Independent coverage of the full email ecosystem.
Meanwhile France's CNIL tracking-pixel deadline is two weeks out, the IETF DKIM working group dropped its second material document in six days, and an agentic-AI acquisition is starting to reshape what a customer engagement platform looks like underneath. Heavy week. Let's get into it.
Blesta ransom email passed SPF, DKIM, and DMARC — what authenticated abuse actually looks like in a 48-hour news cycle
CNIL tracking-pixel deadline: July 14, 2026 — two weeks out, transitional regime evaporates after
Phishers aren't building infrastructure. They're borrowing yours. — Kaspersky on the AWS SES IAM-key economy
DKIM2 advances to draft-03 — and a BCP-00 — two material WG documents in six days
Events & Community — IETF 126 DKIM session July 21, DMA Advanced Email Conference London July 7
Links worth your time — MoEngage / Aampe, the 2026 Great ISP Email Retreat, theMarketer / Conectoo, Spamhaus CERT, SMB1001
Category: Security & Anti-Abuse
On June 26, customers of Blesta — the billing platform widely deployed by hosting providers — received a "Blesta Compromised" ransom email from no-reply@blesta.com. The message threatened to leak the customer database the next day. The attackers had compromised a temp support account originally created for a third-party virtualization vendor, then used it to drive Blesta's own customer portal. The ransom mail went out through Blesta's real outbound infrastructure on Mailgun.
SPF passed. DKIM passed. DMARC passed against Blesta's own p=reject policy. Every authentication signal a receiver could check confirmed the message was routed through the legitimate sender's infrastructure — because it was. DMARC confirms the route the mail took. It was never designed to confirm the intent of the message moving along that route.
This is the cleanest example of "authenticated abuse" we've seen in months, and it pairs with the Xero, Atlassian Jira, and AWS SES patterns we covered earlier this year. The through-line is consistent: in 2026, with spoofing largely closed off by DMARC enforcement at the major receivers, the dominant residual phishing pattern is attackers operating mail from inside a legitimate sender's authenticated infrastructure. If your detection stack still treats SPF/DKIM/DMARC pass as a strong safety signal, this is the case study to take to your security team this week. The signal it carries is "the route is real." Nothing more.
Sources: Suped, DMARC Report, LowEndBox
Category: Regulatory & Compliance
France's CNIL published its email tracking-pixel recommendation on April 14, with a 90-day transitional window. That window closes July 14 — two weeks from today. The clock is real.
The compliance shape: any pixel collecting marketing-measurement data (open, time-on-message, render context) is now treated like a tracker under the ePrivacy Directive. For contacts collected before April 14, senders have until July 14 to send a notification email explaining pixel use and offering an opt-out. Miss the window and the transitional regime evaporates — re-collecting explicit pixel consent across the entire pre-April-14 contact base becomes the only legal path forward. Italy's Garante is on the same arc, with the six-month Italian window ending October 28. Lewis Silkin's comparative analysis published June 23 lays the two regimes side by side.
The carve-out worth knowing: pixels used purely for deliverability hygiene — suppressing chronic inactives, throttling cadence to disengaged segments — are not treated as marketing-measurement and don't require consent. Anything used to feed engagement scoring, journey orchestration, or campaign analytics does. Most ESP integrations don't separate the two cleanly at the pixel level. That engineering work is the part senders keep underestimating.
CNIL enforcement — formal notices, investigations, sanctions — is expected to begin immediately after July 14. If your EU contact base predates April 14 and you haven't sent the notification email yet, this is what you should be doing this week. Not next week.
Sources: Spam Resource, Lewis Silkin, Inside Privacy (Covington), iubenda — Garante guidance
Category: Security & Anti-Abuse
Kaspersky's Securelist research, picked up by emailexpert this week, documents a sharp rise in phishing campaigns sent through Amazon SES — not by exploiting any flaw in SES itself, but by harvesting AWS IAM access keys leaked in GitHub repos, .env files, Docker image layers, public S3 buckets, and similar developer mistakes.
The mechanics are mundane and that's the problem. Attackers scan with TruffleHog and equivalent tools, check each leaked key for SES sending permissions, and inherit the legitimate AWS customer's full reputation the moment they find one. No domain registration. No warmup. No infrastructure to build. SPF, DKIM, and DMARC all pass because the mail is genuinely originating from the victim's authenticated sending domain. The dominant campaigns are fake DocuSign-style document-signing notifications and BEC plays — fabricated email threads and forged invoices aimed at finance teams.
