Files
bongo/docs/client-compatibility.md
T
Mario Fetka 5897512fd9 Modernize Bongo protocols and administration
Complete the current IMAP, POP3, SMTP and proxy protocol work; add the validated setup and administration UI, packaging examples, tests, and maintained roadmap/documentation for the 0.7 development line.
2026-07-18 04:26:00 +02:00

2.5 KiB

Client compatibility

Bongo implements open mail, calendar, and contact protocols. Compatibility depends on the client using those protocols; Bongo 0.7 does not emulate an Exchange server.

Modern clients

Thunderbird can use authenticated SMTP submission and IMAP, with POP3 as an alternative. CalDAV and CardDAV accounts expose Bongo calendars and contacts. A ManageSieve-capable Thunderbird extension or another Sieve editor can upload the user's filter scripts on port 4190.

Other standards-based desktop and mobile clients should use:

  • IMAPS on 993 or IMAP with STARTTLS on 143;
  • submission on 587 with STARTTLS or implicit TLS on 465;
  • POP3S on 995 only when POP3 is required;
  • CalDAV and CardDAV through the external HTTPS Web URL.

Outlook can use generic IMAP/POP3 and SMTP accounts. Native MAPI/Exchange mailboxes, ActiveSync, and Exchange calendar semantics are not implemented. Some Outlook versions require a separate CalDAV/CardDAV connector.

Web browsers

The Bongo Web interface retains the classic Dragonfly appearance but runs on maintained Python 3 code and current browser APIs. It is not targeted at historical Firefox 1.x or Internet Explorer versions. JavaScript, secure cookies, a correct external HTTPS URL, and accurate trusted-proxy handling are required for a public deployment.

Legacy mail clients

The server retains classic IMAP4, POP3, SMTP HELO, and clear protocol ports where practical. Old clients which do not understand modern capability names can therefore continue to perform basic mail operations.

Legacy TLS is never a global default. If a Windows 98-era client or embedded device cannot negotiate TLS 1.2, place it on a trusted network and enable the smallest listener-specific compatibility policy which works. Prefer the rate-limited port 26 relay for printers, UPS devices, access points, cron jobs, and management controllers which cannot authenticate safely. Sender normalisation and DNS/address mapping can then turn local device identities into valid Internet senders.

Do not expose a compatibility listener to the Internet and do not disable modern TLS on the normal user listeners. See tls.md and smtp.md.

Future clients

JMAP is scheduled for 0.9 and will use the same Store rather than replace IMAP. Exchange/MAPI compatibility remains later research and is not a 1.0 release requirement. External provider OAuth and an optional OIDC/Authelia master-login source are 1.0 roadmap items; service-scoped app passwords remain the stable protocol credential model.