Half-Year Review: Email in the AI Inbox Era
Six months that rearranged the reading layer: Gemini in Gmail, Microsoft rejecting outright, DMARC finally a standard. What the first half of 2026 means for senders.
Six months that rearranged the reading layer: Gemini in Gmail, Microsoft rejecting outright, DMARC finally a standard. What the first half of 2026 means for senders.
The incident is over, placement recovered, and the pressure to move on is enormous. The blameless postmortem practice that converts each incident into prevention.
Five months of AI Overviews data shows opens up and clicks down: recipients read summaries. How to structure email so the model's version still does your job.
When spammers forge your domain as their envelope sender, the bounces come to you. What backscatter is, why it happens, and how to stop causing and receiving it.
After eleven years, DMARC is a real standard: RFC 9989, 9990, and 9991 replace RFC 7489. What is different, what stays, and the short list of actions for senders.
The big three score senders differently, expose different data, and fail in different ways. One operating playbook per provider beats one averaged strategy.
user+anything@gmail.com is one mailbox wearing labels. How subaddressing works, why blocking it backfires, and what plus addresses reveal about your data flows.
Every email trust decision resolves through DNS, and DNSSEC is what makes those answers tamper-proof. What it buys email, what DANE requires, and safe operations.
For OTPs and password resets, seconds are the metric. Where latency hides in the sending path, how to measure time-to-inbox honestly, and what budgets to hold.
A preference center offers frequency and topic choices to people about to leave. Where it genuinely saves subscribers, where it violates one-click rules, and the design that works.
A rebrand replaces the one asset deliverability cannot: your domain's history. The parallel-running plan that carries trust from the old name to the new one.
Security gateways click every link in every email before humans see them. How scanner traffic pollutes click metrics, breaks one-click flows, and how to filter it.
Outlook now hard-rejects non-compliant bulk mail with 550 5.7.515, and Safe Senders cannot override it. Diagnosing the bounce and fixing the authentication behind it.
Gmail's January update puts Gemini between senders and readers: thread summaries, an AI-prioritized inbox, and suggested replies. What changes for email programs.
January is the quiet window between peak seasons. The full-stack audit that catches drift in authentication, DNS, list hygiene, and monitoring before it costs mail.
Microsoft joined the mandate, Gmail moved to hard rejection, and DMARCbis reached the finish line. What 2025 changed for senders and what it sets up for 2026.
Receiving servers defend themselves with deliberate delays, temporary rejections, and traps for impatient senders. How each defense works and how a good MTA passes them.
Postmaster Tools, SNDS, FBLs, DMARC reports, TLS-RPT, bounce logs, engagement data: the full observability stack, what each layer catches, and the alerts worth paging on.
Everyone has received the same email twice. The retry loops, queue semantics, and race conditions that cause duplicates, and the idempotency patterns that stop them.
Addresses like 佐藤@例え.jp are valid email. How EAI and SMTPUTF8 work, who supports them, and what sending systems break when a Unicode address shows up.
Email is a DNS application. The full record inventory a sending domain needs, the TTL strategy for safe changes, and the misconfigurations that quietly break delivery.
Between Black Friday and year end, send volumes triple while filters tighten. How to ramp into peak season so November's volume looks like growth, not an incident.
DMARCbis is finishing its journey through the IETF, replacing RFC 7489 with a Standards Track spec. The tree walk, retired tags, and what senders should do now.
Every sending platform offers SMTP relay and an HTTP API. The differences in latency, error handling, portability, and observability, and how to choose per workload.
Validation APIs verify syntax, domains, and mailbox existence. Where each check works, where catch-alls and traps defeat them, and where validation belongs in your stack.
Warmup services exchange automated opens and replies between member accounts to simulate engagement. Why providers treat this as manipulation and what to do instead.
Seed lists promise a number for the question every sender asks: inbox or spam folder? What placement tests measure, where they systematically mislead, and how to use them.
Every include, a, mx, and redirect in your SPF record costs a DNS lookup, and the budget is ten. Why records break at scale and how to fix them without flattening regret.
Every delivery question has its answer in the headers. How to trace a message's path through Received lines and decode Authentication-Results like a postmaster.
Microsoft now requires SPF, DKIM, and DMARC from high-volume senders to Outlook consumer domains. What the rules demand, how enforcement works, and how to comply.
Spam filters do not detect AI authorship. They detect what careless AI usage produces: template sameness, volume spikes, and engagement decline. Where the real risks are.
The NIS2 directive makes email authentication and transport security a regulatory matter for thousands of EU organizations. What it requires and where email fits.
Switching email providers resets your IPs, your DKIM keys, and every provider assumption about your traffic. A migration plan that carries your reputation across.
TLS-RPT delivers daily JSON reports on every failed TLS negotiation to your domain. The record, the report format, and how to turn failures into fixes.
MTA-STS closes the STARTTLS downgrade hole by letting domains require verified TLS for inbound mail. The policy file, the DNS record, and the gotchas in between.
RUA reports arrive as gzipped XML that nobody reads by hand. The report anatomy, a working parsing pipeline, and how to interpret the sources you will find.
MPP fires your tracking pixel whether or not anyone reads the message. How the proxy works, how badly it skews your metrics, and what to measure instead.
A DKIM signature stays valid no matter who forwards the message. How replay attacks abuse that property to spend your reputation, and the defenses that limit the damage.
Spam traps are addresses that never belonged on your list. The types, who operates them, how they end up in your database, and the hygiene that keeps them out.
Feedback loops send you the complaints your recipients file. How to register with Microsoft, Yahoo, and the rest, and what to build so the data actually gets used.
Hard versus soft is not enough. How SMTP codes, enhanced status codes, and provider quirks should drive your retry, suppression, and reputation logic.
Gmail's filtering models weigh replies, moves, stars, and deletes far more than the open rates senders obsess over. What the signals are and how to influence them.
Gmail enforces a 0.3% user-reported spam ceiling, but the denominator is inboxed mail, not sent volume. How the rate is computed and how to stay under it.
AMP for Email promised interactive inboxes. Six years after launch, here is who actually supports it, what it costs to run, and when the investment makes sense.
Gmail Postmaster Tools and Microsoft SNDS report sender reputation in fundamentally different ways. How to read both dashboards and act on what they actually show.

