In This Issue
FEATURED: France requires double consent for email tracking pixels
FBI IC3 Report: $20.9B in cybercrime, BEC at $3B
Apple Business launches — Apple enters B2B email
GitHub & Jira notifications weaponized for phishing
Mailgun report: 18% of emails miss the inbox
Deliverability: Outlook deadline, Spamhaus, Cloudflare DMARC stats
Security: Payroll Pirates, precision phishing, Booking.com breach
Infrastructure: Postmark migrates to KumoMTA, MTA Buyer's Guide
Platforms: Mailjet MCP Server, Amazon WorkMail wind-down
AI & Email: Gmail deprioritizing 40% of inbox, agentic AI shift
Regulatory: EU AI Act, Yahoo storage cuts, Bitsight DMARC ratings
The CNIL just published final rules requiring separate consent for email tracking pixels — the most consequential regulatory move for open-rate tracking since Apple MPP. The FBI's annual cybercrime report crossed $20.9 billion for the first time, with BEC still the second-costliest category. Apple launched its business email platform today. Cisco Talos found attackers weaponizing GitHub and Jira notification emails to bypass every gateway on the market. And Microsoft's authentication enforcement deadline is two weeks out.
Heavy week. Let's get into it.
FEATURED: France Now Requires Double Consent for Email Tracking Pixels
Category: Regulatory
The CNIL — France's data protection authority — today published its final recommendation on tracking pixels in email, and it is a significant shift. Tracking pixels are now classified as equivalent to cookies under French law, meaning a single "I agree to receive marketing emails" checkbox no longer covers open-rate tracking. Organizations must obtain two independent consents: one for the marketing email itself, and a separate, specific consent for the tracking pixel.
There's a technically demanding wrinkle: when recipients withdraw consent, the change must take effect at the pixel server level immediately — including for pixels in emails already sitting in their inbox. That means real-time consent verification at pixel load time. Transactional emails and truly anonymous aggregate tracking (identical pixel, no per-recipient identifiers) are exempt. Existing senders have a 3-month transition window, roughly until July 14.
This is arguably the most important regulatory development for email open-rate tracking since Apple's Mail Privacy Protection in 2021. Between MPP, Gmail AI auto-opens, and now CNIL's double consent — open rate as a metric is getting squeezed from every direction. If your measurement strategy still leans heavily on opens, the time to shift toward clicks, conversions, and replies was yesterday.
Sources: CNIL Official | ChapsVision Analysis | Didomi Analysis | Badsender
FBI IC3 Report: $20.9B in Cybercrime Losses, BEC Still at $3B
Category: Security
The FBI's 2025 Internet Crime Report hit landmark numbers: over 1 million complaints for the first time, $20.88 billion in losses (up 26% from 2024). Business Email Compromise remained the second-costliest category at $3.05 billion across nearly 25,000 complaints. For the first time, the report breaks out AI-enabled fraud as a distinct category — 22,000+ complaints with $893 million in losses. BEC schemes with a confirmed AI component accounted for over $30 million alone.
Email remains the primary initial access vector across nearly every crime category the FBI tracks. The AI-enabled fraud number is almost certainly an undercount — detection attribution is still immature — but the fact that the FBI now categorizes it separately tells you where the threat landscape is heading.
Sources: IC3 Report (PDF) | The Register | SecureWorld
Apple Business Launches — Apple Enters B2B Email
Category: Platforms
Apple Business went live this week in 200+ countries. The free platform includes business email, calendar, and directory services on custom domains for up to 500 users. It replaces Apple Business Essentials, Apple Business Manager, and Apple Business Connect — all discontinued. This is Apple's first direct play in business email hosting, putting them in competition with Google Workspace and Microsoft 365.
The catch: the email/calendar/directory features require iOS 26, iPadOS 26, or macOS 26. That's a meaningful ecosystem lock-in. If your organization runs mixed-OS or has devices that can't jump to the latest version, this isn't an option. For small Apple-native shops, though, a free business email suite with tight device integration is a compelling proposition. Worth watching how this affects the SMB email hosting landscape.
Sources: Apple Newsroom | TechSpot | PPC Land
GitHub & Jira Notifications Weaponized for Phishing
Category: Security
Cisco Talos published research showing attackers embedding phishing links inside SaaS notification emails from GitHub and Jira. The emails pass SPF, DKIM, and DMARC because the platforms themselves send them. On GitHub, attackers drop malicious links into issue and PR descriptions that flow into notification emails. On Jira, they abuse the "Invite Customers" feature to inject phishing into Atlassian's own email templates. On peak days, roughly 2.89% of all GitHub emails were abuse-related.
This is a hard problem because there's nothing wrong with the emails at the authentication level. The sender infrastructure is legitimate. The message templates are legitimate. The content is the only signal — and it's user-generated content flowing through trusted pipes. Gateway-level defenses that rely on sender reputation and authentication status are essentially blind to this vector.
