{"id":13565320,"url":"https://github.com/davidmoten/subethasmtp","last_synced_at":"2026-01-14T03:32:48.375Z","repository":{"id":20516497,"uuid":"87984488","full_name":"davidmoten/subethasmtp","owner":"davidmoten","description":"SubEtha SMTP is a Java library for receiving SMTP mail","archived":false,"fork":true,"pushed_at":"2025-09-22T05:10:20.000Z","size":6878,"stargazers_count":163,"open_issues_count":10,"forks_count":44,"subscribers_count":14,"default_branch":"master","last_synced_at":"2025-09-22T07:09:30.454Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"bigjosh/subethasmtp","license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/davidmoten.png","metadata":{"files":{"readme":"README.md","changelog":"ChangeLog.md","contributing":null,"funding":null,"license":"LICENSE.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2017-04-11T22:22:03.000Z","updated_at":"2025-09-22T05:10:17.000Z","dependencies_parsed_at":"2023-02-10T18:10:20.944Z","dependency_job_id":"5826b297-d6e7-422d-af06-96677e56d36c","html_url":"https://github.com/davidmoten/subethasmtp","commit_stats":null,"previous_names":[],"tags_count":58,"template":false,"template_full_name":null,"purl":"pkg:github/davidmoten/subethasmtp","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/davidmoten%2Fsubethasmtp","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/davidmoten%2Fsubethasmtp/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/davidmoten%2Fsubethasmtp/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/davidmoten%2Fsubethasmtp/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/davidmoten","download_url":"https://codeload.github.com/davidmoten/subethasmtp/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/davidmoten%2Fsubethasmtp/sbom","scorecard":{"id":327327,"data":{"date":"2025-08-11","repo":{"name":"github.com/davidmoten/subethasmtp","commit":"399613d0f0b0800d8185e437cbb5af8451efce6d"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.7,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":1,"reason":"Found 3/20 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":8,"reason":"7 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 8","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/davidmoten/subethasmtp/ci.yml/master?enable=pin","Info:   0 out of   1 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE.txt:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 16 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-18T02:46:55.132Z","repository_id":20516497,"created_at":"2025-08-18T02:46:55.132Z","updated_at":"2025-08-18T02:46:55.132Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28408668,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T00:40:43.272Z","status":"ssl_error","status_checked_at":"2026-01-14T00:40:42.636Z","response_time":56,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T13:01:44.530Z","updated_at":"2026-01-14T03:32:48.358Z","avatar_url":"https://github.com/davidmoten.png","language":"Java","funding_links":[],"categories":["Java"],"sub_categories":[],"readme":"# subethasmtp\n\u003ca href=\"https://github.com/davidmoten/subethasmtp/actions/workflows/ci.yml\"\u003e\u003cimg src=\"https://github.com/davidmoten/subethasmtp/actions/workflows/ci.yml/badge.svg\"/\u003e\u003c/a\u003e\u003cbr/\u003e\n[![Maven Central](https://maven-badges.herokuapp.com/maven-central/com.github.davidmoten/subethasmtp/badge.svg?style=flat)](https://maven-badges.herokuapp.com/maven-central/com.github.davidmoten/subethasmtp)\u003cbr/\u003e\n[![codecov](https://codecov.io/gh/davidmoten/subethasmtp/branch/master/graph/badge.svg)](https://codecov.io/gh/davidmoten/subethasmtp)\u003cbr/\u003e\n\nSubEtha SMTP is a Java library which allows your application to receive SMTP mail with a simple, easy-to-understand API.\n\nThis component can be used in almost any kind of email  processing application.  