← Back to home
Comparison · Comms

Maddy vs Stalwart

A side-by-side editorial comparison of Maddy and Stalwart — release velocity, themes, recent moves, and the top alternatives to consider.

Shared themes:mail-serverself-hosted

Maddy vs Stalwart: at a glance

FeatureMaddyStalwart
SectorCommsComms
Velocity score0.05.0
Sparks · 30d00
Top themesmail-server, self-hosted, golang, zero-downtime-reloadmail-server, jmap, imap, rfc-compliance
Last editorial update17d ago22h ago
WebsiteVisit →Visit →

What is Maddy?

A one-binary mail server learning to behave like production infrastructure.

maddy is an all-in-one SMTP and IMAP server written in Go, aimed at people who want a working mail host without assembling Postfix, Dovecot and a policy daemon themselves. The 0.9 line moved quickly — 0.9.0 through 0.9.5 between late March and late May — with the sequence following a recognisable shape: a feature release, an immediate patch for a broken integration, a security release, then cleanup. Configuration is directive-based, and much of the changelog concerns the behaviour of individual modules like auth.ldap, check.rspamd and check.dnsbl.

Read the full Maddy trajectory →

What is Stalwart?

Stalwart is chasing mail RFCs and its own storage layer at the same time

Stalwart ships roughly weekly, and the releases divide cleanly between standards implementation and correctness work. v0.16.18 turns toward resource control — bounds on decompressed inbound DMARC and TLS report size, a cap on RocksDB block-cache memory, column families tuned per access pattern, and a queue scheduler that stops rescanning from the earliest pending event. The preceding releases added IMAP UIDONLY, UIDBATCHES and MESSAGELIMIT, plus JMAP email push and VAPID.

Read the full Stalwart trajectory →

Maddy vs Stalwart: editorial side-by-side

M
Maddy
COMMS
0.0

A one-binary mail server learning to behave like production infrastructure.

◆ Current state

maddy is an all-in-one SMTP and IMAP server written in Go, aimed at people who want a working mail host without assembling Postfix, Dovecot and a policy daemon themselves. The 0.9 line moved quickly — 0.9.0 through 0.9.5 between late March and late May — with the sequence following a recognisable shape: a feature release, an immediate patch for a broken integration, a security release, then cleanup. Configuration is directive-based, and much of the changelog concerns the behaviour of individual modules like auth.ldap, check.rspamd and check.dnsbl.

◆ Where it's heading

The project is systematically removing the compromises that made early versions convenient. Obsolete SASL LOGIN was disabled by default, the STARTTLS plaintext fallback was dropped, the maddyctl symlink behaviour and the implicit run command were deleted after four years of deprecation warnings, and libdns providers that have not kept up with 1.x are being cut. Running the other way is operational maturity: no-downtime config reload, queue-length metrics, OpenMetrics fixes, systemd readiness reporting, and SLSA build attestations on release artifacts. This is a project moving from hobbyist-friendly to operator-friendly, and accepting breakage to get there.

◆ Prediction

0.10.0 is already scoped by the deprecations announced in 0.9.1 — expect the flagged libdns providers to be removed and gandi to require Bearer tokens. Given the 0.9.x pattern, a feature release followed quickly by an integration fix is the likely shape.

S5.0

Stalwart is chasing mail RFCs and its own storage layer at the same time

◆ Current state

Stalwart ships roughly weekly, and the releases divide cleanly between standards implementation and correctness work. v0.16.18 turns toward resource control — bounds on decompressed inbound DMARC and TLS report size, a cap on RocksDB block-cache memory, column families tuned per access pattern, and a queue scheduler that stops rescanning from the earliest pending event. The preceding releases added IMAP UIDONLY, UIDBATCHES and MESSAGELIMIT, plus JMAP email push and VAPID.

◆ Where it's heading

Two threads run through every release. One is RFC coverage across IMAP, JMAP, CalDAV and WebDAV, implemented close to the specification including drafts. The other is a long tail of protocol-conformance fixes, many of them cases where JMAP and IMAP disagreed about the same state. The newest release adds a third: memory and scheduling limits, which is what a server codebase starts doing when deployments get large enough for defaults to hurt.

◆ Prediction

Expect continued RFC additions across the JMAP and IMAP surfaces, with more of the storage-tuning work that v0.16.18 started as RocksDB deployments scale.

Alternatives to Maddy and Stalwart

Other Comms products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Maddy or Stalwart.

See all Maddy alternatives → · See all Stalwart alternatives →

Recent activity from Maddy and Stalwart

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 1d agoStalwartResource limits arrive for inbound reports and RocksDB caches
  2. 8d agoStalwartIMAP gains UIDONLY, UIDBATCHES and message-limit extensions
  3. 16d agoStalwartJMAP delivery push arrives; strict relays stop rejecting calendar mail
  4. 23d agoStalwartFix-only release: JMAP semantics and a credential escalation
  5. 29d agoStalwartVAPID lands for JMAP Web Push
  6. 1mo agoStalwartFreeBSD support, plus OAuth scopes for IMAP, SMTP and Sieve
  7. 2mo agoMaddymaddy 0.9.5 fixes nested pipeline logging and systemd reload reporting
  8. 3mo agoMaddymaddy 0.9.4 removes the maddyctl symlink and implicit run command
  9. 4mo agoMaddymaddy 0.9.3 patches an LDAP injection flaw in auth.ldap
  10. 4mo agoMaddymaddy 0.9.2 fixes an rspamd panic on unspecified tls_client
  11. 4mo agoMaddymaddy 0.9.1 flags libdns providers for removal in 0.10.0
  12. 4mo agoMaddymaddy 0.9.0 adds no-downtime configuration reloading

Frequently asked questions

What is the difference between Maddy and Stalwart?

Both compete on the same themes — mail-server, self-hosted — within Comms. Stalwart is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Maddy better than Stalwart?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Stalwart is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Comms products to evaluate alongside.

What are the best alternatives to Maddy?

Top Maddy alternatives in Comms are ranked by recent ship velocity. Browse the "Maddy alternatives" section above for the current picks, or visit /alternatives/maddy for the full list with editorial commentary on each.

What are the best alternatives to Stalwart?

Top Stalwart alternatives in Comms are ranked by recent ship velocity. Browse the "Stalwart alternatives" section above for the current picks, or visit /alternatives/stalwart for the full list with editorial commentary on each.