NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1284 by repository stars
Last release 16 days ago
22 Sep 2026
Release timing varies
gaps range from 8 days to 5 months
Rarely documented
notes for 9 of 47 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
235 releases · first in 2022
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release is only a small release, but fixes a regression on the 386 platform. We hope you enjoy!
Welcome to go-mail v0.8.1! 🎉
This release is only a small release, but fixes a regression on the 386 platform. We hope you enjoy!
The NTLM support introduced in v0.8.0 contained a bug affecting 386 platforms: a 32-bit integer could overflow because it wasn't cast to int64. This caused problems when cross-compiling to the 386 architecture. The bug is fixed in #589. In addition, the CI pipeline has been extended to run cross-compile tests for every platform supported by GitHub runners. Thanks to @firefart for reporting the issue.
PR #585 introduces an opportunistic authentication mechanism that lets users provide a list of preferred auth types. During SMTP authentication, the client checks the mechanisms the server supports and selects the first match from the preferred list. If the server supports none of the preferred mechanisms, the client falls back to Autodiscover mode and selects the strongest mechanism the server offers.
We already expose the HeaderListUnsubscribe and HeaderListUnsubscribePost header constants, but until now there was no dedicated function to construct these headers. Users had to assemble the angle-bracket URI list and the exact List-Unsubscribe=One-Click token by hand via SetGenHeader—something that's easy to get subtly wrong (missing <>, an incorrect POST token, or GET-triggerable URLs). Since February 2024, Gmail and Yahoo require a working RFC 8058 one-click unsubscribe for senders exceeding 5k messages per day, making this a common compliance requirement rather than a niche feature. PR #587 adds three convenience helpers to set these headers correctly:
SetListUnsubscribe(uris ...string): sets an RFC 2369 List-Unsubscribe header only (mailto/https links).SetListUnsubscribePost(): sets List-Unsubscribe-Post: List-Unsubscribe=One-Click.SetListUnsubscribeOneClick(httpsURL string, additionalURIs ...string): the common case: sets both headers correctly, validating that at least one HTTPS URL is present as required by RFC 8058.Full Changelog: v0.8.0...v0.8.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release brings two big new features and a couple of improvements and fixes to go-mail. We hope you enjoy this release!
Welcome to go-mail v0.8.0! 🎉
This release brings two big new features and a couple of improvements and fixes to go-mail. We hope you enjoy this release!
Important
This release adds a new dependency to go.mod. We now rely on the crypto package of the Go extended library. We already relied on golang.org/x/text before, but it's worth noting that if you have strict dependency requirements, that golang.org/x/crypto was added in this release.
With PR #576 native NTLMv2 SMTP auth support has been added to go-mail. This feature has been requested several times and so far we've always resorted to a custom SMTP authentication provider using some 3rd party libraries. With go-mail v0.8.0 you can now natively authenticate with NTLM servers like any of the other supported authentication methods. Big thanks to @mkalus for providing some ground work in #549 and for helping to test the code. The development was mainly based on the excellent documentation of the cURL project.
Note
Please note that I do not have access to an Exchange server to test the code in a real-life scenario. While I believe that the code is functional (I implemented extensive unit tests), please consider it as an experimental feature for the time being. Please report any issue you might run into.
PR #582 adds native DKIM signing support to go-mail. So far we only supported DKIM via go-mail middleware, which proved to very limited and had the caveat that it needs to be the last middleware to be executed, otherwise the signature would be invalid. With go-mail v0.8.0 you can now natively DKIM sign your mails. DKIM support has been added in the Msg as well as in the Client types. In the Msg type you can sign individual mail messages, while the DKIM support in the Client instructs the mail sender to sign every outgoing message that runs through it.
With PR #556 go-mail now has support for named templates. So far we've been executing a template as a whole, but with this new functions one is allowed to execute only a portion of the template. Thanks to @Maldiran for contributing this PR!
PR #569 adds a new Client option: WithoutRset(). This instructs the client to skip the RSET we usually send after a successful mail delivery. This option can be useful for MTAs that do not support the RSET command and would fail because of that, even though the mail was successfully delivered.
Full Changelog: v0.7.3...v0.8.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release brings some cool improvements, new features, and fixes to go-mail. We hope you enjoy it!
Welcome to go-mail v0.7.3! 🎉
This release brings some cool improvements, new features, and fixes to go-mail. We hope you enjoy it!
PR #521 fixes a missing deadline in the Client that could cause a deadlock for connections to a TLS port without TLS enabled. Thanks to @james-d-elliott for finding and fixing this issue!
PR #528 fixes an error for cases in which both the HELO and EHLO fail during a client connect. In this case the first error would be overwritten by the 2nd action, potentially deleting valuable information. In go-mail v0.7.3 both errors are now combined. Thanks to @Yanhu007 for their contribution!
