Skip to content

Blog

Notes from the
honest side of email

Deliverability, honest analytics and outreach craft — written in plain language, with no growth-hack snake oil.

Earlier articles

253 articles

Deliverability8 min

Rejection, soft bounce, or spam folder: reading a 2026 delivery failure correctly

Gmail, Yahoo, and Microsoft fail mail differently now — a hard rejection, a reputation soft bounce, and silent spam-foldering each need a different fix.

ComplianceAnalysis6 min

What regulators actually check when you say 'we deleted it'

The EDPB's 2026 report on right-to-erasure enforcement surveyed 764 controllers across 32 DPAs and found most can't prove erasure happened. What auditors check.

DeveloperAnalysis6 min

Phishing doesn't need malware anymore — it just needs your session token

Adversary-in-the-middle kits relay real logins in real time and steal the session token directly, skipping malware — what it means for OAuth and session handling.

Copywriting8 min

Your cold email is probably asking for two things. That's the problem

Decision-making research on choice overload explains why a cold email with one clear ask consistently outperforms one offering the reader several options.

AIField note5 min

What happens when someone flips off the 'ask first' switch on an AI agent

An AI offensive-security agent run with human approval disabled operated unattended inside a government ministry's systems. The lesson applies past security tooling.

ComplianceAnalysis6 min

The UK blocked 80 million spoofed emails a month. That's what enforcement, not adoption, looks like

National DMARC mandates cut phishing delivery from 69% to 14%. The UK blocked 80 million spoofed emails in 30 days — proof enforcement works.

DeliverabilityAnalysis5 min

An unauthenticated Exchange spoofing bug shows why DMARC and patching aren't the same control

CVE-2026-42897, an exploited XSS bug in Exchange OWA, ran JavaScript from one crafted email — client trust and transport auth are different controls.

ComplianceAnalysis8 min

A US state just cut its penalty for a misleading subject line by 80%

Washington's HB 2274 lowered CEMA's per-violation damages from $500 to $100, after a state Supreme Court ruling expanded what counts as a misleading subject line.

DeveloperAnalysis6 min

Why Google, Microsoft, Salesforce, Snowflake, and ServiceNow all back one AI agent protocol

Google, Microsoft, Salesforce, Snowflake, and ServiceNow all back Anthropic's MCP. What one shared protocol buys developers, and its blast radius.

StrategyAnalysis9 min

Why the third email in your sequence often beats the first

The psychology of repeated exposure, from Zajonc's original experiments to advertising's three-exposure theory, and why familiarity is doing work your copy isn't.

StrategyAnalysis8 min

A hacked ad script just showed how fragile your marketing stack really is

A single compromised ad-tech script hit every site that had embedded it, with no phishing email and no local weakness. Here's the lesson for your own domain.

AIField note5 min

Small businesses just got an AI 'employee' that posts on its own. Cold email is next

Vendasta's autonomous AI Social Media Manager went live July 29, 2026 with no human review step. Outbound email is a much higher-stakes version of the same bet.