hMailServer 6.2.5

Built 15 June 2026 6.2 series

This is not the current release. hMailServer 6.3.3 is the one to install unless you need this exact version.

Downloads for 6.2.5

Windows

Windows 10 (version 1607 or later) and Windows 11, or Windows Server 2016 and newer; 64-bit only. Run the installer as an administrator: it upgrades an installation older than this version in place, and it cannot go backwards — an older server refuses a database a newer one has upgraded, so back up the database and the data directory first. It is not Authenticode-signed, so Windows names an unknown publisher and SmartScreen warns before it will run it.

  • hMailServer-6.2.5-x64.exex64 · 78.9 MB
    Download
    SHA-256dbc34efe35d3…16755448

What’s new in 6.2.5

hMailServer 6.2.5 is a critical fix release. The default fresh install — an internal SQL Server Compact database with DPAPI secret protection (both shipped defaults) — could not connect to its own database. Anyone running a default install should upgrade.

Full release notes for 6.2.5 4 sections

Critical fixes

  • DPAPI database-password truncation (SQL CE error 25028). IniFileSettings::ReadIniSettingString_ used a fixed 255-character buffer, so GetPrivateProfileString truncated the ~356-character DPAPI-protected database-password envelope. The truncated blob failed to decrypt, yielding an empty password and SQL CE error 25028 (Authentication failed) on a default install. The buffer is now 4096 characters (also protects long OAuth2 HMAC secrets and the password pepper).
  • Fresh-install database version (6004 → 6005). The CreateTables scripts (MSSQL / MySQL / PostgreSQL — SQL CE uses the MSSQL script) still stamped hm_dbversion = 6004 while the server required 6005, so a brand-new install reported "database too old" (6004 vs 6005). Bumped to 6005. (The recipientdsnnotify column was already present; only the version row was stale.)

Validation

Validated end-to-end on a real Windows Server 2025 Active Directory domain controller:

  • Default internal-DB install now connects successfully.
  • AD authentication passes via COM ValidatePassword (both DNS domain.tld and NetBIOS DOMAIN\user forms) and a real IMAP LOGIN (correct password → OK, wrong → NO).

Control Panel

The modern .NET 8 WPF Control Panel (hMailCP.exe) reaches full settings parity with the classic Administrator. The Server Status page (version, server state, database details, statistics, session counts, uptime, configuration-warnings panel including open-relay detection) and the per-account rule criteria/action editor are validated and wired into navigation.

Downloads

  • hMailServer-6.2.5-x64.exe — Windows x64 installer (bundles the server, the Control Panel, and the .NET 8 Desktop Runtime bootstrapper). hmailserver.spdx.json / hmailserver.cyclonedx.json — Software Bill of Materials (SPDX + CycloneDX).

Copyright © 2026 Christopher Holloway / Progressive Robot Ltd.

Release facts

Version
6.2.5
Packages
1Windows, x86-64
Installer SHA-256
dbc34efe35d3…16755448hMailServer-6.2.5-x64.exe

Every file in 6.2.5

Full SHA-256 of each file as recomputed on this server. The SBOM is not needed to install; it lists every component in the build. Nothing in this release is signed — the signing workflow came later — so the hash above is this server’s own recomputation rather than a check against something the project signed.

FileWhat it isSizeSHA-256Signature
hMailServer-6.2.5-x64.exeWindows installer · x6478.9 MBdbc34efe35d3eaa6a7ee0437ed5eb7e6ff011f147df96f65e4e9f19716755448
hmailserver.spdx.jsonSBOM (SPDX)Every component in the build, in SPDX JSON.84 KBa1be2ec903675705bce7d701dcabedf5a68ca16691943252abd85bd92e9797c0
hmailserver.cyclonedx.jsonSBOM (CycloneDX)The same inventory in CycloneDX JSON.43 KB557b8dfcc51dd71c1d938514e7308497f5ab3638a7f3a849721e6c0371f595bf