Tags: debold/GraphMailer.NET
Tags
Release 1.5.1.1094 A patch release with two fixes that operators run into directly. A single mailbox that Exchange Online throttles no longer stalls the queue for every other sender, and the SDK no longer resends busy or timed-out mailbox writes within seconds - which could deliver the same message twice after a gateway timeout. Graph rejections are logged in one line with the error code, request id and the response headers Microsoft support asks for, and every delivery request carries the queue id as its client-request-id. A missing Graph permission is now visible where the admin looks for it: on the ConfigTool's Graph API page, on the Status page and in the periodic operations report, not only in the alert mail. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Log what the malware filter actually does in audit mode Audit mode exists to be watched: it rejects nothing, so the log is the only evidence of what the scanner is doing. Only detections were written though, at Warning, which meant complete silence on a normal mail flow with nothing to find — indistinguishable from a scanner that was never running. Audit mode now logs the disposition of every message at Information: how many parts were scanned and how long it took, which messages a bypass rule skipped, and which ones went out unscanned after a failed or oversized scan. Enforce keeps the same lines at Debug, where the rejection is the event worth seeing. An unavailable scanner is deliberately never logged as "no detection" — the audit trail must not claim coverage that did not happen. The scanner also never reported itself at service start. Its startup line (the AMSI providers it found and the mode it runs in, or a loud error when no provider is registered) was written only once the first message arrived, because nothing resolved the singleton until then. It is now initialised while the service starts, unless scanning is switched off. Recent Detections could likewise show an empty list while detections were on disk: it took the newest 200 files from mail\blocked\ and only then dropped the message rules' discard records, which share that folder, so a busy rule could push every finding out of sight. The limit now counts detections and the search reads past discards, bounded at 5,000 records so the page cannot stall — and says so in the caption instead of claiming there is nothing. The selection moved into DetectionRecordReader, which makes it testable without a visual tree. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Act on a log entry from the log list instead of copying it out Reacting to a rejection meant reading the address off a log entry, switching to the IP Filtering page, pressing Add and typing it back in. Copying an entry at all was possible only from the details panel, and only the message text. Right-clicking a row now offers "Copy entry" — the whole line including timestamp, level, component and any stack trace, which is the form worth pasting into a ticket — followed by every IP address the entry mentions, each with a whitelist and a blacklist choice. A deny reason usually names both the client and the rule it matched, so both are offered. Picking one switches to the IP Filtering page and opens the same dialog the Add button opens, prefilled, so the duplicate check, the validation and the comment field are the ones already there and the address can be widened to a CIDR range first. An address already on the list selects the existing row rather than opening a dialog that could only end in a duplicate error. Navigating there is the point of routing this through the main window: the entry is added to the document but not saved, and the operator has to see the list and the unsaved-changes marker to know that. Candidates are validated as addresses rather than pattern-matched, which is what keeps the menu usable — a log line is full of dotted and colon-separated numbers. Build numbers, Defender platform paths, wall-clock times and zero-padded octets are all rejected, and the regex lookarounds keep a qualified name like Amsi::ScanBuffer from yielding "::ba", which parses perfectly well. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Release 1.3.2.1058: browsable GitHub help, ConfigTool screenshots Finalizes the 1.3.2 changelog. Highlights since 1.3.1: Graph client certificate monitoring, the shared recommendation catalogue with its ConfigTool page, the admin-notifications master switch, strict envelope-recipient delivery, and the help now browsable on GitHub with Configuration Tool screenshots. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
GraphMailer 1.2.3.1013 - Relayed mail is saved to the sender's "Sent Items" - Operations report: informational "Recommendations" box for disabled optional features - ConfigTool Monitoring page leads with Update Check + Usage Telemetry - SMTP session summary log line includes the client's HELO/EHLO name
PreviousNext