This Week In Email — July 22, 2026
A new IETF Internet-Draft from Comcast, Iterable, and Google proposes exactly what deliverability practitioners have wanted for years: daily placement and engagement reports sent from mailbox providers directly to senders. That's the story of the week. Alongside it: a California class action landed on Apple's desk over the Hide My Email flaw it sat on for 13 months, a federal judge kicked the Thele v. Google inbox-AI lawsuit on standing and handed plaintiffs a ~July 28 deadline to try again, and Washington's CEMA amendment took effect — cutting per-email damages by 80% without actually ending the litigation. beehiiv, meanwhile, had its best quarter ever and then dropped its biggest product expansion to date.
It's a packed one. Let's get into it. But first…
I have an announcement.
Next week, TWIE is moving to a new platform, and introducing some new features!
A new format!
Sponsorships! (If you’d like to sponsor this newsletter and reach our highly-engaged readership, drop me a line!)
Rewards for referring new subscribers!
In This Issue
APRF: The IETF Draft That Could End Third-Party Inbox Monitoring — daily placement data, straight from the mailbox provider
beehiiv Summer Release: Community, AI Copilot, Programmatic Ads — the platform just repositioned as a full creator OS
Apple Sued Over Hide My Email Flaw — class action follows the 100%-exploit-rate disclosure
Thele v. Google Dismissed — But Not Dead — procedural win, not a merits ruling; July 28 deadline to refile
Washington CEMA: $500→$100 Per Email, But Litigation Isn't Over — amended damages, new knowledge bar, still dangerous at scale
Top Stories
FEATURED — APRF: The IETF Draft That Could End Third-Party Inbox Monitoring
Deliverability & Authentication
Here's the fundamental problem with deliverability monitoring as it exists today: it's inference all the way down. Seed networks. Panel data. Blended engagement signals used as proxies for placement. The actual answer — inbox vs. spam, from the mailbox provider — has always been opaque to senders. A new IETF Internet-Draft proposes to fix that at the protocol level.
draft-brotman-aggregate-performance-reporting-00 — APRF (Aggregate Performance Reporting Framework) — defines a mechanism for mailbox providers to send senders daily JSON reports showing (a) how many messages landed in inbox vs. spam/unwanted and (b) engagement actions: recoveries from spam, complaints. Co-authored by Alex Brotman (Comcast), Tom Corbett (Iterable), and Emil Gustafsson (Google). Discovery works just like DMARC — senders publish a TXT record at [selector]._aprf._domainkey.[domain], reports come back DKIM-signed and keyed to your d= and selector. Comcast is already running a live beta. The draft is not yet formally adopted by an IETF working group.
This is explicitly not replacing DMARC aggregate reports. Those are authentication-focused. APRF is placement- and behavior-focused: did the mail land in inbox, and did users do something about it? That's the data deliverability teams have been paying Validity, Return Path, and similar tools to approximate for years.
Google's co-authorship is the signal worth sitting with. When Comcast is already running a beta and Google puts its name on the draft, the calculus is different from a random individual submission. This isn't "interesting academic proposal." This has the fingerprints of an ecosystem with the scale to actually deploy it.
The draft has real distance to travel — no working group adoption yet, no deployment commitment from the big four outside Comcast. But if APRF achieves even partial meaningful adoption, seed-based inbox monitoring starts looking like the legacy workaround it always was. That's not a dig at the tools. It's what happens when the ground truth becomes available at the protocol level.
Sources: Spam Resource (July 19), emailexpert, IETF Datatracker
Email Marketing & Platforms
beehiiv Summer Release: Community, AI Copilot, Programmatic Ads, Visual Editor
beehiiv announced its best quarter ever — $4.5M ARR added in Q1 2026, 10B+ emails sent, 50K+ active users — and then held a first-ever Summer Release Event on July 16 and dropped four major product additions simultaneously.
Community brings discussion spaces with paid membership tiers inside the platform — Circle or Discord functionality, but native to your newsletter and subscriber list. Copilot is an AI assistant trained on your specific content, audience, and performance metrics — it can draft campaigns, surface monetization opportunities, and give growth advice via chat. The differentiation from generic AI drafting tools is that Copilot understands your own data: your open rates, your segments, your revenue. Programmatic Ads automates ad-slot fills based on audience and content match, giving publishers a passive revenue stream without a direct-sales operation. Visual Editor adds simultaneous edit-and-preview side-by-side — overdue quality-of-life feature.
