Infobip just bought the industry's self-declared "neutral control layer," the CNIL's pixel-consent grace period expired yesterday, and the device-code phishing technique we flagged last week is now a $400/month subscription product. Oh, and IETF 126 kicks off in Vienna three days after this lands in your inbox — with DKIM2 on the Tuesday agenda. It's a lot. Let's get into it.

In This Issue

  • Infobip acquires SocketLabs — CPaaS consolidation reaches email's "control layer"

  • CNIL pixel-consent window closes — the transitional period ended July 14; enforcement starts now

  • Forg365 — device-code phishing gets a $400/month storefront

  • IETF 126 is this week — DKIM WG session Tuesday, July 21 in Vienna

  • Links worth your time — Outlook preview-line controls, email-to-SMS gateways dying, KDDI's 14.2M-account breach, Gmail Live, and more

Top Stories

Infobip Acquires SocketLabs: CPaaS Consolidation Reaches Email's Control Layer

Email Marketing & Platforms

Croatian CPaaS giant Infobip — an SMS/WhatsApp/RCS-first shop — announced around July 9 that it's buying Pennsylvania-based SocketLabs: 2,000+ customers, 1.2B+ emails a month, the Hurricane on-prem MTA it's shipped since 2007, and Spotlight, the cross-provider observability product. It's Infobip's first email-specific acquisition in roughly four years.

Here's what makes this one different from Twilio/SendGrid, Sinch/Mailgun, or Bird/SparkPost: Infobip didn't buy raw sending volume. It bought visibility and routing intelligence. SocketLabs built its whole position as a neutral layer that sits above ESPs — including Infobip's competitors — watching traffic and steering it.

The open question is whether that neutrality survives corporate ownership. Infobip told emailexpert that "neutrality and data segregation remain foundational principles." Maybe. But every acquired "neutral" platform says that on day one, and the competitor connectors and the Hurricane roadmap are where you'll see the truth. If you run Spotlight over non-Infobip sending infrastructure, watch your contract renewals and your connector deprecation notices. Watch this space.

Regulatory & Compliance

Following up on last week's CNIL coverage: the 90-day transitional window for notifying pre-April-14 EU contacts about email tracking pixels closed yesterday, July 14 — formal notices, investigations, and sanctions can begin immediately.

The interesting part is what actually happened in the run-up. Major brands shipped real notices: Carrefour emailed its list July 6 with a branded "your choice" notice, Disneyland Paris sent Dutch-language notices to Netherlands subscribers July 10, and France Télévisions and Allociné followed suit. That Disneyland Paris detail matters — compliance is spreading beyond France, ahead of Italy's mirror Garante deadline on October 28.

If you missed the window, the situation is now simple and bad: re-collecting explicit pixel consent across your pre-April-14 base is the only legal path left. The senders who treated this as a French-only technicality are about to find out how the CNIL feels about that.

Sources: emparrot, Batch, gblock

Security & Anti-Abuse

Forg365: Device-Code Phishing Gets a $400/Month Storefront

Last week we covered device-code phishing as "the attack DMARC can't see." This week it's for rent. Forg365, a new Telegram-distributed phishing-as-a-service platform, packages device-code phishing and adversary-in-the-middle session theft against Microsoft 365 for $400/month or $3,800/year — antibot evasion, AI-assisted lure creation, and post-compromise mailbox operations included.

Two details land squarely on this audience. First: lures go out through legitimate delivery infrastructure — Amazon SES, Twilio SendGrid — so they arrive fully authenticated. SPF passes. DKIM passes. DMARC passes. Second: a "ForgCookie" Chromium extension auto-refreshes SSO cookies after compromise, so access persists even when the stolen session should have expired.

The lesson: a technique that required real capability seven days ago now requires a Telegram account and a credit card. Commoditization is the whole story here — the volume of these attacks is about to be set by the market, not by attacker skill.

Events & Community

IETF 126 Is This Week: DKIM Session Tuesday, July 21, Vienna

We've previewed this one for two issues — now the logistics are final. IETF 126 runs July 18–24 in Vienna, and the DKIM WG session is confirmed for Tuesday, July 21, 14:00–16:00 CEST in Park Suite 6, with Brotman, Gondwana, Clayton, Herr, and Chuang expected in the room.