In PR #512 @srpvpn refactored the Base64LineBreaker type to be more performant and easier to read by removing the recursion. Thanks for your contribution!
In PR #518 @sblinch introduced a new compile time flag gomailnotpl which will make the text/template and html/template optional. Background is, that using reflect.Value.Method or reflect.Value.MethodByName prevents Go from performing full dead-code elimination because any exported method of any struct in the codebase could potentially be referenced at runtime. Unfortunately text/template and html/template do exactly this to allow method invocation from within templates. So in case your code does not need template support, you can use the new compile flag to remove the support for both packages completely and same some bytes in the resulting binary. Thanks for your contribution!
PR #543 fixes a potential nil pointer panic in the partWriter in case the underlying io.Writer returns an error during a multipart message write. Thanks to @UgurTheG for reporting and fixing the issue!
PR #530 adds support to access the HELO/EHLO responses via the smtp.Client. This feature is useful when using an SMTP servers pool behind a load balancer, to know which instance took the job. Thanks to @maxatome for submitting this feature!
PR #517 adds support for multiple Reply-To addresses within a Msg, as permitted in RFC5322. Thanks to @christian-heusel for pointing this out and for comitting the PR!
PR #548 adds support for skipping the SMTPUTF8 extension to MAIL FROM commands. By default, when a server announces SMTPUTF8 support in the EHLO, go-mail will add SMTPUTF8 to the MAIL FROM command. As pointed out in #545, some SMTP servers (e. g. specific MS Exchange versions) announce the SMTPUTF8 extension in the EHLO response but when adding the SMTPUTF8 to the MAIL FROM, they will fail with an error. The PR introduces a new WithoutSMTPUTF8() option for the Client which will make sure to skip the SMTPUTF8 extension in the MAIL FROM, even if the server announced it previously. Thanks @mkalus for reporting this issue and for their detailed analysis in #545.
SendWithSMTPClient to improve error handling and added test cases by @wneessen in #502golang.org/x/text module versions by @wneessen in #526.golangci.toml for linter exclusions on specific use cases by @wneessen in #523Full Changelog: v0.7.2...v0.7.3
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Unfortunately with the v0.7.1 vulnerability fix, a regression was introduced when formatted mail address with full name ( "Toni Tester" <toni.tester@e…
Welcome to go-mail v0.7.2!
Unfortunately with the v0.7.1 vulnerability fix, a regression was introduced when formatted mail address with full name ("Toni Tester" <toni.tester@example.com> were used, resulting in only the mail address (<toni.tester@example.com>) being handed over to the SMTP client. This bug was spotted and reported by @NCRonB in #497 - thank you very much for the report.
Sorry for any incovenience this might have caused!
Full Changelog: v0.7.1...v0.7.2
Important This release fixes a vulnerability. All users are encouraged to update to this release at their earliest convenience.
Important
This release fixes a vulnerability. All users are encouraged to update to this release at their earliest convenience.
Welcome to go-mail v0.7.1!
This is a security release, which addresses a bug that causes insufficient address encoding when passing mail addresses to the SMTP client, which could lead to possible wrong address routing or even to ESMTP parameter smuggling.
The details of the bug are outlined in #495 and in the go-mail security advisory: GHSA-wpwj-69cm-q9c5
Github assigned the following CVE for this vulnerability: CVE-2025-59937
The vulnerability has been reported by xclow3n. Thank you very much for the detailed report and the thorough testing!
Full Changelog: v0.7.0...v0.7.1
This creates the risk of leaving users exposed to unpatched security vulnerabilities and critical issues.
Welcome to go-mail v0.7.0! 🎉
This release brings important improvements, new features, and fixes to make working with go-mail more reliable and powerful.
Warning
BREAKING CHANGES! This release introduces some changes that might potentially break your code base, so please review carefully before upgrading.
With this release, go-mail will no longer commit to supporting the last four Go versions. Instead, we will follow the official Go release policy and only support versions that are actively maintained by the Go team.
Security and Dependencies
Even though go-mail currently has very few dependencies, keeping support for outdated Go versions would prevent us from safely updating them in the future. This creates the risk of leaving users exposed to unpatched security vulnerabilities and critical issues.
Maintenance Costs
Supporting unsupported Go versions requires extra workarounds, conditionals, and testing overhead. Every additional version increases maintenance complexity and takes valuable time away from adding new features, improving the code base, and fixing bugs.
Alignment with the Go Ecosystem
The Go team provides two releases per year, and each version receives about one year of official support. By aligning with this policy, go-mail ensures that users always benefit from current language features and security patches.
