Two stories this week distill the limits of email security into headlines you can hand to a CMO. Blesta's billing platform sent a ransom email through its own authenticated mail path — SPF, DKIM, and DMARC all passed. Kaspersky published research the same week documenting phishers harvesting AWS SES IAM keys out of leaky GitHub repos and inheriting their victims' sending reputation for free. Authentication confirms the route. It never confirmed the intent.
Meanwhile France's CNIL tracking-pixel deadline is two weeks out, the IETF DKIM working group dropped its second material document in six days, and an agentic-AI acquisition is starting to reshape what a customer engagement platform looks like underneath. Heavy week. Let's get into it.
In This Issue
Blesta ransom email passed SPF, DKIM, and DMARC — what authenticated abuse actually looks like in a 48-hour news cycle
CNIL tracking-pixel deadline: July 14, 2026 — two weeks out, transitional regime evaporates after
Phishers aren't building infrastructure. They're borrowing yours. — Kaspersky on the AWS SES IAM-key economy
DKIM2 advances to draft-03 — and a BCP-00 — two material WG documents in six days
Events & Community — IETF 126 DKIM session July 21, DMA Advanced Email Conference London July 7
Links worth your time — MoEngage / Aampe, the 2026 Great ISP Email Retreat, theMarketer / Conectoo, Spamhaus CERT, SMB1001:2026
Top Stories
Blesta ransom email passed SPF, DKIM, and DMARC
Category: Security & Anti-Abuse
On June 26, customers of Blesta — the billing platform widely deployed by hosting providers — received a "Blesta Compromised" ransom email from [email protected]. The message threatened to leak the customer database the next day. The attackers had compromised a temp support account originally created for a third-party virtualization vendor, then used it to drive Blesta's own customer portal. The ransom mail went out through Blesta's real outbound infrastructure on Mailgun.
SPF passed. DKIM passed. DMARC passed against Blesta's own p=reject policy. Every authentication signal a receiver could check confirmed the message was routed through the legitimate sender's infrastructure — because it was. DMARC confirms the route the mail took. It was never designed to confirm the intent of the message moving along that route.
This is the cleanest example of "authenticated abuse" we've seen in months, and it pairs with the Xero, Atlassian Jira, and AWS SES patterns we covered earlier this year. The through-line is consistent: in 2026, with spoofing largely closed off by DMARC enforcement at the major receivers, the dominant residual phishing pattern is attackers operating mail from inside a legitimate sender's authenticated infrastructure. If your detection stack still treats SPF/DKIM/DMARC pass as a strong safety signal, this is the case study to take to your security team this week. The signal it carries is "the route is real." Nothing more.
Sources: Suped, DMARC Report, LowEndBox
CNIL email tracking-pixel deadline: July 14, 2026
Category: Regulatory & Compliance
France's CNIL published its email tracking-pixel recommendation on April 14, with a 90-day transitional window. That window closes July 14 — two weeks from today. The clock is real.
The compliance shape: any pixel collecting marketing-measurement data (open, time-on-message, render context) is now treated like a tracker under the ePrivacy Directive. For contacts collected before April 14, senders have until July 14 to send a notification email explaining pixel use and offering an opt-out. Miss the window and the transitional regime evaporates — re-collecting explicit pixel consent across the entire pre-April-14 contact base becomes the only legal path forward. Italy's Garante is on the same arc, with the six-month Italian window ending October 28. Lewis Silkin's comparative analysis published June 23 lays the two regimes side by side.
The carve-out worth knowing: pixels used purely for deliverability hygiene — suppressing chronic inactives, throttling cadence to disengaged segments — are not treated as marketing-measurement and don't require consent. Anything used to feed engagement scoring, journey orchestration, or campaign analytics does. Most ESP integrations don't separate the two cleanly at the pixel level. That engineering work is the part senders keep underestimating.
CNIL enforcement — formal notices, investigations, sanctions — is expected to begin immediately after July 14. If your EU contact base predates April 14 and you haven't sent the notification email yet, this is what you should be doing this week. Not next week.
Phishers aren't building infrastructure. They're borrowing yours.
Category: Security & Anti-Abuse
Kaspersky's Securelist research, picked up by emailexpert this week, documents a sharp rise in phishing campaigns sent through Amazon SES — not by exploiting any flaw in SES itself, but by harvesting AWS IAM access keys leaked in GitHub repos, .env files, Docker image layers, public S3 buckets, and similar developer mistakes.
The mechanics are mundane and that's the problem. Attackers scan with TruffleHog and equivalent tools, check each leaked key for SES sending permissions, and inherit the legitimate AWS customer's full reputation the moment they find one. No domain registration. No warmup. No infrastructure to build. SPF, DKIM, and DMARC all pass because the mail is genuinely originating from the victim's authenticated sending domain. The dominant campaigns are fake DocuSign-style document-signing notifications and BEC plays — fabricated email threads and forged invoices aimed at finance teams.