CEO Tyler Denk's framing on Community: "People following your content have a shared interest in what you're creating, but they can't communicate with each other." That's the direct Substack counterplay — Substack's community tab has been a meaningful retention driver, and beehiiv's version is baked into the same platform as the newsletter tooling.
Whether Copilot's "trained on your metrics" claim delivers meaningfully better outputs than a generic LLM is something to evaluate, not assume. But the programmatic ads angle is genuinely interesting for mid-size newsletters that have the audience but not the sales team to monetize it directly. beehiiv is no longer a newsletter-first platform. This repositioning is either a smart land-grab or the beginning of scope creep. Probably both — and that tension usually resolves itself in a few years.
Security & Anti-Abuse
Apple Sued Over Hide My Email Flaw — Class Action Filed in California
Following up on our W28 coverage of the Hide My Email disclosure: the litigation arrived. A proposed class action was filed in California around July 14–16 alleging Apple violated California's false advertising law and other consumer protection statutes by knowingly marketing a privacy feature that doesn't work as described.
The timeline here is damning. Researcher Tyler Murphy first alerted Apple in June 2025. Apple claimed a fix in March 2026. That fix wasn't actually deployed. The 100%-exploit-rate vulnerability was still active when 404 Media published the disclosure on July 1. The legal theory isn't "Apple made a mistake" — it's "Apple marketed a working privacy feature while knowing it was broken." There's no known real-world exploitation. The damage theory is the product misrepresentation itself.
Apple's announced migration of Hide My Email addresses from icloud.com to private.icloud.com — "later this summer" — is presumably part of the eventual fix roadmap, but it hasn't shipped.
For senders, nothing changes operationally — these are permanent inboxes, treat them accordingly, as Al Iverson advised when we covered the original disclosure. But Apple's response pattern here — acknowledge in June 2025, miss the fix deadline in March 2026, wait for external disclosure to force action — is now generating litigation liability on top of the reputational damage. When your security fix timeline runs 13 months and counting, a class action isn't a surprise. Watch whether the lawsuit accelerates the domain migration Apple has been slow-walking.
Source: MacRumors (July 16)
Regulatory & Compliance
Thele v. Google Dismissed — But Not Dead; Plaintiffs Have Until ~July 28 to Refile
Following up on our W28 coverage: on July 7, U.S. District Judge Noël Wise (N.D. Cal.) dismissed Thele v. Google LLC — the proposed class action covering ~130 million Gmail users alleging Google violated CIPA and the federal Wiretap Act when it turned Gemini "smart features" default-on in October 2025 without consent.
The dismissal is on standing. Plaintiffs didn't allege a concrete enough injury to satisfy Article III. The judge granted 21 days to amend — deadline falls around July 28.
This is not a Google win on the merits. The court did not rule that processing inbox content for AI is legal. It ruled that these specific plaintiffs didn't describe their harm precisely enough. If the amended complaint clears the standing bar, the inbox-AI-as-wiretap question goes to a merits hearing. Two companion cases remain active: In re Otter.AI (motion to dismiss already argued May 20) and Noel v. Perplexity.
The procedural win here is real but narrow. Google has bought some time, not a verdict. An amended complaint with tighter harm allegations filed before July 28 restarts the clock on the core liability question — and the plaintiffs have a roadmap from the dismissal opinion for exactly what they need to fix. Watch this space closely over the next week.
Washington CEMA Amendment Live: $500→$100 Per Email, But Litigation Isn't Over
Washington's Commercial Electronic Mail Act (CEMA) was amended effective June 11, 2026 (HB 2274). Two changes: a knowledge requirement was added — plaintiffs must now prove the sender "knew or reasonably could have known" a subject line was false or misleading — and per-email damages were cut from $500 to $100.
