When email_in_authserv_id is set and an incoming email carries a matching Authentication-Results header with no result (Authentication-Results: ``mx.example.com``; none, the RFC 8601 §2.2 “no-result” form), creating the post fails with:
NoMethodError: undefined method 'each' for nil
lib/email/authentication_results.rb:45:in 'block in Email::AuthenticationResults#calc_dmarc'
The post is lost, and the sender gets no rejection email.
Why: in parse_header, the no_result branch of authres_payload matches, so resinfo_val is nil and parsed_resinfo is never assigned. The result is { authserv_id: "``mx.example.com``", resinfo: nil }, and calc_dmarc then calls result[:resinfo].each.
When it happens: some MTAs add the no-result form when they ran no checks. rspamd does this for unauthenticated mail from its local_addrs, for example mail relayed from inside the network. The crash only shows when a post is created (Email::Receiver#create_post → auth_res_action). Mail that is rejected earlier, for example from a stranger, never reaches it.
Reproduce (rails console):
SiteSetting.email_in_authserv_id = "mx.example.com"
Email::AuthenticationResults.new(["mx.example.com; none"]).verdict
# => NoMethodError: undefined method 'each' for nil
Suggested fix: in calc_dmarc, Array(result[:resinfo]).each do |resinfo|, or set parsed_resinfo = [] in parse_header. A no-result header then counts as gray, which matches its meaning.
Seen on ESR v2026.7.3, and the same line is still on main.