Hypothetical (and not-so hypothetical) uses include:\n\n  * A mailing list manager (see SubEthaMail)\n  * A mail server that delivers mail to user inboxes\n  * A mail archiver like [The Mail Archive](http://www.mail-archive.com/)\n  * An email test harness (see [Wiser](Wiser.md))\n  * An email2fax system\n  * SMTPseudo [A filtering forwarding server](http://code.google.com/p/smtpseudo/)\n  * [Baton](http://code.google.com/p/baton/) SMTP proxy for one or more backends (rules based on sender/envelope)\n  * [Mireka](http://code.google.com/p/mireka/) - Mail server and SMTP proxy with detailed logging, statistics and built-in, fail-fast filters\n  \n## Features\n* Supports minimum SMTP specification described in [rfc2821](https://tools.ietf.org/html/rfc2821#section-4.5.1) (4.5.1)\n* Supports STARTTLS \n* Supports SMTP AUTH\n* Supports SMTP over SSL/TLS (via specification of server socket factories)\n* Uses builders for concise code and a discoverable API\n\n\n## Example\n\nThe code below starts an SMTP server and logs messages to the console:\n```java\nSMTPServer server = SMTPServer \n  .port(25000) \n  .build();\n  \n //start server asynchronously\n server.start();\n ```\n \n Do your own thing with a message (from, to and a byte array of data):\n ```java\nSMTPServer server = SMTPServer //\n  .port(PORT) //\n  .messageHandler(\n    (ctx, from, to, data) -\u003e \n       System.out.println(\n           \"message from \" + from \n           + \" to \" + to\n           + \":\\n\" + new String(data, StandardCharsets.UTF_8)))\n  .build();\n  \nserver.start();\n```\n\nThe builder has a lot of options. This fragment sets a bunch of them:\n\n```java\nSMTPServer server = SMTPServer \n  .port(port) \n  .connectionTimeout(1, TimeUnit.MINUTES) \n  .authenticationHandlerFactory(ahf) \n  .backlog(100) \n  .bindAddress(address) \n  .requireTLS() \n  .hideTLS() \n  .hostName(\"us\") \n  .maxMessageSize(10000)\n  .maxConnections(20)\n  .maxRecipients(20) \n  .messageHandlerFactory(mhf) \n  .executorService(executor)\n  .startTlsSocketFactory(sslContext)\n  .fromAddressValidator(emailValidator)\n  .build();\n```\n\n## Getting started\nUse this maven dependency:\n\n```xml\n\u003cdependency\u003e\n    \u003cgroupId\u003ecom.github.davidmoten\u003c/groupId\u003e\n    \u003cartifactId\u003esubethasmtp\u003c/artifactId\u003e\n    \u003cversion\u003eVERSION_HERE\u003c/version\u003e\n\u003c/dependency\u003e\n```\n\n## A Little History ##\nSubEthaSMTP was split out of the SubEthaMail mailing list manager because it is a useful standalone component.  When we wrote SubEtha, the last thing we wanted to do was write our own SMTP server.  In our search for a modular Java SMTP component, we examined:\n\n  * [Apache JAMES](http://james.apache.org/)\n  * [JBoss Mail Server](http://labs.jboss.com/portal/jbossmail/index.html), now also defunct [Meldware Mail](http://www.buni.org/mediawiki/index.php/Meldware_Mail)\n  * [Dumbster](http://quintanasoft.com/dumbster/)\n  * [Jsmtpd](http://www.jsmtpd.org/site/)\n  * [JES](http://www.ericdaugherty.com/java/mailserver/)\n  * [Green Mail](http://www.icegreen.com/greenmail/)\n\nSince you're reading this page you probably already know what we found:  Seven different SMTP implementations without the slightest thought given to reusability. Even Jstmpd, which purports to be a \"A Modular Java SMTP Daemon\", isn't.  Even though JBoss Mail/Meldware Mail is in active development, the team was unintersted in componentization of the SMTP processing portion of their server.  GreenMail, which is based on the JAMES code base is best summarized with this [blog posting](http://eokyere.blogspot.com/2006/10/get-wiser-with-subethasmtp.html).\n\nDuring the development of SubEtha's testing harness, we tried out the [Dumbster](http://quintanasoft.com/dumbster/) software  and found that not only was the API difficult to use, it did it not work properly, the developer has not done any development on it in about a year and it does not work reliably on Mac OS X. With two simple classes we re-implemented it as an included project called [Wiser](Wiser.md).\n\nWe hate reinventing wheels.  This should be the LAST FREAKING JAVA SMTP IMPLEMENTATION (Dave Moten: not including forks!).\n\n## A New Fork ##\nEngine821.com too did a survey of existing Java SMTP implementations and were unsatisfied... until they found SubEthaSMTP! The code is clean and very well thought out. The changes they made were minor, including...