Two new enterprise policies let you disable Thunderbird's built-in chat client and cloud-upload FileLink feature across an entire fleet. It's the least flashy release note of the week — and the most important one if email is infrastructure.

Thunderbird 157 landed September 30, and the headline features sound like maintenance: the status-bar 100%-CPU bug is fixed, IMAP sender display is correct again, Gmail OAuth2 behaves, and the port field in manual IMAP/POP setup is now optional. Worth updating for — but not worth writing about. What is worth writing about is two one-word additions to the enterprise policy engine: DisableChat and DisableFileLink.

Why off-switches are the feature

Every Thunderbird install ships with a chat client inside it — XMPP, IRC, Matrix, the works — that nobody provisioned and few people manage. On a home machine that's a harmless extra. On a company or government fleet, it's an unapproved communications channel sitting one click away from every inbox.

FileLink is the bigger one. Thunderbird's answer to oversized attachments is to upload them to a cloud provider and send a link instead. Convenient — and a quiet end-run around every data-loss-prevention rule your mail gateway enforces, because the file never passes through the gateway at all. An employee attaching a 50 MB internal spreadsheet is one default setting away from storing it on a third-party service. Admins have long wanted this controlled centrally; now they can kill it fleet-wide with one policy line.

The context: digital sovereignty is the product strategy

This isn't a one-off. In their September development digest, the Thunderbird team is explicit about why Q3 was heavy on enterprise work: governments and institutions are moving toward digital sovereignty and asking for FOSS infrastructure they can actually govern. The stated goal is to bring Thunderbird's policy framework up to the standard Firefox set — granular administrative control over end-user configurations, so an organization can deploy Thunderbird the way it deploys any other managed application.

Policies are the difference between "nice open-source mail client" and "deployable mail client." A CIO can't standardize on software where every user can re-enable whatever the compliance team disabled. Two off-switches per release, compounded quarterly, is how Thunderbird becomes the obvious answer in procurement meetings.

How to deploy it

On Linux, drop a policies.json next to the install (typically /usr/lib/thunderbird/distribution/policies.json on distro packages) or push it through your configuration management:

{
  "policies": {
    "DisableChat": true,
    "DisableFileLink": true
  }
}

Verify on a client by opening about:policies — it shows exactly which policies are active and where they were loaded from. Same engine as Firefox, same deployment story, nothing new to learn.

The rest of the release

Short version for the fleet update ticket: 157 also fixes disappearing inline images in edited drafts, recurring calendar events leaking past their end dates, CalDAV task sync staleness, and message filters firing when they shouldn't. The OpenPGP handling got better too — external content in encrypted messages with integrity protection now displays without weakening the encryption. Meanwhile the ESR branches moved to 153.4.0 and 140.17.0, the latter being the final release of that series, so if you're standardizing on ESR, that migration is overdue.

The flashy features get the screenshots. The policies get the contracts. Update your fleet, drop the two lines into policies.json, and sleep a little better about where your attachments live.


Sources: Thunderbird Monthly Development Digest: September 2026 · 9to5Linux — "Mozilla Thunderbird 157 Email Client Released with New Enterprise Policies" · Linuxiac — "Mozilla Thunderbird 157 Fixes 100% CPU Usage, OpenPGP, and IMAP Issues"