← All issues

This Week In Email — August 5, 2026

The Russian state actor that spent last month popping Zimbra just took the same no-click webmail exploit to on-prem Exchange OWA — and it's been in the wild since May. Google confirmed the full scope of its third-party-account teardown in Gmail: Send-as, Gmailify, and POP fetching all die in January 2027. RIPE Labs dropped ten years of DNS measurement data showing just how consolidated email hosting has become — and that DMARC enforcement is actually going backwards. And Chrome is running an origin trial that could kill the verification email entirely. It's a lot. Let's get into it.

In This Issue

Top Stories

Laundry Bear Takes Its No-Click Webmail Exploit From Zimbra to Exchange OWA

Security & Anti-Abuse

Following up on last week's Zimbra zero-day coverage: Laundry Bear has pivoted the same "view the mail, lose the mailbox" mechanic to a far larger install base. CVE-2026-42897 is an XSS in Outlook Web Access on on-premises Exchange Server that fires when a user simply opens a crafted email. Microsoft traced exploitation back to May 2026, with the current wave starting July 22. Targets include US and European government, telecom, financial, hospitality, and aerospace organizations.

The particularly nasty part: persistence survives credential rotation. Victims reset passwords and the attackers keep mailbox access anyway. Not phished. Not brute-forced. Just quietly resident.

The through-line is now unmistakable — Zimbra, then Roundcube, now Exchange OWA. Self-hosted webmail is squarely in the espionage crosshairs, and the actors are working down the list by install base. If you run on-prem Exchange, patch immediately and hunt — rotating credentials alone will not evict this actor.

Sources: BleepingComputer, The Register, The Hacker News, Help Net Security

Google Confirms the Full Teardown: Send-As, Gmailify, and POP All End January 2027

Deliverability & Authentication

Following up on the Gmailify and POP-fetch sunset we covered last week: Google's support documentation now confirms the third leg. "Send mail as" from third-party addresses — @yahoo.com, @hotmail.com, anything non-Google — also dies in January 2027, on web and mobile alike. The transition period starts Q3 2026, which is to say now, and new configurations may be restricted before full removal. Workspace aliases and Gmail-to-Gmail send-as are unaffected. The story blew up on Hacker News this week as users discovered the scope.

For senders, here's the operational read: a real population of recipients has lived in Gmail for years while sending and receiving as another domain. Come January, they either migrate addresses or scatter to native apps — and either way, expect address churn and engagement-signal shifts on those cohorts. If your list skews long-tenured consumer, start watching now.

Sources: Google support doc, Hacker News discussion

Deliverability & Authentication

RIPE Labs: Ten Years of Email DNS Data — Two Providers, a Stubborn Plateau, and a Very Long Tail

This is exactly the kind of vendor-neutral measurement work the industry needs more of. Using daily OpenINTEL snapshots from 2016 to 2026 across the Tranco Top-1M domains, RIPE Labs shows self-hosted mail collapsing from 44.6% to 22.4% of domains, with Google Workspace and Microsoft 365 now handling 38.6% of inbound MX between them. The next-closest provider is Proofpoint — at 1.9%.

The sharper finding is on DMARC. Of roughly 458K domains publishing a DMARC record, only 46.9% actually enforce (quarantine or reject) — and enforcement declined 0.44 percentage points over a recent thirty-day window. Having a DMARC record and being protected by DMARC are two entirely different things, and this data says the industry is treating it as a compliance checkbox, not a security control.

Also worth noting: 36K+ unclassified MX hostnames — a long tail invisible to mainstream measurement. Next time a vendor deck shows you a DMARC adoption curve going up and to the right, remember this study. The records are multiplying; the protection isn't.

Source: RIPE Labs

Chrome Runs an Origin Trial That Could Kill the Verification Email

Chrome is testing the Email Verification Protocol — the browser proves you own an email address by checking directly with your email provider. No one-time code. No magic link. The user never leaves the signup page. And Gmail is already live as a provider in the trial. The blog post is a few weeks old, but Hacker News attention landed this week and it deserves yours.

If this sticks, a workhorse email use case partially leaves email. Verification mail volume shrinks, and "email as identity layer" moves partly into the browser. Deliverability folks should watch what happens to transactional OTP streams; product folks should watch the conversion claims. A browser vendor and the largest mailbox provider testing this together isn't a side experiment — watch this space.

Sources: Chrome Developers blog, HN discussion

Events & Community

Links Worth Your Time

That's the week. If something is wrong, reply and tell me — I read every response. Better yet, hit "forward" and send it to a colleague who should be reading.

— John


This Week In Email — thisweekin.email

A note from John
This one is coming to you from new machinery.
This is the first issue sent from This Week in Email’s own infrastructure — new signup page, new archive, new sending setup, same newsletter. If anything looks off — a broken link or image, odd formatting, or this landing somewhere it shouldn’t — hit reply and tell me. I read every response.

Enjoyed this issue?

Subscribe to This Week in Email and get future issues delivered to your inbox.