An 80% damage reduction sounds like a big win. A Mondaq analysis published July 15 walks through why it's a partial win. High-volume campaigns still produce catastrophic aggregate exposure at $100/email — the math hasn't changed, just the multiplier. Plaintiffs can argue "repeated standardized practices" to establish the knowledge threshold: if your program systematically runs "Last Day" or "24 Hours Only" subject lines at scale, that pattern is exactly the evidence used to demonstrate knowledge. And Washington's Consumer Protection Act provides a parallel track for treble damages and injunctions that CEMA's amendment doesn't touch.
The catch nobody's saying loudly enough: the amendment is prospective. Pre-June 11 campaigns are still exposed under the old $500/email rules. If you revised subject line practices after the 2025 Washington Supreme Court ruling, the amendment doesn't retroactively un-expose you for sends before June 11. That litigation is still live.
Sources: Mondaq (July 15), National Law Review
Links Worth Your Time
DKIM2 spec-04 + IETF 126 Vienna Sessions — Building on W28 DKIM2 coverage:
draft-ietf-dkim-dkim2-spec-04published July 5, adding a header-field summary for unsigned fields, improved chain-of-custody handling (nd= tag), and clarified DSN verification. Cross-implementation interop testing across three stacks (Rust/Stalwart, Python, Go) reports successful results with header folding disabled — and surfaced two open spec bugs where all three implementations fail on folded header fields. IETF 126 DKIM Working Group Session 2 is July 24, 14:00–15:30 CEST in Vienna; these sessions shape the path to spec-05 and whether the Q4 2026 experimental-rollout target holds. This is the most concrete standards milestone in DKIM2's lifecycle yet. IETF Datatracker, Interop results (ietf-dkim list)AOL Mail's Future Under Bending Spoons: Four Scenarios — Bending Spoons completed its Nasdaq IPO on July 1 at a $25.2B market cap, up 40% on day one, raising $1.68B. Al Iverson's Spam Resource analysis asks what actually happens to AOL Mail (roughly 8M daily / 30M monthly active users) under new public-company ownership. His four scenarios: status quo (Yahoo keeps the backend), webmail shutdown, Bending Spoons infrastructure migration, or outsource to a white-label provider. His read: email migrations are slow and painful, making sudden change unlikely — but Bending Spoons has a history of aggressive restructuring. AOL still appears meaningfully in B2C email analytics. Worth knowing this situation exists. Spam Resource
"The Race to the Bottom Runs Straight Past the Inbox" — Jakub Olexa (CEO, Mailkit / Omnivery) writing at Spam Resource with a pointed take on ESP commoditization: treating all email as interchangeable infrastructure and competing purely on per-message pricing created the warm-up-services economy that now exists to clean up the mess that better sender vetting would have prevented. Key line: "A good chunk of the modern deliverability-services economy exists to clean up a mess that better gatekeeping would have prevented." Worth reading for anyone evaluating ESP purchasing decisions or thinking structurally about where market incentives landed. Spam Resource
Flodesk Studio — AI Email Design Generator, Free Beta — Flodesk launched Studio on July 3: describe what you want, get brand-matched email HTML in under 5 minutes. Average Flodesk build time is 2 hours; Studio targets sub-5-minute creation from a natural language prompt. Exports to any ESP — Mailchimp, Klaviyo, beehiiv, Kit — not locked to Flodesk. Free during beta. Built on a library of professional-designer-created templates. Relevant for SMB marketers and solo newsletter operators whose current design workflow is the bottleneck. PR Newswire
Events & Community
ZeroBounce "Ask Us Everything" — July 23, 1 PM ET; live deliverability Q&A with COO Brian Minick and Director of Deliverability Luke Glasner. Register
IETF 126 DKIM WG Session 2 — July 24, 14:00–15:30 CEST, Park Suite 6, Vienna. If you're tracking DKIM2's path to experimental deployment, this session shapes the spec-05 direction. Agenda
MailCon New York — August 3, NYC; deliverability, automation, AI tracks. Details
M3AAWG 68 — October 26–29, Paris. Hotel group-rate cutoff is September 30. Don't sleep on this one. Details
That's the week. Three legal and regulatory situations in motion simultaneously, a deliverability standard that could reshape how practitioners think about placement feedback, and beehiiv making a loud claim on the creator-OS category. As always — if something's wrong, or I missed a story that matters, hit reply and tell me. I read every one.
— John
This Week In Email — thisweekin.email

