NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #182 most downloaded on NuGet
MimeKit is an Open Source library for creating and parsing MIME, S/MIME and PGP messages on desktop and mobile platforms. It also supports parsing of Unix mbox files. Unlike any other .NET MIME parser, MimeKit's parser does not need to parse string input nor does it use a TextReader. Instead, it parses raw byte streams, thus allowing it to better support undeclared 8bit text in headers as well as message bodies. It also means that MimeKit's parser is significantly faster than other .NET MIME parsers. MimeKit's parser also uses a real tokenizer when parsing the headers rather than regex or string.Split() like most other .NET MIME parsers. This means that MimeKit is much more RFC-compliant than any other .NET MIME parser out there, including the commercial implementations. In addition to having a far superior parser implementation, MimeKit's object tree is not a derivative of System.Net.Mail objects and thus does not suffer from System.Net.Mail's limitations. API documentation can be found on the web at http://www.mimekit.net/docs For those that need SMTP, POP3 or IMAP support, check out https://github.com/jstedfast/MailKit
Last release 19 days ago
19 Sep 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 58 of the last 60 stable releases
115 versions withdrawn
withdrawn after publishing
127 years old
198 releases · first in 1900
Prevent integer overflows in TnefPropertyReader due to corrupt content.
Removed base, embed, input, link and source tags as "unsafe" tags. These are all void tags in HTML, meaning they do not have inner content. (issue #12
Note: As of BouncyCastle 2.7.0, decrypting S/MIME content encrypted with Blowfish, CAST5, RC2/40, RC2/64,
or RC2/128 will fail with a CmsException: no fixed size for content-encryption key; constant-time RSA unwrap unavailable.
Use the following code snippet to restore pre-2.7.0 behavior:
Org.BouncyCastle.Utilities.Properties.SetThreadBoolean (Org.BouncyCastle.Utilities.Properties.CmsAllowLenientRsaPkcs1, true);
One column per quarter.
…to protect against Cross-Size Scripting (XSS) vulnerabilities.
Simplified logic for illegal ctrl characters within quoted-string local-part tokens in addr-specs.
[SECURITY] Use stricter parsing logic for quoted-strings in addr-specs to prevent SMTP command injection attacks when those quoted-strings include CRL
Fixed inexact read in TnefPropertyReader.GetEmbeddedMessageReader().
Updated BouncyCastle.Cryptography dependency to v2.6.1.
Fixed a memory leak in MimeAnonymizer and MimeUtils.Unquote() which gets used by the address parser. (issue #1161)
Removed CTRL characters from the list of allowed domain characters.
Fixed logic for validating HTML Tag and Attribute names. (issue #1136)
Fixed logic for converting BouncyCastle DSA keys to System.Security equivalents.
Started adding some DynamicallyAccessedMembers attributes for AOT compatibility.
Added TypeConverters for InternetAddress and InternetAddressList.
Bumped System.Formats.Asn1 to v8.0.1 to fix a denial of service security issue.
Bumped BouncyCastle.Cryptography from 2.3.1 to 2.4.0
Fixed hex format specifier for PGP keyserver lookup. (issue #1028)
Fixed MailboxAddress to not use punycode to encode or decode the local-part of an addr-spec. (issue #1012)
Improved folding logic for Disposition-Notification-Options header values. (issue #979)
Added work-around for broken Message-ID header values of the form <id@@domain>. (issue #962)
Follow the spec more closely for allowable header field characters. (issue #936)
List<string>s in DomainList.ctor(), lazily allocate the
list only when a domain is added. Another minor reduction in GC pressure.Readded the System.Net.Mail-to-MimeKit conversion APIs for the netstandard2.x frameworks. (issue #913)
Ported to BouncyCastle v2.1.1. (issue #865)
Improved the UrlScanner to allow numeric key/value pairs (seems to match behavior in other url detection algorithms).
