Back to Changelog
Panel Backend
v1.0.556
Per-account outgoing mail limits, direct outbound port 25 policy and Postfix settings fixes
New Features
4- Outgoing mail limits per plan: per account per hour, per account per day and per mailbox per hour, counted in recipients outside the server. Over the hourly limit up to 25% more mail is held and sent in the next hour; beyond that it is refused (SMTP 451, sendmail 550). The account owner, its reseller/admin and root are notified, and the webhook event email.send_limit_reached fires.
- Mail sent with the sendmail command (PHP mail(), cron) is charged to the site account that sent it, read from the Postfix queue file so it cannot be forged with a header. Mail from root is not counted.
- Direct outbound SMTP (port 25) policy for site accounts: block (only root, the mail server and exempt accounts), log, or off. Ports 587 and 465 are never restricted. Attempts are listed with the account for the last 7 days.
- Users can pin, hide and reorder their own sidebar menu; the layout is saved per user.
Improvement
1- Existing panels keep sending exactly as before: every plan starts unlimited and port 25 starts in log mode. New installations get example hourly limits on the default plans and port 25 blocked for site accounts.
Bug Fixes
5- Turning DKIM signing off in Email Settings now actually stops signing; the stored setting is reconciled once with what Postfix really does.
- Port 25 no longer requires TLS (RFC 3207: a public mail server must accept mail without it). Ports 587 and 465 always require encryption.
- Saving Email Settings waits for the Postfix configuration to be applied and reports the reason when it fails.
- Password reset emails are sent from the configured system sender address.
- DKIM, SPF and DMARC Generate no longer add a second TXT record when the zone stores the name in relative form. Exact duplicates left by earlier versions are removed at startup; different values are only logged.
Security Fix
1- Trusted networks reject 0.0.0.0/0 and overly broad public ranges; a whole-internet entry left in mynetworks (open relay) is removed at startup.