The architecture lesson generalizes well beyond SES. Sender reputation in 2026 is inherited by whoever holds the credentials, not by whoever earned them. That applies to every shared ESP — API key in a leaked repo, OAuth refresh token in a stale backup, service-account credential baked into a Docker image — and to every SaaS-mail integration that ships a long-lived secret. Rotate, scope, and monitor. If your SES setup still uses long-lived IAM users instead of role-assumption with short tokens, that is the week-one fix.
Sources: Kaspersky Securelist, emailexpert, TechRadar
Deliverability & Authentication
DKIM2 advances to draft-03 — and the first BCP draft
The IETF DKIM working group landed two material documents in six days. On June 18 the WG published the first DKIM2 Best Current Practices draft (draft-ietf-dkim-dkim2-bcp-00). On June 24 the main spec advanced to draft-ietf-dkim-dkim2-spec-03. Two thirds of a year before the Q4 2026 mailbox-provider experimental-rollout target, the working group's tempo is picking up — not slipping.
The headline changes in spec-03. A new nd= tag has been introduced as an alternative mechanism to the existing mf= and rt= tags for handling imaginary hops between domains — the construct that always made forwarding scenarios under DKIM2 their own engineering problem. A new feedhere flag has been added to support privacy-conscious forwarding scenarios. The list of header fields ignored during signing has been promoted into its own dedicated section, with the experimental Delivered-To: header added to it. The rules for DSN propagation have been tightened so a DSN always carries the message headers up to the point where the DSN creator saw the message on its outward journey. Null recipes for header field modifications have been eliminated.
None of that is procedural cleanup. The forwarding-edge cases that always blow up real DKIM deployments — your delegated-domain replays, your Listserv hops, your security-vendor inline rewrites — are exactly the surface area this revision touches.
IETF 126 in Vienna kicks off July 18. The DKIM session Tuesday July 21 is where spec-04 direction gets set and the Q4 experimental-rollout target either holds or starts slipping. Watch that session.
Events & Community
IETF 126 DKIM working group session — Tuesday July 21, 14:00–16:00 Europe/Vienna, Park Suite 6. With spec-03 fresh and the BCP-00 draft only six days older, this is the session where the rest of the year's DKIM2 timeline gets set. Meeting page
DMA Advanced Email Conference — London, July 7. Senior-marketer audience focused on AI, data, and customer insight in lifecycle email. Pre-event webinar July 2, in-person day six days later. Details
Links worth your time
MoEngage acquires Aampe to put a dedicated AI agent behind every customer. Announced June 24. Aampe operates millions of per-user agents processing more than 200 billion decisions per week, in production at ZenBusiness, Taxfix, Grab, and Swiggy. Founding team — Paul Meinshausen, Schaun Wheeler, Sami Abboud — joins MoEngage to lead a new Agentic Decisioning group. The first concrete agentic-CEP transaction with a clear "per-user agent" model — Braze, Klaviyo, and Salesforce Agentforce have all been racing toward this from the roadmap side; MoEngage just got there with a checkbook. CMSWire · MoEngage blog
The 2026 Great ISP Email Retreat — emailexpert's running tally of ISPs exiting consumer email: Goo Mail (Feb 25), Sparklight's Nova1Net (Mar 3), EONI and Ptera (May 1), iPrimus suspensions the same week, Evertek (September), Quadro (November). ISPs that don't outsource to Yahoo are exiting consumer mail entirely. List hygiene on the affected domains stops being a periodic task and becomes a Q3 cleanup project. emailexpert
theMarketer acquires Conectoo from eMAG Group — Romanian CDP vendor takes over an email platform owned inside one of the region's largest e-commerce groups. Six-month integration. The story matters more as a signal than as a single transaction — large enterprise groups across Europe are increasingly divesting "owned" email platforms, and dedicated email and CDP vendors are picking up the books of business. Romania Insider
Spamhaus CERT Insight Portal — enriched botnet C&C data live. Spamhaus added protocol, country codes, ASNs, malware-family naming, and last-seen dates to the free portal for government-funded CERTs and CSIRTs on June 14. Context number worth carrying: botnet C&C activity rose 56% in 2025, and Spamhaus tracks ~1,500 active C&Cs at any given time. Geographic distribution for June: Hungary down 60%, Slovenia up 2,100%. Spamhaus
CyberCert + Suped partner on SMB1001:2026 email auth — turnkey toolkit for MSPs serving Australian SMBs. Product story is niche; the signal that national-tier SMB cybersecurity frameworks are now mandating DMARC enforcement is the part that travels. SMB1001 Silver requires valid SPF; Gold requires SPF + DKIM + DMARC at
p=quarantineorp=reject. Suped
That’s it for this week! If you have feedback to make this newsletter more useful, just hit reply!
This Week In Email — thisweekin.email