Added the .msg <-> application/vnd.ms-outlook mime-type mapping. (issue #880)
startIndex and count arguments.https://example.com?query
(issue #897)Fixed potential NRE's in the GnuPG config parser
Fixed a variety of memory leaks revealed by (issue #852)
Fixed MessageDeliveryStatus.ParseStatusGroups() to catch FormatException instead of ParseException. (issue #837)
Improved logic for reformatting headers when MimeMessage.WriteTo() is called with FormatOptions.International set to true.
Introduced a new IPunycode interface and Punycode class allowing developers to override the default implementation that uses .NET's IdnMapping class.
Added Import() methods for X509Certificate2 for all S/MIME contexts. (issue #784)
Special thanks to Fedir Klymenko for his improvements to MemoryBlockStream and SecureMimeContext.Compress!
Rewrote QuotedPrintableEncoder to more strictly fold at the specified line length. (issue #781)
Special Thanks to Jason Nelson for taking the lead on many of the listed (and unlisted) performance improvements and helping me make MimeKit even more awesome!
When initializing character encodings for netstandard and net50/net60, wrap the Reflection logic to invoke System.Text.Encoding.RegisterProvider() in
message/delivery-status parts where all status groups after
the first are base64 encoded. This seems to be a bug in Office365 where it treats the first
status group as MIME entity and the following status groups as the content.
(issue #250)Always use a lowercase domain name in the Message-Id to work around bugs in eM Client. (issue #734)
Removed APIs marked as \[Obsolete\] in 2.x.
Nothing published for this version
Improved MimeParser to be a little more efficient based on work being done for the upcoming v3.0 release.
Use DebugType=full for .NET Framework v4.x. (MailKit issue #1239)
Allow ..'s and trailing .'s in the local-part of an addr-spec by introducing a new RfcComplianceMode.Looser enum value that can be set on the ParserOp
Added a way to force MimeKit to always quote parameter values. (issue #674)
Fixed S/MIME support using WindowsSecureMimeContext with MimeKit's CmsSigner classes which was causing a PlatformNotSupportedException. (issue #664)
Fixed DSA key conversion logic to work more reliably.
Treat message/disposition-notification and message/delivery-status the same as text/* when preparing for signing. (issue #626)
Added SQL Server support. (issue #619)
Include WindowsSecureMimeContext in the .NET Standard 2.x build. (issue #600)
Refactored OpenPgpContext to separate out key storage implementation. (issue #576)
Nothing published for this version
Improved logic for verifying signatures for MimeParts containing mixed line endings. (issue #569)
Fixed InternetAddressList.Insert() to allow inserting at the end of the list. (issue #559)
Fixed the MimeEntity.ContentId setter to use ParseUtils.TryParseMsgId() instead of MailboxAddress.TryParse() so that it is more lenient in what it acc
Updated net46, net47, and net48 builds to reference Portable.BouncyCastle instead of the standard BouncyCastle package, just like the netstandard buil
;.Fixed parsing of email addresses containing unicode or other types of 8-bit text. (issue #536)
Fixed message reserialization after prepending headers. (issue #524)
"[" and "]"
characters in the display-name.
(issue #532)Don't use PublicSign on non-Windows NT machines when building. (issue #516)
Added the text/csv mime-type to the MimeTypes mapping table for files with a .csv extension.
text/csv mime-type to the MimeTypes mapping table for files with a .csv extension.message/global-delivery-status, message/global-disposition-notification,
and message/global-headers to MimeParser.
(issue #514)Fixed reserialization of message/rfc822 parts to not add an extra new-line sequence to the end of the message. (issue #510)
Updated CmsSigner's default DigestAlgorithm to Sha256 instead of Sha1 to match System.Security.Cryptography.Pkcs.CmsSigner's default.
Fixed MultipartRelated to fall back to the multipart/related type parameter when locating the Root. (issue #489)
Added AuthenticationResults class for parsing and constructing Authentication-Results and ARC-Authentication-Results headers.
Updated the BouncyCastle assemblies to version 1.8.5 for iOS and Android.
msg-id token.Added a setter for FormatOptions.MaxLineLength, allowing developers to override this value.
Your coding agent can read these notes before it upgrades. Set up the MCP server →