Two stories this week distill the limits of email security into headlines you can hand to a CMO. Blesta's billing platform sent a ransom email through its own authenticated mail path — SPF, DKIM, and DMARC all passed. Kaspersky published research the same week documenting phishers harvesting AWS SES IAM keys out of leaky GitHub repos and inheriting their victims' sending reputation for free. Authentication confirms the route. It never confirmed the intent.

Meanwhile France's CNIL tracking-pixel deadline is two weeks out, the IETF DKIM working group dropped its second material document in six days, and an agentic-AI acquisition is starting to reshape what a customer engagement platform looks like underneath. Heavy week. Let's get into it.

In This Issue

  • Blesta ransom email passed SPF, DKIM, and DMARC — what authenticated abuse actually looks like in a 48-hour news cycle

  • CNIL tracking-pixel deadline: July 14, 2026 — two weeks out, transitional regime evaporates after

  • Phishers aren't building infrastructure. They're borrowing yours. — Kaspersky on the AWS SES IAM-key economy

  • DKIM2 advances to draft-03 — and a BCP-00 — two material WG documents in six days

  • Events & Community — IETF 126 DKIM session July 21, DMA Advanced Email Conference London July 7

  • Links worth your time — MoEngage / Aampe, the 2026 Great ISP Email Retreat, theMarketer / Conectoo, Spamhaus CERT, SMB1001:2026

Top Stories

Blesta ransom email passed SPF, DKIM, and DMARC

Category: Security & Anti-Abuse

On June 26, customers of Blesta — the billing platform widely deployed by hosting providers — received a "Blesta Compromised" ransom email from [email protected]. The message threatened to leak the customer database the next day. The attackers had compromised a temp support account originally created for a third-party virtualization vendor, then used it to drive Blesta's own customer portal. The ransom mail went out through Blesta's real outbound infrastructure on Mailgun.

SPF passed. DKIM passed. DMARC passed against Blesta's own p=reject policy. Every authentication signal a receiver could check confirmed the message was routed through the legitimate sender's infrastructure — because it was. DMARC confirms the route the mail took. It was never designed to confirm the intent of the message moving along that route.

This is the cleanest example of "authenticated abuse" we've seen in months, and it pairs with the Xero, Atlassian Jira, and AWS SES patterns we covered earlier this year. The through-line is consistent: in 2026, with spoofing largely closed off by DMARC enforcement at the major receivers, the dominant residual phishing pattern is attackers operating mail from inside a legitimate sender's authenticated infrastructure. If your detection stack still treats SPF/DKIM/DMARC pass as a strong safety signal, this is the case study to take to your security team this week. The signal it carries is "the route is real." Nothing more.

CNIL email tracking-pixel deadline: July 14, 2026

Category: Regulatory & Compliance

France's CNIL published its email tracking-pixel recommendation on April 14, with a 90-day transitional window. That window closes July 14 — two weeks from today. The clock is real.

The compliance shape: any pixel collecting marketing-measurement data (open, time-on-message, render context) is now treated like a tracker under the ePrivacy Directive. For contacts collected before April 14, senders have until July 14 to send a notification email explaining pixel use and offering an opt-out. Miss the window and the transitional regime evaporates — re-collecting explicit pixel consent across the entire pre-April-14 contact base becomes the only legal path forward. Italy's Garante is on the same arc, with the six-month Italian window ending October 28. Lewis Silkin's comparative analysis published June 23 lays the two regimes side by side.

The carve-out worth knowing: pixels used purely for deliverability hygiene — suppressing chronic inactives, throttling cadence to disengaged segments — are not treated as marketing-measurement and don't require consent. Anything used to feed engagement scoring, journey orchestration, or campaign analytics does. Most ESP integrations don't separate the two cleanly at the pixel level. That engineering work is the part senders keep underestimating.

CNIL enforcement — formal notices, investigations, sanctions — is expected to begin immediately after July 14. If your EU contact base predates April 14 and you haven't sent the notification email yet, this is what you should be doing this week. Not next week.

Phishers aren't building infrastructure. They're borrowing yours.

Category: Security & Anti-Abuse

Kaspersky's Securelist research, picked up by emailexpert this week, documents a sharp rise in phishing campaigns sent through Amazon SES — not by exploiting any flaw in SES itself, but by harvesting AWS IAM access keys leaked in GitHub repos, .env files, Docker image layers, public S3 buckets, and similar developer mistakes.

The mechanics are mundane and that's the problem. Attackers scan with TruffleHog and equivalent tools, check each leaked key for SES sending permissions, and inherit the legitimate AWS customer's full reputation the moment they find one. No domain registration. No warmup. No infrastructure to build. SPF, DKIM, and DMARC all pass because the mail is genuinely originating from the victim's authenticated sending domain. The dominant campaigns are fake DocuSign-style document-signing notifications and BEC plays — fabricated email threads and forged invoices aimed at finance teams.

