In This Issue

  • EvilTokens PhaaS targets 340+ Microsoft 365 orgs

  • Bubble.io weaponized for credential phishing

  • FBI Director's Gmail hacked

  • Gulf phishing up 130%

  • Gmail AI inbox is measurably killing click rates

  • Microsoft authentication enforcement goes hard

  • NCSC Mail Check shuts down today

  • Forrester Wave full results

  • And more!

EvilTokens: Device Code Phishing-as-a-Service Hits 340+ Microsoft 365 OrganizationsA new Phishing-as-a-Service platform called EvilTokens -- sold on Telegram since February 16 -- has powered a device code phishing campaign targeting 340+ Microsoft 365 organizations across the US, Canada, Australia, New Zealand, and Germany. By March 23, researchers tracked over 1,000 domains hosting phishing pages disguised as DocuSign, OneDrive, and SharePoint documents.

What makes this particularly nasty: it abuses the legitimate Microsoft device code authentication flow, meaning the phishing page redirects to real Microsoft infrastructure. The kit provides affiliates with email harvesting tools, account reconnaissance, a built-in webmail interface, and AI-powered automation. This is the most significant new PhaaS platform to emerge in 2026, and email is the entry point for every attack chain.

Forrester Wave Q1 2026: Cordial and Zeta Named Email Marketing Leaders

Forrester published its Q1 2026 Wave for Email Marketing Service Providers, evaluating 12 vendors. Two came out on top: Cordial earned highest possible scores in 10 criteria including identity resolution, dynamic messaging, and pricing transparency (used by Levi's, L.L.Bean, Boot Barn). Zeta Global received the highest Strategy score of any vendor, with perfect 5.0 marks in 11 criteria including AI Approach, Innovation, and Roadmap.

Zeta's positioning reflects its aggressive M&A strategy — the $325M Marigold acquisition we covered previously is clearly paying dividends in the analyst community. Worth watching how this reshapes enterprise ESP selection in 2026.

Bubble.io No-Code Platform Weaponized for Microsoft Credential Phishing

Kaspersky uncovered attackers using Bubble.io, a legitimate no-code app builder, to host phishing apps that steal Microsoft 365 credentials. Because the pages live on Bubble's trusted domain (*.bubble.io), email security filters don't flag the links. The Shadow DOM and complex JavaScript bundles generated by Bubble are opaque to static analysis tools, making detection extremely difficult.

The pattern is clear: attackers are systematically moving to legitimate platforms -- OAuth flows, no-code builders -- to evade URL reputation checks. Kaspersky expects this technique to spread to PhaaS kits. Watch for *.bubble.io URLs in phishing attempts.

FBI Director Kash Patel's Personal Gmail Hacked by Iran-Linked Group

The Iran-linked Handala Hack Team breached FBI Director Kash Patel's personal Gmail account and published 300+ emails and personal photos. The leaked correspondence dates from 2010-2019, predating his role as FBI Director. Handala claimed retaliation for the FBI's seizure of several of the group's domains. The State Department has offered a $10 million reward for information identifying the group.

The sitting FBI Director's personal email getting popped is a reminder that personal email accounts remain prime targets for state-sponsored actors -- no matter how high your security clearance.

Gmail AI Inbox Is Measurably Killing Click Rate

The first hard data is in. Omeda's analysis of billions of emails quantifies what Gmail's Gemini-powered AI features are doing to email metrics:

  • Click-through rates dropped from 4.35% to 3.93% -- users get what they need from AI summaries without clicking

  • Newsletter CTR fell from 7.68% to 6.78%

  • Open rates are artificially inflated -- Gmail's AI auto-opens emails to generate summaries

That's roughly a 10% relative decline in clicks, and the open rate inflation masks the actual engagement drop. This is the most consequential change to email metrics since Apple's Mail Privacy Protection.

Gulf Countries See 130% Phishing Surge After Middle East War Escalation

Bitdefender Antispam Labs detected a sustained 130% average increase in phishing and malware campaigns targeting Gulf countries following the escalation of conflict involving Israel, the US, and Iran. Peak activity reached nearly 4x pre-war levels. The turning point was February 28, with malicious email volumes doubling within days and remaining elevated. Campaigns use business-themed lures -- invoices, contracts, banking, deliveries -- deploying Java-based RATs and fileless PowerShell chains. Palo Alto's Unit 42 corroborates the findings.

Geopolitical events translate directly into email threat spikes. Organizations with Middle East operations or partners should be on heightened alert.

Security & Anti-Abuse

PXA Stealer Surges Against Financial Institutions, Filling Post-Lumma Vacuum

CyberProof MDR researchers (presented at RSAC 2026) identified an 8-10% increase in PXA Stealer activity targeting global financial institutions during Q1 2026. PXA has filled the gap left by 2025 takedowns of Lumma, Rhadamanthys, and RedLine. Campaigns use phishing emails with malicious URLs triggering ZIP downloads -- lures include CVs, Adobe installers, tax forms, and legal documents. Email remains the primary delivery vector for infostealers, and the whack-a-mole continues.

