Aliases and shared-mailbox access name their members as text
GET and POST /api/email/aliases (and /aliases/member/{id}) and GET and POST **************** answered with the entities themselves, whose Long memberId and gran...
An opt-out row carries the member behind its last change
The opt-out list named who made each address's last change (lastActorName) but not who they are, so the settings page could not open their member card. Each row...
Saving a calendar/contacts integration never blanks or drops its stored credentials
A contact integration's credentialsJson was replaced by whatever a save sent. The org CalDAV/CardDAV tab sends all four server fields (empty — they never show w...
A shared mailbox's access list is only readable inside its own organization
GET **************** called **************** which read the access rows for any mailbox id. Every other access operation (update, delete, grant, revoke) loads t...
A shared mailbox response carries no IMAP login
GET /api/email/shared-mailboxes (and /my-access, create, update) return SharedMailboxEntity itself to any session in the organization. Until the library's crede...
A person taken out of a drip stays out
The engine moves on up to 200 due people per drip from copies it read at the start of a pass, up to 25 seconds old by the time each is used. Meanwhile a member ...
A drip's People counts follow the search, so All is always the sum of its chips
Drip campaigns
A drip is an automated sequence of emails a person enters when something happens: a lead arrives (by hand, imported, or from an integration), a lead's status or...
A campaign's replies go to NoReply, the member's e-mail, or a custom address — NoReply by default
The editor's Reply-To becomes three choices (CampaignReplyTo), kept in the existing reply_to column. No DDL. - NO_REPLY (empty column, the default): Reply-To: N...
Stop refreshing a mailbox grant no app can refresh, and say it needs reconnecting
An org connected Microsoft 365 through Kamo's platform app; the platform app was later switched off and the org has no registration of its own. The resolver the...
Liveness probe on /actuator/health/liveness, not the DB-aware aggregate
The aggregate /actuator/health includes the DataSource indicator, so restarting the database failed liveness on every pod at once and restarted the whole platfo...
Bounces to org sending domains come home, test sends are signed, and the relays' DNS is read
Async bounces. A campaign's envelope sender is its From at the organization's sending domain, whose MX (through the CNAME to contact.kamocrm.com) is the shared ...
Release idle Hikari connections now that YSQL pooling is shared
The connection manager no longer pins sessions **************** so idle app connections no longer each hold a database backend. Keep the pool maximum, but stop ...
Campaign mail is signed as, sent from, and routed by its verified sending domain
A campaign may name its own From on a verified domain; otherwise it goes as the org's bulk sender — which must itself be on a verified domain (saveSender refuse...
Domain Setup's API, the shared relay's sender map, and a sweep that confirms records live
**************** GET the tab (VIEW_BULK_EMAIL), GET lookup for the add form, POST add, POST {id}/check, DELETE (MANAGE_BULK_EMAIL); every write answers with the...
Sending domains — add one, read its DNS record by record, verify it, know what an address may do
A sending domain (news.acme.com) is kept in the org's encrypted bulk provider blob with its DKIM key. SendingDomainChecker reads what receivers will see — SPF e...
DKIM keys and a relaxed/relaxed rsa-sha256 signer for organizations' sending domains
DkimKeys generates a domain's RSA-2048 key (kept in the org's encrypted bulk provider blob) and the TXT value a member publishes at kamoXXXXXX._domainkey.<domai...
The sendToUser ratchet counts three overloads [skip ci]
TransactionalSendRatchetTest pinned sendToUser at two overloads, so that its first test provably inspects them rather than passing on none. c47fcf6 added the bl...
Every refused request says why, not just campaign calls
2a72597 gave the campaign controllers the member's sentence instead of "Bad Request". The same loss happened everywhere else in EmailService that refuses with a...
DNS for sending domains — each domain's own nameservers first, SPF evaluated, DNS provider named
LiveDnsResolver asks the zone's authoritative nameservers (found through 1.1.1.1/8.8.8.8), so a record a member just saved at their DNS provider is seen at once...
The shared org relay (47.181.8.86) is seeded for every organization; the platform relay stays KamoCRM's
PlatformRelayProperties now knows both in-cluster relays: postfix-bulk (47.181.8.87, hello.kamocrm.com) and postfix-orgs (47.181.8.86), with the egress address,...
The campaigns widget read drops its Live / Sent / Drafts counts
CampaignWidgetView.groups carried those counts only for widget builds from before the stage tabs (kamo-internal d0b56adf). Every deployed build since 949d3889 r...
A refused campaign call says why, instead of "Bad Request"
CampaignService refuses with a ResponseStatusException carrying a sentence written for the member ("Pause the campaign before deleting it.", "Only paused campai...
The campaigns widget reads by stage, the stages the campaigns screen files by
The launchpad widget's read now groups and counts campaigns by the stages /marketing/email's tabs use: In-Progress (sending), Not Started (draft or scheduled), ...