If you are already on a Go version that is actively maintained (at this point: 1.24 or 1.25), nothing changes. If you are on an older, unsupported version, you will not be able to run go-mail v0.7.0 or higher and we strongly encourage upgrading. This will not only allow you to continue using go-mail but will also ensure you benefit from the security and performance improvements provided by the Go team.
|Breaking change| With PR #441 we changed Reply-To header to an AddrHeader type. Since Reply-To is actually an address header which formats the mail address accordingly, and not a generic header, this could lead to potential double encoding if the address and name contain special characters. This change is potentially a breaking change, since we are changing a public type, but as long as the user makes use of msg.ReplyTo() or msg.ReplyToFormat() this should not cause any problems.
|Breaking change| With PRs #445, #448 and #443 we address an issue with the Base64LineBreaker.Write implementation which reports an incorrect count of bytes written ("short writes). While those short writes aren't noticed in practice, since we use base64.Encoder.Encode.Write under the hood, which ignores short writes, the issue was still fixed to make it future-proof against potential changes in the base64 package. This issue was reported and fixed by @dolmen. Thank you very much for your contribution! It was also pointed out, that our Base64LineBreaker was a public type without exposing any public methods, making it unusuable for any 3rd party library. Therefore the Base64LineBreaker type was made private (which in theory is a breaking change, but in practice should not affect any user, given that no public methods were exposed)
The EML parsing was made more robust by introducing several fixes/improvements:
panic: assignment to entry in nil map. This issue was reported by numerous users (see: #446, #462, #468, #482 and #490). Thanks to everybody who reported this issue!PR #472 adds support for directly providing *mail.Address instances by providing a SetAddrHeaderFromMailAddress method. It also provides methods for directly providing *mail.Address instances for all the various address types (From, To, CC, BCC, etc.). Additionally it adds a IsAddrHeader method, which checks if the provided string is an address header.
PR #492 introduces ResponseErrorHandler and ErrorHandlerRegistry - an interface that defines a method for handling SMTP responses that do not comply with expected formats or behaviors and would cause errors during the SMTP communication. It is useful for implementing retry logic, logging, provider-specific error handling. It injects itself into the smtp.Client and is called whenever a server response does fail. This feature addresses #464 and #463. In our Wiki we will collect a currated list of known providers with issues and corresponding code examples on how to implement the error handler.
Full Changelog: v0.6.2...v0.7.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This would happen if a nil message would be provided to the method. This bug was reported using Github's private vulnerability reporting feature by @y…
Welcome to go-mail v0.6.2! This release fixes some bugs and makes go-mail ready for Go 1.24.
PR #429 fixes a regression in the handling of custom smtp.Auth methods that was introduced with the v0.6.0 release. Basically, if a custom SMTP auth method was provided, it was simply ignored. Thanks to @james-d-elliott of the Authelia project for reporting this.
With commit 4641da4 we fixed a possible nil pointer dereference in the SendWithSMTPClient method. This would happen if a nil message would be provided to the method. This bug was reported using Github's private vulnerability reporting feature by @younes199511. Thanks for the report!
PR #421 fixed an issue in the header count logic that is used for S/MIME signing. If a header was broken into mutliple lines due to its lenght, the count logic was giving false results, resulting into false content for the S/MIME signature. Thanks to @theexiile1305 for reporting the issue and helping to debug the issue!
The PRs #431 and #433 make go-mail and its CI ready for Go 1.24.
Full Changelog: v0.6.1...v0.6.2
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Welcome to go-mail v0.6.1! This release is a bug-fix release that addresses a regression introduced in v0.6.0.
Welcome to go-mail v0.6.1! This release is a bug-fix release that addresses a regression introduced in v0.6.0.
Important
If you are working with multipart messages and are currently using v0.6.0, it is advised to upgrade to v0.6.1 to avoid rendering issues.
The v0.6.0 release introduced a regression in the multipart message generation (See #412). The boundary lines were not correctly seperated with a new line. This bug was introduced while working on the S/MIME handling. The issue has been fixed in #413. I am sorry for any inconveniences this might have caused. Thanks to @Thomas2500 for reporting the issue!
While working on #412, I noticed a general issue with the boundary handling when fixed boundaries are set for the message. This bug was present already since the introduction of Msg.WithBoundary/Msg.SetBoundary, but was only brought to light with the new S/MIME feature introduced in v0.6.0. Since the S/MIME signing needs to set a fixed boundary, it was using the Msg.SetBoundary feature. If more than one multipart parts were used with a fixed boundary, this would render the mail broken (since it was using the same boundary for multiple parts). This has been fixed in #414 and #416. The GoDoc for Msg.WithBoundary/Msg.SetBoundary has also been updated with a warning that using the feature with more than one parts will break the message rendering.
Since XOAUTH2 works with Bearer tokens instead of passwords but the Auto-Discovery SMTP auth feature makes use of a username/password pair having XOAUTH2 in the prefered mechanisms list could cause authentication failures. Therefore the XOAUTH2 mechanism has been removed from the feature completely. Thanks to @james-d-elliott for pointing this out!
Full Changelog: v0.6.0...v0.6.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →