What’s new?

Deprecation of Verify and Verify+CN

Verify and Verify+CN are deprecated due to the removal of the TLS Web Client Authentication Extended Key Usage (EKU) from publicly trusted certificates. From 18 May 2026, existing configurations will be automatically downgraded to Encrypt or Encrypt+CN.

Short non-delivery timeout for undeliverable messages

Mail held in queues pending delivery for certain deferral reasons such as The recipient's inbox is out of storage will now be deleted, and a non-delivery report sent to the originator, after 1 day rather than the usual 7 days.

DKIM canonicalization updated to relaxed/relaxed

Outbound DKIM signing now uses relaxed/relaxed canonicalization instead of relaxed/simple. This resolves DKIM verification failures experienced when sending emails to certain recipients (e.g., Microsoft Teams).