← All issues

This Week In Email — September 16, 2026

Microsoft's third Exchange Online incident in ten days turns a one-off outage into a pattern, Validity launches a public blocklist aimed at synthetic domain warming, and two unrelated companies bet on the same AI-agent integration layer in the same week — right as a researcher demonstrated what can go wrong when that layer isn't isolated properly. It's a solid week, not a blockbuster one. Let's get into it.

In This Issue

Top Stories

Microsoft's Ten Days: Three Separate Exchange Online Incidents, Three Unrelated Causes

Following up on last week's coverage of the Aug 31 Exchange Online cert-lapse outage — the one we flagged as a 67-hour one-off (MO1465074) — it turns out that was just the opener. Microsoft's had two more Exchange Online incidents since, with three unrelated root causes inside ten days.

On Sept 4, a malfunctioning anti-spam model started deferring external mail with a 451 4.7.500 error, telling senders their own reputation had tanked when it hadn't. Microsoft issued no public incident report on that one. Then on Sept 9, a mail-flow update spiked CPU on mailbox database infrastructure badly enough that Microsoft reverted it rather than fix it forward.

If you've been fielding M365 deliverability complaints from this window, figure out which of the three incidents you're actually looking at before you start second-guessing your own sending practices. A hyperscaler having three distinct failures in ten days — one of which actively misled senders about their own reputation — is a pattern that should worry anyone dependent on M365 mail flow, not just annoy them.

Source: EmailExpert

Klaviyo Goes "Headless" — 260+ MCP Tools Let AI Agents Read and Write Directly Into the Platform

Announced at K

on Sept 9, Klaviyo Headless exposes 260+ MCP (Model Context Protocol) tools so agents running in Claude, ChatGPT, or a custom internal app can read platform data, write changes, and launch campaigns — with the platform positioned as the system of record underneath. Same week, Bouncer shipped its own hosted MCP server for email verification (more on that below): two unrelated companies making the identical bet that "email platform as MCP surface for AI agents" is where the puck is going.

Worth watching whether this becomes a genuine standard interface across vendors or a fragmented mess of incompatible MCP schemas, each with its own permission model and its own blast radius if something goes wrong. This is Klaviyo's own framing of its own keynote, so treat the specifics as marketing — but the strategic direction is real, and it's not an outlier bet given who else is making it this week.

Sources: Klaviyo, Agile Brand Guide

A Hidden Cross-Account Channel in ChatGPT Could Leak a Victim's Gmail Data

Check Point Research found that ChatGPT's sandboxed code-execution containers for two entirely different user accounts could pass messages to each other through a shared internal service (JFrog Artifactory) neither account was supposed to reach. An attacker's session could instruct a victim's session — via a planted prompt in a shared conversation or custom GPT — to pull data from the victim's connected Gmail using OAuth permissions the victim had already granted. The victim saw nothing beyond a small "Talked to Gmail" label, logged after the read had already happened.

The structural point for email people: mailbox providers' abuse detection watches login patterns and sending behavior, but this attack used a valid token through a channel nobody was monitoring. OpenAI has decommissioned the specific Artifactory instance; the broader class of risk — agent-to-agent side channels bypassing per-account isolation — is not obviously closed. If your org has connected Gmail, Drive, Teams, or GitHub to ChatGPT, this is worth a five-minute conversation with whoever owns that integration.

Sources: Check Point Research, Check Point Blog

Deliverability & Authentication

Validity Launches "Heatwave" — a Public Blocklist for Synthetic Domain Warming and Cold Outreach

Heatwave tracks over 1 million domains engaged in "synthetic warming" — bots exchanging mail with each other to fake trust signals — plus bulk cold-outreach sending. It gives mailbox providers and deliverability teams a named, quantified way to flag senders using warming-as-a-service tools, backed by Validity's own data showing those tools tend to leave domains worse off, not better.

It's a single-vendor list, not a mailbox-provider policy shift, so don't treat inclusion as gospel. But it's good ammunition next time a client asks whether a warming tool is worth the money.

Sources: Spam Resource, EmailExpert

Infrastructure & MTAs

September Patch Tuesday: Nine Exchange Server Flaws, One Triggered by Inbound Mail — and Exchange 2016 Doesn't Get the Fix

CVE-2026-55007 (CVSS 8.1) is exploitable via a crafted Visio attachment processed by Exchange's content-indexing engine — no user interaction required, triggered purely by inbound mail arriving. None of the nine flaws patched this cycle are rated Critical, which is probably why this one isn't leading anyone's headlines.

It should be leading yours if you're still on Exchange 2016. That version is out of mainstream support, and the CU23 update shipping fixes for the other eight specifically omits this one — meaning the inbound-mail RCE stays unpatched even for customers paying for Extended Security Updates. Check your version today, not next sprint.

Source: EmailExpert

Security & Anti-Abuse

See "A Hidden Cross-Account Channel in ChatGPT Could Leak a Victim's Gmail Data" above.

Events & Community

Links worth your time


That's the week. If something is wrong, reply and tell me — I read every response.

— John

This Week In Email — thisweekin.email

Enjoyed this issue?

Subscribe to This Week in Email and get future issues delivered to your inbox.