The architecture lesson generalizes well beyond SES. Sender reputation in 2026 is inherited by whoever holds the credentials, not by whoever earned them. That applies to every shared ESP — API key in a leaked repo, OAuth refresh token in a stale backup, service-account credential baked into a Docker image — and to every SaaS-mail integration that ships a long-lived secret. Rotate, scope, and monitor. If your SES setup still uses long-lived IAM users instead of role-assumption with short tokens, that is the week-one fix.

Deliverability & Authentication

DKIM2 advances to draft-03 — and the first BCP draft

The IETF DKIM working group landed two material documents in six days. On June 18 the WG published the first DKIM2 Best Current Practices draft (draft-ietf-dkim-dkim2-bcp-00). On June 24 the main spec advanced to draft-ietf-dkim-dkim2-spec-03. Two thirds of a year before the Q4 2026 mailbox-provider experimental-rollout target, the working group's tempo is picking up — not slipping.

The headline changes in spec-03. A new nd= tag has been introduced as an alternative mechanism to the existing mf= and rt= tags for handling imaginary hops between domains — the construct that always made forwarding scenarios under DKIM2 their own engineering problem. A new feedhere flag has been added to support privacy-conscious forwarding scenarios. The list of header fields ignored during signing has been promoted into its own dedicated section, with the experimental Delivered-To: header added to it. The rules for DSN propagation have been tightened so a DSN always carries the message headers up to the point where the DSN creator saw the message on its outward journey. Null recipes for header field modifications have been eliminated.

None of that is procedural cleanup. The forwarding-edge cases that always blow up real DKIM deployments — your delegated-domain replays, your Listserv hops, your security-vendor inline rewrites — are exactly the surface area this revision touches.

IETF 126 in Vienna kicks off July 18. The DKIM session Tuesday July 21 is where spec-04 direction gets set and the Q4 experimental-rollout target either holds or starts slipping. Watch that session.

Events & Community

  • IETF 126 DKIM working group session — Tuesday July 21, 14:00–16:00 Europe/Vienna, Park Suite 6. With spec-03 fresh and the BCP-00 draft only six days older, this is the session where the rest of the year's DKIM2 timeline gets set. Meeting page

  • DMA Advanced Email Conference — London, July 7. Senior-marketer audience focused on AI, data, and customer insight in lifecycle email. Pre-event webinar July 2, in-person day six days later. Details

  • MoEngage acquires Aampe to put a dedicated AI agent behind every customer. Announced June 24. Aampe operates millions of per-user agents processing more than 200 billion decisions per week, in production at ZenBusiness, Taxfix, Grab, and Swiggy. Founding team — Paul Meinshausen, Schaun Wheeler, Sami Abboud — joins MoEngage to lead a new Agentic Decisioning group. The first concrete agentic-CEP transaction with a clear "per-user agent" model — Braze, Klaviyo, and Salesforce Agentforce have all been racing toward this from the roadmap side; MoEngage just got there with a checkbook. CMSWire · MoEngage blog

  • The 2026 Great ISP Email Retreat — emailexpert's running tally of ISPs exiting consumer email: Goo Mail (Feb 25), Sparklight's Nova1Net (Mar 3), EONI and Ptera (May 1), iPrimus suspensions the same week, Evertek (September), Quadro (November). ISPs that don't outsource to Yahoo are exiting consumer mail entirely. List hygiene on the affected domains stops being a periodic task and becomes a Q3 cleanup project. emailexpert

  • theMarketer acquires Conectoo from eMAG Group — Romanian CDP vendor takes over an email platform owned inside one of the region's largest e-commerce groups. Six-month integration. The story matters more as a signal than as a single transaction — large enterprise groups across Europe are increasingly divesting "owned" email platforms, and dedicated email and CDP vendors are picking up the books of business. Romania Insider

  • Spamhaus CERT Insight Portal — enriched botnet C&C data live. Spamhaus added protocol, country codes, ASNs, malware-family naming, and last-seen dates to the free portal for government-funded CERTs and CSIRTs on June 14. Context number worth carrying: botnet C&C activity rose 56% in 2025, and Spamhaus tracks ~1,500 active C&Cs at any given time. Geographic distribution for June: Hungary down 60%, Slovenia up 2,100%. Spamhaus

  • CyberCert + Suped partner on SMB1001:2026 email auth — turnkey toolkit for MSPs serving Australian SMBs. Product story is niche; the signal that national-tier SMB cybersecurity frameworks are now mandating DMARC enforcement is the part that travels. SMB1001 Silver requires valid SPF; Gold requires SPF + DKIM + DMARC at p=quarantine or p=reject. Suped

That’s it for this week! If you have feedback to make this newsletter more useful, just hit reply!

This Week In Email — thisweekin.email

Keep Reading