← All issues

This Week In Email — June 24, 2026

Independent coverage of the full email ecosystem.

A week where Microsoft, Google, Apple, and the State of Washington all moved at once. The headliner is Microsoft's SNDS + JMRP overhaul going live — but Gmail also shipped a plain-English deliverability verdict, Apple's WWDC reshaped what an "open" means, and Washington narrowed its subject-line law in the middle of an active wave of litigation. If your week looks calm, look again.

In This Issue

Top Stories

Microsoft's SNDS + JMRP overhaul lands in production

Microsoft rebuilt both SNDS and JMRP at the same time, and the new behavior is now live. JMRP reports are fully ARF-standardized — and ship with the sender address redacted and the message body completely stripped. Any complaint-attribution workflow that was parsing the body for a customer ID, order reference, or account token has broken plumbing as of this week.

The fix is to inject stable identifiers at send time and re-key off headers: Message-ID, campaign ID, customer ID, DKIM selector, sending domain, Return-Path domain, outbound IP. While you're in there, rotate the new 30-day OAuth tokens and migrate any static-URL scrapers to the new REST API.

SNDS and JMRP are the only first-party signals Microsoft gives senders. If you don't fix this, you stop being able to trace which campaigns generate which complaints — the field that gave you that traceability is simply gone.

Sources: Spam Resource, emailexpert, Suped

Deliverability & Authentication

Gmail Postmaster Tools v2 ships a "Deliverability analysis" verdict

Google rolled out a new section under the Compliance dashboard that condenses the underlying signals into a single sentence per domain — "users want your mail" or "users don't want your mail" — plus a concrete next step. For deliverability teams, this changes both internal escalation (the verdict is finally legible to a CMO) and the playbook for what to fix first when Gmail starts drifting.

Postmaster Tools has historically been a stack of dashboards you triangulated. Now there's a verdict. Worth checking against your own domains this week.

Sources: emailexpert, DMARC Report

From DMARCbis to DMARC — the new RFC family in plain English

Al Iverson published the first practitioner-readable walkthrough of what changed when RFCs 9989, 9990, and 9991 obsoleted RFC 7489. The headline behavior changes: receivers can now walk up the DNS hierarchy rather than leaning on a static public-suffix list, the np (non-existent subdomain policy) and psd (public-suffix domain) tags are real, and pct, rf, and ri are gone.

For most senders the promotion to Proposed Standard matters less than the concrete receiver-side rollout. If you operate at scale or carry a complex domain tree — especially .edu, .gov, or anything public-suffix-adjacent — the schedule by which the big receivers adopt the new walk is the thing to watch.

Sources: Spam Resource, RFC 9989

Infrastructure & MTAs

Apple Mail at WWDC 2026 — Siri reads your message before the user does

Apple rebuilt Siri on Google Gemini and gave it system-wide read access to Mail, Messages, and Photos. Calendar now auto-extracts reservations from inbound mail; Mail's search index updates "almost immediately" and rendering is up to 80% faster on iOS 27.

For the roughly half of opens that already happen behind Apple Mail Privacy Protection, this is the next leg down on signal quality. If Siri surfaces the reservation time, discount code, or delivery window before the user opens the message, the open doesn't fire, the click doesn't fire, and the sender sees nothing.

Three things worth doing: (a) make the critical facts plain-text in the body — not in images, not buried below the fold — so the model has clean structure to extract; (b) further down-weight Apple Mail engagement in any lifecycle scoring; (c) watch the iOS 27 developer betas yourself rather than trust the early "what this means" takes.

Sources: emailexpert, TechCrunch

Security & Anti-Abuse

Microsoft June Patch Tuesday — Exchange Server + Online critical CVEs

The Exchange bundle ships seven on-prem CVEs across 2016 CU23 and 2019, plus a critical Exchange Online information-disclosure bug (CVE-2026-48579, CVSS 9.1). CVE-2026-42897 was revised and flagged "install as soon as possible," with reports of active exploitation via crafted email.

Exchange remains the single highest-stakes mail server in the on-prem world. If you're still running 2016 or 2019 — and most regulated environments are — this is a same-week patch decision.

Sources: Messageware, Petri, Qualys

Regulatory & Compliance

Washington CEMA narrows on June 11 — and three Béis class actions race the clock

Washington's HB 2274 took effect June 11. Statutory damages dropped from $500 to $100 per email, and plaintiffs now have to plead actual knowledge that the subject line was false or misleading. Days before that effective date, plaintiffs filed three CEMA class actions against luggage brand Béis over a "FRAUD ALERT" Cyber Monday subject line — and the new law is not retroactive, so those suits ride the old $500 / no-knowledge framework.

Washington has been the most plaintiff-friendly state for subject-line litigation since the April 2025 Supreme Court ruling that made misleading subject lines a per-se Consumer Protection Act violation. Three things worth doing: (a) treat Washington-resident lists with subject-line discipline going forward; (b) re-read any "RE:", "Fwd:", or fake-alert subject lines in your current calendar; (c) understand that the rules going forward are tighter for plaintiffs, but residual exposure from past sends is real.

Sources: emailexpert (CEMA narrowing), emailexpert (Béis suits), Morgan Lewis, Epstein Becker Green

Links worth your time

This Week In Email — thisweekin.email

Enjoyed this issue?

Subscribe to This Week in Email and get future issues delivered to your inbox.