Sources: Cisco Talos | Help Net Security | GBHackers
Mailgun Report: 18% of Emails Miss the Inbox
Category: Deliverability
Sinch Mailgun's 2026 Email Impact Report, based on 400 billion+ emails and 1,200+ senders across 5 countries, puts a hard number on the inbox placement gap: nearly 18% of all emails fail to reach the inbox. And only 46% of organizations can actually measure their promotional email ROI — though among those who can, 60% report $10+ return per dollar spent.
The disconnect is striking: 78% say email is critical to their business, but fewer than half can prove it. The report also flags that AI adoption in email is still mostly limited to content generation — the teams applying AI to deliverability optimization, segmentation, and send-time decisions are seeing meaningfully better results, but they're in the minority.
Sources: Mailgun Report | MarTech | Telecom Reseller
Deliverability & Authentication
Microsoft Outlook Authentication: 14 Days Until Enforcement
Two weeks until the April 30 deadline. After that date, high-volume senders (5,000+ emails/day) to Outlook, Hotmail, and Microsoft 365 without SPF/DKIM/DMARC alignment will see emails junked or rejected. Compliance failures now include missing PTR records, lack of TLS, high complaint rates, and missing one-click unsubscribe. This completes the trifecta — Google (2024), Yahoo (2024), and now Microsoft all enforce strict authentication.
Sources: Microsoft Tech Community | Redsift Guide
Also Noteworthy
Spamhaus Oracle DNS deadline has passed — Since April 9, queries from Oracle IP space return error codes instead of real blocklist data. If you haven't migrated to DQS, you may be silently blocking all inbound email. Check your setup now. Spamhaus
Cloudflare: 46% of emails fail DMARC — Their 2026 Threat Report analyzed 450M emails. 43% failed SPF, 44% lacked valid DKIM. Only 10.7% of domains globally have strict DMARC reject at 100%. 70.9% have no effective DMARC protection at all. Cloudflare
Security & Anti-Abuse
Storm-2755 "Payroll Pirates": SEO Poisoning Steals Salaries
Microsoft disclosed a campaign targeting Canadian workers via poisoned search results for "Office 365." Victims click top results that lead to adversary-in-the-middle credential harvesting pages. Once inside, the attackers change direct deposit details to redirect salary payments to accounts they control. Not industry-specific — pure geographic targeting. The payroll fraud vector is growing fast alongside generative AI that helps attackers identify payroll managers and craft impersonation messages.
Sources: Microsoft Security Blog | Help Net Security
Five Precision-Targeted Phishing Attacks That "Already Knew Your Name"
IRONSCALES highlighted five attacks showing the shift from volume to precision: a zero-click PDF that auto-launched a credential harvest, a QR code phishing PDF with the target's email pre-encoded in base64, phishing kit assets hosted on a commercial phishing simulation vendor's S3 bucket, a Google Drive share notification used for law firm impersonation (passed SPF/DKIM/DMARC because Google sent it), and an invoice thread typosquat with a one-letter domain difference. Every attack was built for a specific person before it was sent.
Sources: IRONSCALES | Security Boulevard
Also Noteworthy
Booking.com confirms data breach — Hackers accessed customer data including emails, phone numbers, and booking details. Phishing messages using accurate booking details are already circulating. Reservation PINs reset. TechCrunch
Crunchyroll breach: 1.2M+ email addresses — Sony's anime platform disclosed a third-party credential compromise exposing 8M support records. 1.2M unique emails added to Have I Been Pwned. CyberInsider
Hallmark breach: 1.7M emails leaked — ShinyHunters leaked 9.59 GB via Salesforce compromise. 82% of exposed emails were already in HIBP from previous breaches. Third-party platform risk in action. CyberInsider
Proton: 67% of US state legislators' emails in dark web breaches — 3,568 of 5,312 official emails exposed, 750 with passwords. Every legislator in Arizona and Oklahoma appeared. 20% of congressional staffers also affected. Proton
Barracuda: 127% YoY increase in identity-based attacks targeting Google Workspace. Attackers exploiting compromised accounts and trusted relationships. Barracuda
Infrastructure & MTAs
Postmark Completes Migration to KumoMTA
Every email Postmark sends now runs through KumoMTA, the open-source Rust-based MTA. The key driver: PowerMTA's proprietary limitations and aging hardware made real-time traffic shaping difficult at scale. The performance numbers are notable — Gmail queue times dropped from ~2s to ~1.2s, Yahoo from ~4.6s to ~3.2s, Microsoft from ~4.8s to ~2.8s. Bounce rates held stable. Another major sender choosing open-source over proprietary is a meaningful signal for the commercial MTA market.
