← All issues

This Week in Email: June 10, 2026

Independent coverage of the full email ecosystem.

M3AAWG is live in Montreal this week; Washington's email subject-line law gets a statutory rewrite that takes effect Thursday; and Leboncoin published a detailed engineering post-mortem on moving 12 million daily transactional emails to a new MTA. Heavy week. Let's get into it.

In This Issue

Top Stories

Washington CEMA: The Email Subject-Line Law Just Got Rewritten

Washington's Commercial Electronic Mail Act has been a quiet source of litigation risk for years — a state law with $500-per-email statutory damages for subject lines deemed false or misleading. That changes Thursday. HB2274, signed March 23 and effective June 11, 2026, rewrites the standard in two ways: damages drop from $500 to $100 per email, and the law now requires "actual knowledge" that a subject line is false or misleading. Under the old standard, objective misleadingness was enough; under the new one, a plaintiff needs to show the sender knew or had objective reason to know.

That's a materially higher bar for litigation. For marketing operations teams with any Washington state exposure, this is statutory language worth putting in the legal review process — both the change and the fact that the $500 regime still governs anything commenced before June 11.

Source: Lexology / Seyfarth Shaw

Microsoft Q1 2026: 8.3 Billion Phishing Threats, QR Code Attacks Nearly Doubled

Microsoft's Defender Research team published their Q1 2026 email threat landscape on April 30, and the numbers tell a clear story. 8.3 billion email-based phishing threats in 90 days. QR code phishing grew 146% from January to March, with 70% of those attacks embedded in PDF attachments by the end of the quarter — specifically to route around URL-scanning defenses. CAPTCHA-gated phishing hit 11.9 million attacks in March alone, a 125% increase from January. Credential phishing tightened its grip: 89% to 95% of all payload-based attacks over the quarter.

The through-line: attackers are systematically routing around automated detection. QR codes and CAPTCHAs both work because they interrupt the scanning chain that defenders built for link-based threats. If your email security posture is tuned for URL-based credential phishing, the threat has already moved. Microsoft also flagged 10.7 million BEC attacks in Q1 — 82–84% were generic outreach messages, not sophisticated executive impersonation. The bar to run a BEC campaign is not high.

Source: Microsoft Security Blog

Infrastructure & MTAs

Leboncoin's 12M-Email/Day Migration: Why PowerMTA Won Over KumoMTA

Leboncoin — large French classifieds platform — published a detailed engineering post-mortem this month on migrating 12 million daily transactional emails from Postfix to PowerMTA. Postfix got them here, but per-provider delivery tuning was manual, IP reputation management across a Postfix cluster was untenable, and they needed AWS BYOIP support with per-IP scheduling that Postfix doesn't provide natively.

They evaluated both KumoMTA and PowerMTA; they chose PowerMTA for its Virtual MTA architecture — specifically the ability to associate multiple public IPs with a single EC2 instance and tune delivery behavior by destination domain, provider, and IP. The write-up covers IP warm-up sequencing, observability reconstruction, and the things that broke during cutover. Worth your time if you're managing transactional infra at scale.

Source: Leboncoin Tech Blog / Medium

Events & Community

Links worth your time

If you’re attending M3AAWG this week, be sure to say hi!

This Week In Email — thisweekin.email

Enjoyed this issue?

Subscribe to This Week in Email and get future issues delivered to your inbox.