Exim 4.100 Released: Native DMARC, Hardened Security, and 30 Years of Linux MTA History

Published by

Exim has released version 4.100, celebrating thirty years of development since its inception by Philip Hazel in 1995. This update introduces native DMARC evaluation, enhances security by addressing vulnerabilities, and consolidates features from the previous 4.99 release cycle. Key improvements include taint tracking for endpoint certificates, fixes for performance regressions, and new logging and configuration capabilities. The update also emphasizes a shift towards loadable modules, reducing the attack surface and simplifying auditing, while all source tarballs are cryptographically signed for security



Exim 4.100 Released: Native DMARC, Hardened Security, and 30 Years of Linux MTA History

Exim has shipped version 4.100, marking exactly thirty years of continuous development since Philip Hazel first wrote the project at the University of Cambridge in 1995. The release consolidates two years of experimental additions like native DMARC evaluation, Public Suffix List lookups, and dynamic module enumeration, while specifically patching a use-after-free vulnerability and several performance regressions introduced during the 4.99 cycle. Security hardening remains the top priority, with taint tracking now extending to certificate extraction and the eval operator, alongside four high-severity CVEs addressed between April and August 2026

Exim 4.100 Released: Native DMARC, Hardened Security, and 30 Years of Linux MTA History @ Linux Compatible