Sources: Postmark Blog | KumoMTA
Also Noteworthy
KumoMTA publishes 2026 MTA Buyer's Guide — Downloadable guide covering open-source vs. commercial trade-offs (KumoMTA, Postfix, PowerMTA, Halon, Momentum). Well-timed given the Postmark migration. KumoMTA
Platforms & Marketing
Mailjet Open-Sources MCP Server for AI-to-Email Integration
Mailjet (Sinch) released an open-source MCP (Model Context Protocol) Server — a bridge that lets AI tools like Claude connect directly to Mailjet's API for contact management, campaigns, segmentation, and analytics. Built on Anthropic's open MCP standard. Read-only by default. This is one of the first ESPs to ship native MCP integration, and it signals a broader trend: ESPs building AI-native interfaces beyond "generate a subject line for me."
Sources: Mailjet Blog | GitHub
Also Noteworthy
Amazon WorkMail stops accepting new customers April 30 — Full shutdown (web client, APIs, IMAP/SMTP) on March 31, 2027. Existing customers should be actively planning migration. AWS
AI & Email
Gmail AI Filtering: Up to 40% of Inbox Emails Deprioritized
Folderly's analysis introduces "effective inbox placement" as a metric — and the numbers are alarming: up to 40% of emails that technically reach the Gmail inbox are being deprioritized by AI filtering. Not blocked. Not bounced. Just quietly buried. Gmail's Gemini-powered AI is evaluating content quality, structure, and value density as direct delivery signals. AI auto-opens for summarization are also inflating open rate metrics even further.
The recommendations: front-load key information in the first 100-200 characters, use clear structure, eliminate filler, deliver obvious value immediately. In other words, write emails worth reading. The AI is optimizing for the reader — and if your email doesn't hold up to that standard, it'll get deprioritized whether it "delivered" or not.
Also Noteworthy
Agentic AI shift in email platforms — The industry is moving beyond "AI writes your subject line" to autonomous agents that monitor list health, A/B test their own drafts, and pivot sequences in real time. Kit and ActiveCampaign are leading. Click-through rates for AI-driven campaigns average 13.44% vs 3% for non-AI. The gap is widening. Email Marketing News
Regulatory & Compliance
EU AI Act: August 2 deadline approaching — Transparency obligations (Article 50) become enforceable: AI interactions must be disclosed, synthetic content labeled, deepfakes identified. AI-generated email content may require disclosure. AI-driven segmentation may face high-risk classification. Penalties: up to EUR 35M or 7% of worldwide turnover. Legal Nodes
Yahoo Mail storage cuts continuing — UK/EU accounts drop from 1TB to 15GB, North America to 20GB. After August 27, accounts over the limit can't send or receive email. Expect increased hard bounces from Yahoo addresses, especially UK/EU subscribers. emailexpert
Bitsight adds DMARC to security ratings — 1% weight, preview April 16, go-live July 16. To get a "GOOD" grade:
p=rejectorp=quarantineatpct=100. DMARC enforcement just went from "nice to have" to "affects your vendor risk score" for Bitsight customers. Bitsight
Events & Community
Next Week
Unspam 2026 — Long Beach, CA (Apr 20-22). Small practitioner conference (<250 attendees). AI, accessibility, deliverability. reallygoodemails.com
Deliverability Summit 2026 — La Pedrera, Barcelona (Apr 20-22). SOLD OUT. Practitioner-led, no vendor pitches. deliverabilitysummit.com
Sender Symposium Barcelona — Apr 24. Hosted by emailexpert. emailexpert.com
Coming Up
Inbox Expo 2026 — Atlanta (May 26-28). inboxexpo.com
M3AAWG 67th General Meeting — Montreal (Jun 8-11). m3aawg.org
What to Watch
Apr 16: Bitsight DMARC ratings algorithm preview goes live
Apr 20-22: Unspam (Long Beach) + Deliverability Summit (Barcelona)
Apr 24: Sender Symposium Barcelona
Apr 30: Microsoft Outlook authentication full enforcement
Apr 30: Amazon WorkMail stops accepting new customers
May 5: Yahoo Mail storage cuts take effect (North America)
Jun 8-11: M3AAWG 67th General Meeting, Montreal
Jun 11: Washington CEMA amendment takes effect ($500 to $100 per violation)
Jul 14: CNIL tracking pixel consent transition period ends
Jul 16: Bitsight DMARC ratings algorithm go-live
Aug 2: EU AI Act transparency and high-risk rules enforcement
Aug 27: Yahoo Mail storage hard enforcement (accounts frozen)
Mar 31, 2027: Amazon WorkMail full shutdown
I’ll be at Twilio Signal May 6-7. If you’re going to be there as well, let’s connect and talk email! As always, I’d love to get your feedback! How can I make this newsletter better? Hit “reply” and tell me! Better yet, hit “forward” and send this to someone you know in the email community! (And if you received this via a forward from someone else, please subscribe at https://thisweekin.email!) See you next week! — John |

