Stalwart Mail Server (community/open-source edition)
Criterion scores (servers model)
| Code | Criterion | Weight | Score |
|---|---|---|---|
| S1 | Sovereignty & self-host design | 20% | 98 |
| S2 | FOSS purity/licensing | 10% | 93 |
| S3 | Security posture & audits | 20% | 92 |
| S4 | Privacy & log control | 10% | 90 |
| S5 | Complexity & attack surface | 15% | 86 |
| S6 | Ops, upgrades & deliverability | 15% | 84 |
| S7 | Community & longevity | 10% | 80 |
Evidence anchors: Open-source edition positioning (stalw.art/open-source), second security audit (stalw.art/blog/security-audit-2025), and RUN_AS_USER privilege escalation issue fixed in 0.8.0 (CVE-2024-35179).
Reading: Feature-rich, audited Rust suite; slightly more complex than maddy but with extremely serious security posture.