shouldiuse.io

VERDICT

Should I use Stalw?

Stalwart Mail & Collaboration Server - stalw.art

Depends. Strong fit if you have ops skills and want a free, all-in-one self-hosted mail stack. Non-technical teams should buy hosted email like Google Workspace instead.

Confidence

Medium. Based on 13 usable public sources; many search results were unrelated noise and no named enterprise customers were found.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo evidence reviewed
  • Security posture

Pricing

Free

Open source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Paid editionsNot listed in sources reviewed

Best for

  • Self-hosters
  • Privacy-focused small orgs
  • Teams replacing hosted Gmail with owned infra
  • Open-source-first shops

Not for

  • Non-technical teams without a sysadmin
  • Anyone wanting hosted Gmail simplicity
  • Businesses that can't manage IP reputation and deliverability
  • One-person shops that just need working email

Gotchas - check before you buy

high

Guess: email migration and IP reputation take weeks; plan deliverability warm-up.

medium

Multiple paid editions differ; read the compare page before committing.

medium

Commercial support scope unclear; community runs on Reddit and forums.

medium

Known 2026 DoS CVEs mean you must patch promptly or stay exposed.

Pros and cons

Pros

  • All-in-one: email, calendar, contacts, files on one server
  • Open-source core, free to self-host
  • Positive shout-outs from the self-hosting community
  • Publishes security advisories openly
  • One-click Railway deployment available

Cons

  • Recent denial-of-service vulnerabilities disclosed in 2026
  • Self-hosting email demands real ops and deliverability skills
  • Support appears community-run; paid support details thin

Sources & method

Analyzed 9/27/2026 - 13 sources - Known 2026 denial-of-service vulnerabilities; advisories disclosed openly and a security page exists.

official x6review x4security x3
  • Out-of-Memory Denial of Service via Malformed Nested Input, Official GitHub advisory GHSA-jm95-876q-c9gw, published Feb 2026.
  • CVE-2026-26312 — denial-of-service vulnerability, Listed against stalw/stalwart in public CVE databases.
  • Dependency vulnerability report for Stalwart binary, User-raised report on official support forum, Jul 2026.

Key stats

  • Value for money: 4/5

    Rating

  • Free

    Starting price

  • 13

    Sources

  • Analyzed

  • Value for money: 4/5. Free open-source core; paid editions optional
  • Ease of use: 3/5. Admin dashboard included, but self-hosting email is hard
  • Feature depth: 4/5. Mail, calendar, contacts, files in one server
  • Support quality. No evidence reviewed
  • Security posture: 3/5. Transparent advisories, but real 2026 DoS CVEs
  • Yes Free tier Open-source core on GitHub
  • London, UK Headquarters Per official site footer
  • 2+ Known CVEs DoS vulnerabilities, 2026
  • One-click Deploy option Railway template available

Pricing

Open source

Free

  • Self-host the full mail server
  • Community support

Paid editions

Not listed in sources reviewed

  • Multiple editions per compare page
  • Pricing FAQ available

Security

Known 2026 denial-of-service vulnerabilities; advisories disclosed openly and a security page exists.

  • Out-of-Memory Denial of Service via Malformed Nested InputOfficial GitHub advisory GHSA-jm95-876q-c9gw, published Feb 2026.⁷
  • CVE-2026-26312 — denial-of-service vulnerabilityListed against stalw/stalwart in public CVE databases.⁸
  • Dependency vulnerability report for Stalwart binaryUser-raised report on official support forum, Jul 2026.⁹

What users say

Self-hosting communities praise it warmly, but large-scale review data is essentially absent.

“Just a shout-out to self-hosting email server StalWart.”
Reddit, r/selfhosted
“Calendars, Contacts and Files in Stalwart”
Hacker News discussion
Full analysis

Based on 13 usable public sources; many search results were unrelated noise and no named enterprise customers were found.

Powerful open-source all-in-one mail server — great if you run your own servers; overkill if you just want working email.

Methodology

Based on 13 usable public sources; many search results were unrelated noise and no named enterprise customers were found.

Sources

  1. official
  2. official
  3. official
  4. official
  5. official
  6. official
  7. security
  8. CVE-2026-26312 — stalw / stalwartopencve.alliance.unm.edu
    security
  9. security
  10. review
  11. review
  12. review
  13. r/stalwartlabsreddit.com
    review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.