Microsoft's third Exchange Online incident in ten days turns a one-off outage into a pattern, Validity launches a public blocklist aimed at synthetic domain warming, and two unrelated companies bet on the same AI-agent integration layer in the same week — right as a researcher demonstrated what can go wrong when that layer isn't isolated properly. It's a solid week, not a blockbuster one. Let's get into it.
Following up on last week's coverage of the Aug 31 Exchange Online cert-lapse outage — the one we flagged as a 67-hour one-off (MO1465074) — it turns out that was just the opener. Microsoft's had two more Exchange Online incidents since, with three unrelated root causes inside ten days.
On Sept 4, a malfunctioning anti-spam model started deferring external mail with a 451 4.7.500 error, telling senders their own reputation had tanked when it hadn't. Microsoft issued no public incident report on that one. Then on Sept 9, a mail-flow update spiked CPU on mailbox database infrastructure badly enough that Microsoft reverted it rather than fix it forward.
If you've been fielding M365 deliverability complaints from this window, figure out which of the three incidents you're actually looking at before you start second-guessing your own sending practices. A hyperscaler having three distinct failures in ten days — one of which actively misled senders about their own reputation — is a pattern that should worry anyone dependent on M365 mail flow, not just annoy them.
Source: EmailExpert
Sponsor this newsletter
Reach 214 people who build and run email.
This spot is open. One sponsor per issue, no competing ads — your logo, your words, and a link, right here in the middle of the read.
See rates and availability →Announced at K
on Sept 9, Klaviyo Headless exposes 260+ MCP (Model Context Protocol) tools so agents running in Claude, ChatGPT, or a custom internal app can read platform data, write changes, and launch campaigns — with the platform positioned as the system of record underneath. Same week, Bouncer shipped its own hosted MCP server for email verification (more on that below): two unrelated companies making the identical bet that "email platform as MCP surface for AI agents" is where the puck is going.Worth watching whether this becomes a genuine standard interface across vendors or a fragmented mess of incompatible MCP schemas, each with its own permission model and its own blast radius if something goes wrong. This is Klaviyo's own framing of its own keynote, so treat the specifics as marketing — but the strategic direction is real, and it's not an outlier bet given who else is making it this week.
Sources: Klaviyo, Agile Brand Guide
Check Point Research found that ChatGPT's sandboxed code-execution containers for two entirely different user accounts could pass messages to each other through a shared internal service (JFrog Artifactory) neither account was supposed to reach. An attacker's session could instruct a victim's session — via a planted prompt in a shared conversation or custom GPT — to pull data from the victim's connected Gmail using OAuth permissions the victim had already granted. The victim saw nothing beyond a small "Talked to Gmail" label, logged after the read had already happened.
The structural point for email people: mailbox providers' abuse detection watches login patterns and sending behavior, but this attack used a valid token through a channel nobody was monitoring. OpenAI has decommissioned the specific Artifactory instance; the broader class of risk — agent-to-agent side channels bypassing per-account isolation — is not obviously closed. If your org has connected Gmail, Drive, Teams, or GitHub to ChatGPT, this is worth a five-minute conversation with whoever owns that integration.
Sources: Check Point Research, Check Point Blog
Heatwave tracks over 1 million domains engaged in "synthetic warming" — bots exchanging mail with each other to fake trust signals — plus bulk cold-outreach sending. It gives mailbox providers and deliverability teams a named, quantified way to flag senders using warming-as-a-service tools, backed by Validity's own data showing those tools tend to leave domains worse off, not better.
It's a single-vendor list, not a mailbox-provider policy shift, so don't treat inclusion as gospel. But it's good ammunition next time a client asks whether a warming tool is worth the money.
Sources: Spam Resource, EmailExpert
CVE-2026-55007 (CVSS 8.1) is exploitable via a crafted Visio attachment processed by Exchange's content-indexing engine — no user interaction required, triggered purely by inbound mail arriving. None of the nine flaws patched this cycle are rated Critical, which is probably why this one isn't leading anyone's headlines.
It should be leading yours if you're still on Exchange 2016. That version is out of mainstream support, and the CU23 update shipping fixes for the other eight specifically omits this one — meaning the inbound-mail RCE stays unpatched even for customers paying for Extended Security Updates. Check your version today, not next sprint.
Source: EmailExpert
See "A Hidden Cross-Account Channel in ChatGPT Could Leak a Victim's Gmail Data" above.
That's the week. If something is wrong, reply and tell me — I read every response.
— John
This Week In Email — thisweekin.email
Subscribe to This Week in Email and get future issues delivered to your inbox.