The architecture lesson generalizes well beyond SES. Sender reputation in 2026 is inherited by whoever holds the credentials, not by whoever earned them. That applies to every shared ESP — API key in a leaked repo, OAuth refresh token in a stale backup, service-account credential baked into a Docker image — and to every SaaS-mail integration that ships a long-lived secret. Rotate, scope, and monitor. If your SES setup still uses long-lived IAM users instead of role-assumption with short tokens, that is the week-one fix.
Sources: Kaspersky Securelist, emailexpert, TechRadar
The IETF DKIM working group landed two material documents in six days. On June 18 the WG published the first DKIM2 Best Current Practices draft (draft-ietf-dkim-dkim2-bcp-00). On June 24 the main spec advanced to draft-ietf-dkim-dkim2-spec-03. Two thirds of a year before the Q4 2026 mailbox-provider experimental-rollout target, the working group's tempo is picking up — not slipping.
The headline changes in spec-03. A new nd= tag has been introduced as an alternative mechanism to the existing mf= and rt= tags for handling imaginary hops between domains — the construct that always made forwarding scenarios under DKIM2 their own engineering problem. A new feedhere flag has been added to support privacy-conscious forwarding scenarios. The list of header fields ignored during signing has been promoted into its own dedicated section, with the experimental Delivered-To: header added to it. The rules for DSN propagation have been tightened so a DSN always carries the message headers up to the point where the DSN creator saw the message on its outward journey. Null recipes for header field modifications have been eliminated.
None of that is procedural cleanup. The forwarding-edge cases that always blow up real DKIM deployments — your delegated-domain replays, your Listserv hops, your security-vendor inline rewrites — are exactly the surface area this revision touches.
IETF 126 in Vienna kicks off July 18. The DKIM session Tuesday July 21 is where spec-04 direction gets set and the Q4 experimental-rollout target either holds or starts slipping. Watch that session.
Sources: IETF Datatracker — DKIM2 spec, Suped — DKIM2 BCP background
IETF 126 DKIM working group session — Tuesday July 21, 14
–16 Europe/Vienna, Park Suite 6. With spec-03 fresh and the BCP-00 draft only six days older, this is the session where the rest of the year's DKIM2 timeline gets set. Meeting pageDMA Advanced Email Conference — London, July 7. Senior-marketer audience focused on AI, data, and customer insight in lifecycle email. Pre-event webinar July 2, in-person day six days later. Details
MoEngage acquires Aampe to put a dedicated AI agent behind every customer. Announced June 24. Aampe operates millions of per-user agents processing more than 200 billion decisions per week, in production at ZenBusiness, Taxfix, Grab, and Swiggy. Founding team — Paul Meinshausen, Schaun Wheeler, Sami Abboud — joins MoEngage to lead a new Agentic Decisioning group. The first concrete agentic-CEP transaction with a clear "per-user agent" model — Braze, Klaviyo, and Salesforce Agentforce have all been racing toward this from the roadmap side; MoEngage just got there with a checkbook. CMSWire · MoEngage blog
The 2026 Great ISP Email Retreat — emailexpert's running tally of ISPs exiting consumer email: Goo Mail (Feb 25), Sparklight's Nova1Net (Mar 3), EONI and Ptera (May 1), iPrimus suspensions the same week, Evertek (September), Quadro (November). ISPs that don't outsource to Yahoo are exiting consumer mail entirely. List hygiene on the affected domains stops being a periodic task and becomes a Q3 cleanup project. emailexpert
theMarketer acquires Conectoo from eMAG Group — Romanian CDP vendor takes over an email platform owned inside one of the region's largest e-commerce groups. Six-month integration. The story matters more as a signal than as a single transaction — large enterprise groups across Europe are increasingly divesting "owned" email platforms, and dedicated email and CDP vendors are picking up the books of business. Romania Insider
Spamhaus CERT Insight Portal — enriched botnet C&C data live. Spamhaus added protocol, country codes, ASNs, malware-family naming, and last-seen dates to the free portal for government-funded CERTs and CSIRTs on June 14. Context number worth carrying: botnet C&C activity rose 56% in 2025, and Spamhaus tracks ~1,500 active C&Cs at any given time. Geographic distribution for June: Hungary down 60%, Slovenia up 2,100%. Spamhaus
CyberCert + Suped partner on SMB1001 email auth — turnkey toolkit for MSPs serving Australian SMBs. Product story is niche; the signal that national-tier SMB cybersecurity frameworks are now mandating DMARC enforcement is the part that travels. SMB1001 Silver requires valid SPF; Gold requires SPF + DKIM + DMARC at p=quarantine or p=reject. Suped
That’s it for this week! If you have feedback to make this newsletter more useful, just hit reply!
This Week In Email — thisweekin.email
Subscribe to This Week in Email and get future issues delivered to your inbox.