Industry Updates

The email deliverability signal log

A running record of the changes that move the inbox: mailbox-provider policy shifts, new authentication standards, privacy and legal rules, blacklist and reputation news, and the acquisitions reshaping the space. Each entry is dated, rated for impact, and written to answer one question - what changed, and what should you do about it.

2026
29
DeliverabilityHigh impact

Validity Launches "Heatwave", a Blocklist Targeting Artificial Domain Warmup

On 3 September 2026 Validity launched Heatwave, a blocklist that targets synthetic (artificial) domain warming - services that spin up networks of fake mailboxes to fake opens, clicks and replies and manufacture sender reputation. It launched with 1M+ domains listed, is mirrored into Validity's DNS reputation zones, and is used or evaluated by Comcast, Proofpoint, Spamhaus and SURBL - so a listing can affect real delivery. Delisting is a manual review and stopping the warmup is not, on its own, grounds for removal.

Read the full briefing →
blocklistwarmupcold-emailvalidity
28
DeliverabilityLow impact

AI Assistants Can Now Run Live Email-Deliverability Checks (via MCP)

AI assistants like Claude can now run real email-deliverability checks through MCP (the Model Context Protocol), an open standard for connecting tools to assistants. Anthropic's Connectors Directory now lists such tools, so a user can ask "is my domain blacklisted?" and the assistant runs the actual check on the tool's infrastructure rather than guessing from training data. Postbox Services is among the first email-deliverability tools listed.

Read the full briefing →
mcpai-assistantstooling
28

DMARCbis Is Now RFC 9989: What Actually Changed, and the t= Trap Everyone Is Getting Wrong

DMARCbis stopped being a draft in May 2026: it is now RFC 9989 (core), 9990 (aggregate reporting) and 9991 (failure reporting), and it obsoletes the original RFC 7489 that almost every DMARC guide still cites. The record you publish keeps working, but three things changed under the hood - the Public Suffix List is replaced by a DNS tree walk, pct/rf/ri are removed, and a new np= tag is the sharpest anti-spoofing control in the record. Watch out for t=: it steps your policy down one level, it does not disable it, and secondary sources are already calling it pct=0 by mistake.

EffectivePublished May 2026

Read the full briefing →
dmarcbisrfc-9989dmarcauthentication
14
Transport SecurityMedium impact

TLS certificate lifetimes: 200 days now, 100 in 2027, 47 by 2029

CA/B Forum ballot SC-081v3 is phasing public TLS certificate validity down from 398 days to 47 by March 2029 - the 200-day cap took effect 15 March 2026. Email surfaces are on the clock: MX/STARTTLS, the MTA-STS policy host, BIMI logo hosting. The first mass renewal wave of 200-day certificates lands around 1 October 2026.

EffectiveIn force since 15 Mar 2026 - next step 15 Mar 2027

Read the full briefing →
tlscertificatescab-forummta-ststls-rpt
9
DeliverabilityMedium impact

APRF: The Draft Standard That Would Finally Show Senders Where Their Mail Lands

A new IETF draft (draft-brotman-aggregate-performance-reporting) proposes a DMARC-style mechanism for mailbox providers to email senders daily JSON reports on inbox placement and engagement - keyed to the DKIM signing domain, not the From address. It is early (Comcast is the only provider sending beta reports, with a Google engineer among the authors), but it could finally standardize the placement data that has always lived behind per-provider portals.

Read the full briefing →
aprfietf-draftreporting
5

DKIM2: Email Signing Gets a Ground-Up Rebuild to Stop Replay and Survive Forwarding

A revived IETF working group is rebuilding DKIM from the ground up. DKIM2 (draft-ietf-dkim-dkim2-spec, authored by engineers from Yahoo, Google and Fastmail) signs every hop, binds each signature to the SMTP envelope to stop replay, records reversible "recipes" so forwarding no longer breaks DMARC, and routes provable bounces up the chain - and a companion draft retires ARC into it. It is real enough to watch (working code exists), but still a draft: do not deploy it in production yet.

Read the full briefing →
dkim2ietf-draftauthentication
Chat with us!