The stakes: DKIM2 spec-03 and BCP-00 are fresh, Stalwart's implementation is live, and this session sets spec-04 direction. It's also the first real stress test of the Q4 2026 experimental-rollout target. If you can't be in Vienna, remote participation is available via the datatracker agenda — worth your time if you touch authentication at all.

Calendar

  • ZeroBounce "Ask Us Everything" — July 23, 1 PM ET; live deliverability Q&A. Details

  • MailCon New York — August 3, NYC; deliverability, automation, and AI tracks. Details

  • M3AAWG 68 — October 26–29, Paris. The meeting is months out, but the hotel group-rate cutoff is September 30 — book now if you're going. Details

  • Email-to-SMS gateways are going away. Al Iverson rounds up the carrier exits: AT&T's txt.att.net died June 2025, T-Mobile's tmomail.net is effectively defunct, and Verizon's vtext.com shuts down by end of March 2027. Every cron job and on-call alert still piping email to a phone number needs a migration plan — proper SMS APIs or purpose-built bridges. Spam Resource

  • "Ghost phishing" hides payloads from scanners. A new EvilTokens campaign AES-GCM-encrypts phishing-page HTML so it only decrypts inside the victim's browser — gateways inspect the response without ever seeing what the employee sees. Paired with device-code phishing, the visibility gap now spans both the auth layer and the content layer. The Hacker News

  • KDDI breach exposed up to 14.2M email logins across six Japanese ISPs. A zero-day in third-party software on KDDI's shared email platform hit au/KDDI, STNet, J:COM, Chubu Telecommunications, NIFTY, and BIGLOBE — some passwords recoverable. One shared backend, six ISP brands, one zero-day. BleepingComputer, Security Affairs

  • New Outlook's July update lets users kill preview text. Message-list preview can now be set to 2 lines, 1 line, or none (GA July 2026, desktop + web) — a direct hit on preheader optimization assumptions. Also coming: a warning before replying to a stale email when a newer one exists in-thread. Windows Forum, Windows Latest

  • Gmail Live is in early-access beta. A voice-first Gemini mode, now in Google's official help docs, lets mobile users ask their inbox questions aloud and get synthesized answers — no search, no message list. Another step toward the inbox as an AI-mediated answer surface where your message is raw material, not the interface. TechMyMoney

  • Notion kills Notion Mail. The company cites "a dramatic shift in user behavior" — users handing inbox management to AI agents instead of reading mail in a client. A well-funded company exiting the email-client business two years in tells you where the standalone client category is headed. TechBuzz

  • Spamhaus published its H1 2026 Botnet Threat Update (July 10) — the half-year numbers behind the monthly whack-a-mole stats — and launched Deteqtive (July 13), passive-DNS intelligence tooling for tracing shared infrastructure, snowshoe ranges, and look-alike domains. Spamhaus

  • How does a mailbox provider actually display BIMI logos? Al Iverson walks the receiver-side flow almost nobody documents — validate the mail, find the record, validate the logo/VMC, decide whether to render. Useful ammo for explaining why a "correct" BIMI setup still doesn't show everywhere. Spam Resource

  • ActiveCampaign shipped twice in one week: a Google Ads connector for spinning up Performance Max campaigns via conversational prompts (July 8), and Active Intelligence 2.8, which persists brand voice and assets across AI drafting sessions (July 10). Email platforms keep racing to become cross-channel AI operating layers. PPC Land

  • Brevo named Inken Kuhlmann-Rhinow CMO & GM Self-Serve — the second exec hire since December's €500M round, running Brevo's largest segment and reporting straight to founder/CEO Armand Thiberge. GlobeNewswire

  • Friday Fun: the surprisingly fascinating story of Hotmail. Thirty years since the free-webmail land grab that shaped everything downstream. Spam Resource

That's the week. If something is wrong, reply and tell me — I read every response. Better yet, hit "forward" and send this to someone who ships email for a living.

— John

This Week In Email — thisweekin.email

Keep Reading