Russian National Sentenced for BitPaymer Ransomware Phishing Botnet

A Russian national was sentenced to two years in prison after admitting the phishing botnet he managed launched BitPaymer ransomware attacks against 72 U.S. companies. Rare accountability for phishing-enabled ransomware operations.

Deliverability & Authentication

Microsoft Outlook Authentication Enforcement Now Returning Hard Rejections

Microsoft's high-volume sender requirements for Outlook.com are actively enforcing. Domains sending 5,000+ emails/day to Outlook.com must comply with SPF, DKIM, and DMARC (at least p=none). Non-compliant mail now returns 550 5.7.515 Access denied -- permanent rejection, not spam folder placement. Additional requirements include valid From/Reply-To addresses, functional unsubscribe links, and regular list hygiene.

Microsoft has moved from warnings to hard bounces. If you're a high-volume sender and haven't gotten compliant, you're already seeing delivery failures to Outlook/Hotmail/Live.com. This aligns Microsoft with Google and Yahoo's existing enforcement posture.

Microsoft SMTP AUTH Basic Auth Timeline Revised Again

Microsoft has again revised its SMTP AUTH Basic Authentication deprecation timeline:

  • Now through December 2026: SMTP AUTH Basic Auth behavior unchanged

  • End of December 2026: Basic Auth disabled by default for existing tenants (admins can re-enable)

  • New tenants after December 2026: Basic Auth unavailable, OAuth required

  • H2 2027: Final removal date TBA

This is a significant extension from the previously announced September 2025 and then March/April 2026 deadlines. The repeated postponement signals that migration is harder than Microsoft expected. The end is still coming -- prioritize OAuth migration.

Spamhaus Oracle DNS Blocklist Deadline: 8 Days Away

Deadline: April 8. Users of Spamhaus's free DNS Blocklists running on Oracle's network must transition to the free Data Query Service (DQS) before April 8. Starting April 9, Spamhaus will return error code 127.255.255.254 across Oracle's IP space. If your mail servers aren't configured to handle this code, all email could be rejected. The fix is free but requires config changes.

Validity Proposes Three New Email Metrics for the AI Era

Validity's Guy Hanson published a MarTech piece proposing three metrics to replace traditional opens and clicks:

  1. Disaffection Index -- combines unsubscribes, complaints, and bounces into a single metric measuring how fast you're burning through your audience

  2. Reply Rates -- replies require intent and indicate genuine engagement

  3. Trust Scores -- measuring subscriber trust through preference center engagement and explicit consent actions

The Disaffection Index is the most useful concept here: a campaign with decent click rates can still wreck your deliverability if it generates enough complaints or unsubscribes. As Hanson puts it, "The focus is shifting from simply reaching the inbox to proving you belong there."

Infrastructure & MTAs

Microsoft Outlook Deliverability Crisis Persists

The Outlook deliverability issues reported in previous editions continued through March with no resolution. Administrators from small ISPs to public libraries and healthcare organizations report outbound messages rejected with 550 errors and vague "temporary rate-limited" notices. Microsoft's internal reputation engine appears to be mistakenly flagging clean IPs as spam sources. Many senders receive automated "no issue detected" replies while delivery remains blocked. E-commerce platforms have reported 48-hour order confirmation delays.

Separately, Microsoft cancelled plans to impose bulk email rate limits on Exchange Online, backing off from a previously announced policy. The combination of false-positive blocking, inadequate support, and cancelled rate-limiting plans signals significant internal confusion about email policy.

Halon Drops Two Releases: Flow Dynamics and Gateway PGP Encryption

Halon shipped two updates this week. Engage 26.1 (March 26) introduces Flow Dynamics, a new Delivery Guru feature for smarter delivery optimization. Protect 26.1 (March 31) strengthens gateway-enforced email encryption with PGP and enhanced S/MIME support. Two solid infrastructure releases in one week from the Swedish MTA vendor.

Platforms & Marketing

Forrester Wave EMSP Q1 2026 -- Full Results

Full results from the Forrester Wave EMSP Q1 2026, evaluating 12 vendors across 26 criteria:

  • Leaders: Adobe, Cordial, Zeta Global

  • Strong Performers: Braze (top scores in dynamic messaging and responsible AI), Iterable, Klaviyo (first-time participant), Netcore Cloud

  • Also evaluated: Bloomreach, Bluecore, Cheetah Digital, Salesforce, SAP

Adobe's Leader position and Klaviyo's debut as a Strong Performer are the key new data points. Forrester's theme across the board: "competitive pressure, combined with the revolutionary power of AI, is pushing the limits of what the email medium can do."