When email reputation collapses, the first 4 hours determine the recovery timeline. Triage, containment, communication the operational playbook teams actually need.

Bounce-based list cleaning is decades behind modern deliverability. The 90/180/365-day engagement model, sunset policies, and re-engagement that actually works.

How to remove your IP or domain from Spamhaus, SORBS, UCEPROTECT, and other blocklists. Which lists matter, which to ignore, and the delisting process for each.

How to architect email subdomains for reputation isolation. The 4-stream model, naming conventions, and why [send.brand.com] beats [mail.brand.com].

DMARC fails when SPF or DKIM pass for the wrong domain. The alignment rules, relaxed vs strict modes, and the ESP configuration that fixes it.

How to rotate DKIM keys in production without breaking signatures. Dual-selector strategy, 2048-bit key sizes, and the rotation cadence that actually works.

RFC 8058 one-click unsubscribe is mandatory for bulk senders. The five implementation mistakes that fail compliance and how to test your endpoint properly.

The complete compliance checklist for Yahoo and Gmail's February 2024 bulk sender requirements. Authentication, unsubscribe, complaint rates—what you actually need.

Forwarders break DMARC by modifying messages in transit. ARC (RFC 8617) preserves authentication results across hops. How it works, who supports it, and the limits.

BIMI displays your logo in supporting inboxes. The VMC certificate costs $1,500/year. Whether the brand recognition lift justifies the spend honestly assessed.

Password resets going to spam? You're sending them from the same IP and domain as marketing campaigns. The four operational fixes that actually work.

Most IP warming schedules fail because they ignore engagement segmentation. The 30-day ramp that actually works volume tables, segment ordering, and recovery rules.

When to move from shared to dedicated IP pools. The volume threshold, reputation contamination risks, and the cost-benefit analysis ESPs don't want you to do.

How to move from DMARC p=none to p=reject without breaking production mail. The phased rollout that actually works with the failures most senders hit.

Most SPF records are subtly broken. The 10-lookup limit, multiple records, +all, and the alignment trap what's actually wrong with your SPF setup.