Archive a campaign, and the widget leaves archived ones out
POST **************** and /unarchive (MANAGE_BULK_EMAIL) set and clear the campaign's archivedAt, and CampaignDTO carries it. The /marketing/email screen files ...
A live read and live frames for the Email Campaigns home widget
GET /api/email/widget/campaigns is the launchpad widget's one read, built for a pane that sits on every campaign viewer's home page all day: lean rows with no b...
Blind copies on the service-to-service template send
SendTransactionalRequest takes an optional bcc list, carried through sendToUser and deliver onto the SMTP envelope — including the platform-address retry — so a...
Accept OCI image indexes when resolving the built digest [skip ci]
The images are pushed as OCI image indexes, so asking the registry for a single image manifest only answered 404, the digest came back empty and the check faile...
Restart when a same-commit rebuild leaves pods on the old digest [skip ci]
The rollout step tried to detect a same-commit rebuild by comparing the Deployment's image reference before and after `set image`. "Apply manifests" has already...
Name the recipient in a header that headers-only complaint reports keep
Microsoft's feedback-loop reports now carry only the original message's headers, with anything shaped like an address masked. Every campaign message carries X-K...
Open and click tracking, complaint reports by email, capped outbox counts
- Tracking: the composer wraps a campaign's web links in a signed redirect (<base>/c/<token>?u=&s=) and adds an open pixel (<base>/o/<token>), as each org c...
One eligibility engine decides who a campaign may mail
Every list add (a member's, an audience's, a copy) and the send itself ask one engine whether an address may receive the campaign, cheapest check first: syntax,...
Running campaign counts, and Send to latest
Counts: - Every status change moves a campaign's counts by exactly what it changed: a send +1 sent, a later bounce report -1 sent +1 bounced, an add +n, a r...
A campaign's recipient list pages both ways, with totals, at any size
The list was already read a page at a time, but only forwards, as an endless scroll with no total — and a status filter found its rows by walking the list in ad...
Saving a campaign no longer fails with "Restart read required"
The bulk-provider row (hosts, send window, warm-ups, campaign audiences) was read inside callers' longer transactions. A campaign save writes the row's audience...
A campaign can go to every lead, account or application a member can see
"All leads / accounts / applications" is a rule, not a list. It is stored with the campaign (the bulk-provider blob, campaignAudiences — no DDL), runs on the ac...
The preference page in every language the product speaks
The page behind every unsubscribe link only spoke English. It now speaks all 22 languages the product UI ships: English, Chinese, Hindi, Spanish, French, Arabic...
An unsubscribe by email is honoured, not dropped
Every bulk and shared-article message offered unsubscribe@<sender's domain> in its List-Unsubscribe header, but nothing read that mailbox - for a tenant it was ...
Opt-out screens refresh live when anyone changes the list
The ledger now tells OptOutChangePublisher after every committed change - a recipient on the preference page, a bounce, a member in Settings - and it publishes ...
The organization owner can open the opt-out list
A brand-new right is granted to nobody on the day it deploys, so a list gated only on MANAGE_EMAIL_OPT_OUTS would ship visible to no organization. The owner hol...
Name the sender once at the top of the preference page
With a logo, the name is its alt text and is not written out again beneath it; without one, the name is the header. It was shown, and read aloud, twice.
A real preference page behind every unsubscribe link
The unsubscribe link opened a bare confirm-or-leave card. Someone who only wanted fewer emails had no way to say so, and nothing told them why they were being m...
The opt-out list only names contacts from organization books
A member's personal address book is theirs; the org-wide opt-out list must not become a way to see whose private contacts include someone.
An org admin can see and change the whole opt-out list
Settings -> Email -> Opt Out now has its API under /api/email/opt-outs, behind MANAGE_EMAIL_OPT_OUTS (god bypasses): a summary with the last 30 days, the list f...
Every suppression check and bounce goes through the opt-out ledger
SuppressionService now asks EmailOptOutLedger, so a check sees the do-not-email list, pauses and topics alike, and a bounce lands in the same history as an unsu...
Several outbound hosts per org, sent round-robin, each warmed on its own, inside a send window
An organization's campaign mail now leaves through any number of outbound hosts, one message at a time in rotation, instead of one bulk provider. - Hosts: an o...
The NoReply ledger can be filtered by subsystem, pruned, and told what to record
Each row now names the subsystem that sent it and, for a template send, the template key. EmailTemplateService and the campaign sender open a NoReplyOutboundSou...
Every campaign is sent as the org's bulk sender, and its From never pauses it
A campaign's own from_email/from_name are no longer read: the From is always the address and name on Settings > Email > Bulk Email Sender (else the org's NoRepl...
Startup checks for the one-address-per-campaign index instead of creating it
EmailService ran CREATE UNIQUE INDEX on every startup. DDL on this cluster costs every service about fifteen minutes of "schema version mismatch", too much to r...
Review fixes to the provider blob, delivery reports and test send
The provider blob is always written in a transaction of its own, so its lock query stays the first statement and a lost lock race can be retried even when a cal...
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
