This Week In Email — June 10, 2026
M3AAWG is live in Montreal this week; Washington's email subject-line law gets a statutory rewrite that takes effect Thursday; and Leboncoin published a detailed engineering post-mortem on moving 12 million daily transactional emails to a new MTA. Heavy week. Let's get into it.
In This Issue
Washington CEMA Amendment — effective June 11, the subject-line liability standard just changed
Microsoft Q1 2026 Email Threat Report — 8.3 billion phishing attempts, QR code attacks up 146%
Leboncoin: 12M-Email/Day Postfix → PowerMTA — why they chose PowerMTA over KumoMTA
M3AAWG 67 Live in Montreal — AI email agents, Yahoo Boys, and what this week's agenda reveals
Top Stories
Washington CEMA: The Email Subject-Line Law Just Got Rewritten
Washington's Commercial Electronic Mail Act has been a quiet source of litigation risk for years — a state law with $500-per-email statutory damages for subject lines deemed false or misleading. That changes Thursday. HB2274, signed March 23 and effective June 11, 2026, rewrites the standard in two ways: damages drop from $500 to $100 per email, and the law now requires "actual knowledge" that a subject line is false or misleading. Under the old standard, objective misleadingness was enough; under the new one, a plaintiff needs to show the sender knew or had objective reason to know.
That's a materially higher bar for litigation. For marketing operations teams with any Washington state exposure, this is statutory language worth putting in the legal review process — both the change and the fact that the $500 regime still governs anything commenced before June 11.
Source: Lexology / Seyfarth Shaw
Microsoft Q1 2026: 8.3 Billion Phishing Threats, QR Code Attacks Nearly Doubled
Microsoft's Defender Research team published their Q1 2026 email threat landscape on April 30, and the numbers tell a clear story. 8.3 billion email-based phishing threats in 90 days. QR code phishing grew 146% from January to March, with 70% of those attacks embedded in PDF attachments by the end of the quarter — specifically to route around URL-scanning defenses. CAPTCHA-gated phishing hit 11.9 million attacks in March alone, a 125% increase from January. Credential phishing tightened its grip: 89% to 95% of all payload-based attacks over the quarter.
The through-line: attackers are systematically routing around automated detection. QR codes and CAPTCHAs both work because they interrupt the scanning chain that defenders built for link-based threats. If your email security posture is tuned for URL-based credential phishing, the threat has already moved. Microsoft also flagged 10.7 million BEC attacks in Q1 — 82–84% were generic outreach messages, not sophisticated executive impersonation. The bar to run a BEC campaign is not high.
Source: Microsoft Security Blog
Infrastructure & MTAs
Leboncoin's 12M-Email/Day Migration: Why PowerMTA Won Over KumoMTA
Leboncoin — large French classifieds platform — published a detailed engineering post-mortem this month on migrating 12 million daily transactional emails from Postfix to PowerMTA. Postfix got them here, but per-provider delivery tuning was manual, IP reputation management across a Postfix cluster was untenable, and they needed AWS BYOIP support with per-IP scheduling that Postfix doesn't provide natively.
They evaluated both KumoMTA and PowerMTA; they chose PowerMTA for its Virtual MTA architecture — specifically the ability to associate multiple public IPs with a single EC2 instance and tune delivery behavior by destination domain, provider, and IP. The write-up covers IP warm-up sequencing, observability reconstruction, and the things that broke during cutover. Worth your time if you're managing transactional infra at scale.
Source: Leboncoin Tech Blog / Medium
Events & Community
M3AAWG 67th General Meeting — June 8–11, Montreal, Canada (Le Centre Sheraton). In progress this week. Agenda includes AI email agent security risks (user data exposure), spam filtering techniques for messaging platforms, cryptographic defenses against phishing, and advanced social engineering detection. Keynote from intelligence analyst Paul Raffile on "Yahoo Boys" crimes targeting minors. Tom Bartel chairs his first meeting as new board chair. Details
Links worth your time
EasyDMARC's 2026 DMARC Adoption Report: 52.1% of domains analyzed now have a DMARC record — but only ~9% combine enforcement policy with reporting. Fortune 500 at 95%; the Inc. 5000 still mostly at p=none. "Has DMARC" and "is protected by DMARC" are not the same thing. EasyDMARC
Microsoft documented a major AiTM device-code phishing campaign from mid-April: 35,000 users, 13,000 organizations, 26 countries. PDF attachments with HR conduct-review themes, device code phishing, MFA bypass via session token theft. If you haven't briefed your security team on this attack vector yet, this is the case study to use. The Hacker News
EU AI Act transparency requirements take effect in August 2026. Article 50 requires disclosure when it's not obvious to a reasonable person that content is AI-generated. If you're sending AI-generated emails to EU residents, a footer disclaimer probably isn't sufficient — the disclosure needs to be at first contact. EmailExpert
Stalwart v0.16 and Bulwark webmail are making self-hosted email a serious conversation again. Stalwart is a Rust-native all-in-one server (JMAP, IMAP, SMTP); Bulwark bundles mail, calendar, contacts, and files in a single deployable web client. Still niche, but the tooling gap is closing. Stalwart | Bulwark
Klaviyo's Spring 2026 release ships "Composer" (AI campaign generation from a prompt) and moves RCS Business Messaging to GA. The RCS development is worth watching for anyone tracking what comes after SMS. Klaviyo
If you’re attending M3AAWG this week, be sure to say hi!
This Week In Email — thisweekin.email

