verify returns ErrNoSuchHost #139Suggestion is filled in for disposable domains, which used to return early before the suggestion was computed #140IsFreeDomain loses 2,009 domains it should not have had #169LookupError wraps the error it was derived from, reachable via errors.Is/errors.As. ParseSMTPError no longer returns a nil *LookupError for a non-nil input. Adds an unexported field, so whole-struct comparison against a LookupError literal no longer matches #202EnableAPIVerifier(YAHOO) and the YAHOO constant are gone #198Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add support for configurable timeouts in SMTP verification by @eos175 in #110
Full Changelog: v1.4.0...v1.4.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Feature: Support Gmail&Yahoo SMTP check by API #88
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Making catchAll detection optional #76
EnableAutoUpdateDisposable(), the disposable domains configuration is updated once by default.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Uses x/net/proxy to fix issue when using SOCKS5
Nothing published for this version
Fix a bug: IsDisposable() matches the complete email domain
IsDisposable() matches the complete email domainNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Support setting SOCKS5 proxy to perform CheckSMTP()
CheckSMTP()Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Support adding custom disposable email domains #31
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
reduce Result struct size from 96 to 80
ParseAddress() return Syntax instead of reference, for reducing GC pressure and improve memory locality.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add a New feature: domain suggestion (typo check)
Add build metadata tools to generate metadata_*.go files
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →