NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2141 most downloaded on npm
Easy as cake e-mail sending from your Node.js applications
Last release today
03 Oct 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
158 versions withdrawn
withdrawn after publishing
15 years old
323 releases · first in 2011
addressparser: keep a quoted display name that holds no "@" out of the address
One column per quarter.
read the advertised SASL methods without backtracking regexes
settle every send on a connection error, back off pool requeues, turn a bare CR into CRLF, bound fetch, honour requireTLS
fetch: report a form body that can not be encoded through the returned stream
derive the attachment filename from the basename of a Windows path
addressparser: bound the '@' probe to the run being scanned
mime-node: clean the boundary where it is written, not only where it is built
mime-funcs: do not double encode Buffer input when chunking base64 mime words
addressparser: scan free text for an address in linear time
addressparser: parse comment-joined addresses in linear time
fetch: scope a cookie without a Path to the RFC 6265 default path
fetch: honor the cookie Domain attribute without accepting public suffixes ( 1608391 ), closes #1856
mime-node: flatten nested recipient arrays without recursion
types: accept an explicit undefined for optional properties ( 209719d ), closes #1853
Node.js 20 or newer is required. The Node.js 6 syntax compatibility check and the .npmignore file are gone.
mailer: apply the message access policy in resolveContent
mailer: cap recipients per message with maxRecipients
addressparser: recover the addr-spec from an angle-addr holding whitespace
ci: retrigger the workflows dropped during the Actions outage
mime-funcs: do not let an unpaired surrogate consume the next character
smtp-connection: harden STARTTLS upgrade and secure socket handling
addressparser: keep operator chars inside an address-literal as text
enforce disableFileAccess/disableUrlAccess for raw message option
replace deprecated url.parse with a WHATWG URL wrapper
tls option).apply the transport-level newline option in stream and sendmail transports
fall back to lower-severity handler when custom logger lacks a level method
two pending security advisories (jsonTransport access bypass, List-* CRLF injection)
enforce strict TLS for OAuth2 and Ethereal credential requests
keep domain as UTF-8 when local part is non-ASCII
restore base64 wrap() trim behavior to prevent trailing CRLF
decode SMTP server responses as UTF-8 at line boundary
sanitize envelope size to prevent SMTP command injection
clean up addressparser and fix group name fallback producing undefined
merge fragmented display names with unquoted commas in addressparser
absorb TLS errors during socket teardown
Error code 'NoAuth' renamed to 'ENOAUTH'
downgrade transient connection error logs to warn level
use 8bit encoding for message/rfc822 attachments
prevent stack overflow DoS in addressparser with deeply nested groups
Increase data URI size limit from 100KB to 50MB and preserve content type
release: Trying to fix release proecess by upgrading Node version in runner
addressparser: Fixed addressparser handling of quoted nested email addresses
ReDoS vulnerability in parseDataURI and \_processDataUrl
updated well known delivery service list
pools: Emit 'clear' once transporter is idle and all connections are closed
attachments: Set the default transfer encoding for message/rfc822 attachments as '7bit'
ses: Fixed structured from header
ses: Use formatted FromEmailAddress for SES emails
SESv2 SDK support, removed older SES SDK v2 and v3 , removed SES rate limiting and idling features
### Bug Fixes - close correct socket
services: add Seznam email service configuration
addressparser: Correctly detect if user local part is attached to domain part
api: Added support for Ethereal authentication
tls: Ensure servername for SMTP
message-generation: Escape single quote in address names
headers: Ensure that Content-type is the bottom header
data-uri: Do not use regular expressions for parsing data URI schemes
security: Fix issues described in GHSA-9h6g-pr28-7cqp. Do not use eternal matching pattern if only a few occurences are expected
punycode: do not use native punycode module
Your coding agent can read these notes before it upgrades. Set up the MCP server →