Blog
Notes from the
honest side of email
Deliverability, honest analytics and outreach craft — written in plain language, with no growth-hack snake oil.
Earlier articles
253 articles
Deliverability8 min
Rejection, soft bounce, or spam folder: reading a 2026 delivery failure correctly
Gmail, Yahoo, and Microsoft fail mail differently now — a hard rejection, a reputation soft bounce, and silent spam-foldering each need a different fix.
ComplianceAnalysis6 min
What regulators actually check when you say 'we deleted it'
The EDPB's 2026 report on right-to-erasure enforcement surveyed 764 controllers across 32 DPAs and found most can't prove erasure happened. What auditors check.
DeveloperAnalysis6 min
Phishing doesn't need malware anymore — it just needs your session token
Adversary-in-the-middle kits relay real logins in real time and steal the session token directly, skipping malware — what it means for OAuth and session handling.
Copywriting8 min
Your cold email is probably asking for two things. That's the problem
Decision-making research on choice overload explains why a cold email with one clear ask consistently outperforms one offering the reader several options.
AIField note5 min
What happens when someone flips off the 'ask first' switch on an AI agent
An AI offensive-security agent run with human approval disabled operated unattended inside a government ministry's systems. The lesson applies past security tooling.
ComplianceAnalysis6 min
The UK blocked 80 million spoofed emails a month. That's what enforcement, not adoption, looks like
National DMARC mandates cut phishing delivery from 69% to 14%. The UK blocked 80 million spoofed emails in 30 days — proof enforcement works.
DeliverabilityAnalysis5 min
An unauthenticated Exchange spoofing bug shows why DMARC and patching aren't the same control
CVE-2026-42897, an exploited XSS bug in Exchange OWA, ran JavaScript from one crafted email — client trust and transport auth are different controls.
ComplianceAnalysis8 min
A US state just cut its penalty for a misleading subject line by 80%
Washington's HB 2274 lowered CEMA's per-violation damages from $500 to $100, after a state Supreme Court ruling expanded what counts as a misleading subject line.
DeveloperAnalysis6 min
Why Google, Microsoft, Salesforce, Snowflake, and ServiceNow all back one AI agent protocol
Google, Microsoft, Salesforce, Snowflake, and ServiceNow all back Anthropic's MCP. What one shared protocol buys developers, and its blast radius.
StrategyAnalysis9 min
Why the third email in your sequence often beats the first
The psychology of repeated exposure, from Zajonc's original experiments to advertising's three-exposure theory, and why familiarity is doing work your copy isn't.
StrategyAnalysis8 min
A hacked ad script just showed how fragile your marketing stack really is
A single compromised ad-tech script hit every site that had embedded it, with no phishing email and no local weakness. Here's the lesson for your own domain.
AIField note5 min
Small businesses just got an AI 'employee' that posts on its own. Cold email is next
Vendasta's autonomous AI Social Media Manager went live July 29, 2026 with no human review step. Outbound email is a much higher-stakes version of the same bet.