\n\n* Eliminate the embedded `/lib` directory. Maven correctly handles pulling in all the dependencies and best practices discourage keeping binary artifacts inside version control.\n* Update to the latest versions of some of the libraries used. \n* Remove some of the IDE metadata files. Your IDE can rercreate whichever ones you need based on your preferences and the Maven POM.\n* Make the message handing exceptions be `checked`. This is possibly controversial, but we thought about it a lot and prefer to have these exceptions show up in the `throws` clause rather than have them potentially pop-up unexpectedly at run-time. \n\n### Fork of a Fork!\nDave Moten came across the Engine821 fork and \n* fixed tests\n* migrated mocking to use Mockito (with apologies but was the most time-efficient way for me to restore the broken tests!)\n* set up pom.xml for release under the `com.github.davidmoten:subethasmtp` artifact \n* released to Maven Central\n* submitted the changes back to the Engine821.com fork (apart from the groupId change and release changes). Note that review/merge of changes does not seem to be forthcoming. \n* added multi-JDK continuous integration using Travis (now using Github Actions)\n* added code coverage using coverage.io\n* added round trip unit test of STARTTLS\n* removed MigBase64 because is complex code without unit tests (even in original source) and Java 8 Base64 is faster\n* cleaned up code (made fields private and final where appropriate, remove public keyword from interface methods)\n* minor coverage improvements\n* required Java 8 (just because of `Base64` class at the moment, Java 7 required now because of use in unit test of `X509TrustManager`)\n* converted `SMTPServer` to be largely immutable and is created with a builder pattern\n* adjusted `Wiser` API to cope with an immutable `SMTPServer`\n* disallowed inheritance of `SMTPServer` (now final)\n* `Wiser` now created with builder pattern (disallowed inheritance and added `accepter` builder method)\n* used composition instead of inheritance in `SmartClient`\n* used static factory method for `SmartClient` so that references don't escape the constructor (`connect` was called from the constructor)\n* used explicit character set with `InputStreamReader` (US_ASCII) in `SMTPClient` and `SmartClient`\n* used `java.util.Optional` and `Preconditions` in `SmartClient`, `SMTPClient` and `SMTPServer`\n* added `@Override` annotations\n* added `EmailUtils` tests\n* moved classes that are not part of the public API to internal packages\n* added pure SSL support to `SMTPServer` builder and a roundtrip unit test\n* added `BDAT` support\n* added support for receiving inbound SMTP connections via a proxy that uses the `PROXY protocol`, built on the HAProxy specification found at https://www.haproxy.org/download/2.3/doc/proxy-protocol.txt\n* and more, see Releases\n\n\n## Project Authors ##\nIan McFarland contributed the first codebase to SubEtha Mail. Then, Jon Stevens and Jeff Schnitzer re-wrote most of Ian's code into what we have today. Edouard De Oliveira and Scott Hernandez have also made significant contributions. Dave Moten made changes as mentioned above.\n\n## Support ##\nIf you have any bug reports, questions or comments about this SubEtha SMTP fork, it's best that you use the GitHub issue tracker to get in touch. Please do not email the authors directly.\n\n## Spec Compliance ##\nFor now, we have just focused on implementing just the minimal required aspects of http://rfc.net/rfc2821.html#s4.5.1. We also return SMTP status responses that mimic what Postfix returns.\n\nThanks to a contribution from [Mike Wildpaner](mailto:mikeREMOVETHISPART@wildpaner.com), we support the [StartTLS specification](http://rfc.net/rfc2487.html).\n\nThanks to a contribution from [Marco Trevisan](mailto:mrctrevisanREMOVETHISPART@yahoo.it), we support the [SMTP AUTH specification](http://rfc.net/rfc2554.html).\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdavidmoten%2Fsubethasmtp","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdavidmoten%2Fsubethasmtp","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdavidmoten%2Fsubethasmtp/lists"}