Validity Launches Engage -- AI Email Platform with Four Specialized Agents

Validity launched Engage, an AI email platform debuted at Litmus Live 2026, featuring specialized agents: Ignite (flags rendering, code, and compliance risks pre-send), Guardian (monitors subscriber experience and deliverability), and Expression (generates on-brand copy and variants). Trained on Validity's data network processing 2.5 billion data points daily.

The move into "AI agents" for email operations mirrors the agentic theme from RSAC. The unlimited pricing model -- no seat caps or usage-based restrictions -- is noteworthy as a market signal.

AI & Email

Forrester: AI Is Driving an "Email Functionality Leap"

Forrester's companion blog to the Wave report argues AI is driving a genuine functionality leap in email platforms -- not just incremental improvements. Conversational interfaces and proactive automation are now table stakes. Klaviyo's K:AI Marketing Agent builds entire email sequences autonomously. HubSpot's Breeze Agents resolve support tickets via email without human intervention. The shift is from AI-assisted to AI-autonomous email operations. The "agentic" theme from RSAC security vendors last week is now confirmed across the marketing platform side too.

Gmail AI: Front-Load Value or Get Summarized Away

Practical guidance is emerging for adapting to Gmail's AI features: front-load key information in the first 100-200 characters (AI summaries pull from there), use direct subject lines and clear structure, and eliminate filler. Gmail's AI prioritizes concrete, actionable information over emotional language or marketing fluff. The good news: AI-optimized email is just good email. The bad news: mediocre email will perform even worse as summarization reduces the need to click.

Regulatory & Compliance

NCSC Mail Check and Web Check Shut Down Today

The UK's National Cyber Security Centre officially retires its Mail Check and Web Check services today, March 31, 2026, after 8 years of operation. Mail Check provided free email security compliance assessment covering SPF, DMARC, TLS, and MTA-STS. The NCSC recommends organizations transition to commercial External Attack Surface Management (EASM) products. Multiple vendors (Valimail, dmarcian, Sendmarc, Red Sift) have offered migration paths.

Any UK public-sector organization that hasn't migrated is now flying blind on email authentication compliance. The NCSC's exit validates the maturity of the commercial market but leaves a gap for smaller organizations that relied on the free service.

Events & Community

  • Deliverability Summit -- Barcelona, April 20-22 (SOLD OUT). La Pedrera. No vendor pitches; standards-aligned, evidence-first sessions. Main stage streamed online April 15 - May 2. Only remaining access: Festival of Email Bundle pass. deliverabilitysummit.com

  • Festival of Email / Sender Symposium -- Barcelona, April 19-25. Full week of email events. Sender Symposium (marketer/CRM-focused) April 24. festivalofemail.com

  • Unspam 2026 -- Long Beach CA, April 20-22. Really Good Emails + Beefree. Under 250 attendees, unconference format. unspam

  • Word to the Wise Gmail/Inbox Signals Webinar -- Early April 2026. Free. Covers authentication, sender reputation, BIMI, and a 90-day deliverability improvement plan. wordtothewise.com

  • M3AAWG 67th General Meeting -- Montreal, June 8-11. CFPs open. m3aawg.org

What to Watch

  • Spamhaus + Oracle: April 8-9 -- Error code rollout begins April 9. Transition to free DQS now or risk all email being rejected. Spamhaus

  • NCSC Mail Check: Shut down today (March 31) -- UK public sector must now use commercial alternatives. NCSC

  • Mautic fundraiser: End of March -- $50K budget shortfall, targeting $40K minimum. Outcome pending. Mautic

  • Yahoo Mail storage cuts: May 5 -- 15-20GB limits for free users. Block after August 27 for those over limit. Expect increased bounces from Yahoo domains.

  • Microsoft SMTP AUTH Basic Auth: December 2026 -- Disabled by default for existing tenants. Final removal H2 2027. Microsoft

  • Proofpoint unified SEG+API launch: June 30 -- Major email security architecture change.

  • EU AI Act Article 50 transparency: August 2 -- Disclosure requirements for AI-generated email content to EU recipients.

  • Gmail AI Inbox rollout -- Continues toward general availability. Monitor metrics impact.

  • iOS 26 Link Tracking Protection -- Apple Mail stripping gclid/fbclid/dclid from clicks. UTM params safe.

  • Middle East cyber escalation -- Phishing volumes up 130%+ in Gulf region. Monitor for spread.

As always, I’d love to get your feedback! How can I make this newsletter better? Hit “reply” and tell me! Better yet, hit “forward” and send this to someone you know in the email community! (And if you received this via a forward from someone else, please subscribe at https://thisweekin.email!)

Also, would your company be interested in sponsoring this newsletter? Hit reply and let’s talk!

Until next week,

John

Keep Reading