Gmail Spam Attack on June 30th

Did you receive more spam than usual in your Gmail account at the end of June? Or did you receive more spam IN YOUR INBOX than usual? It might have been due to this. Google just released a root cause analysis of an issue from June 30th, where "Google's email delivery service was targeted in what we believe was an attempt to bypass spam classification." Sounds like the issue resulted in email delivery delays and some messages not getting spam filtered properly. Find more details here.

I *think* this is the same issue that Ben Schoon from 9to5Google is reporting on here.

Hey good senders, this is just another reminder that sometimes ISPs/webmail providers have bigger things to attend to, beyond whatever our problems are. It's good to remember that we may not be the only problem on a provider's plate. And let's not forget that there are lots of bad guys out there trying to send BILLIONS of spam messages every day. You'd never believe the amount of spam a large webmail provider like Gmail or Yahoo Mail (Verizon) or Microsoft OLC (Hotmail) are forced to process or reject every day. The unwanted junky stuff made up around 45% of internet email traffic as of March.

Re-visiting mail forwarding in a DMARC world

Forwarding email messages automatically can be tricky, as evidenced by recent conversation on the Mailop list. Email forwarding always breaks SPF authentication, and can easily break DKIM authentication if you modify any of the headers (and knowing which headers to stay away from can take a bit of work). But it's still doable if you take some care.

For me, this was a solved problem way back in 2015. In a nutshell, I have a script that will just grab the mail, rewrite the headers, send it on with my domain and IP as the sender (properly authenticated with DKIM and SPF). (Funny how I thought ARC would eventually help with email forwarding, but its use case seems perhaps only suited to the biggest providers.)

Last night, I updated my email forwarding script slightly and here's where you'll find the new version. It's still potentially pretty fragile in that it makes a lot of assumptions about the case sensitivity of headers, but in my (admittedly limited) use case, I actually haven't had any trouble with this in years. If you capture mail on a Linux server running postfix/Maildir set up, you could easily modify this script to edit the username, sender address, and recipient address, and drop it into your server to be called by cron periodically and it'll happily pick up mail, rewrite the headers to prevent DMARC-related forwarding issues, and then email it onward it on as directed.

Here's my top five best practices for email forwarding, if you want to do as I do:
  1. Don't forward spam. Have a spam filter in front of this. Otherwise you'll damage your own IP/domain reputation. (Perhaps even have a separate sending IP address or at lease a separate DKIM domain for forwarding, if you're really worried about this.)
  2. Send as you, not as them. The forwarded mail should have your from domain and you should sign the forwarded mail with your DKIM signature. I strip away the old signature (change the header name to X-DKIM-Signature) to fully remove it from the equation.
  3. Make sure that the mail is fully authenticated. DKIM as noted above, sending IP address is in the SPF record of the return-path domain, domain has a DMARC record. All help with deliverability, directly or indirectly.
  4. Rewrite the return-path address. Why? If you don't, you'll potentially run afoul of DMARC policy due to SPF authentication failure, and some of the forwarded mail will be rejected. (I don't recommend bothering that you configure it to play nice with Sender Rewriting Scheme as SRS is not widely implemented.)
  5. Preserve the original from address in the reply-to field, if at all possible. That way users can still respond to the original sender, in spite of the DMARC-necessary header rewriting. This doesn't always work perfectly, as Gmail has some safeguards to prevent what they think may be funny business in from/reply-to combinations. But it generally works. (And Gmail's limitations aren't set in stone.)
And finally, keep in mind that email forwarding can be complex and imperfect. The biggest providers do it, but I think some of their success with it is due to bending email authentication checks and/or whitelisting forwarding IP addresses, which are options not always available to the hobbyist or smaller enterprise. That doesn't mean you can't or shouldn't do it, but like with so many things deliverability-related, it's important to "keep your nose clean" and do whatever you can to ensure that your IP address and domain are only sending (or in this case forwarding) wanted mail.

(And don't complain to me about how this "breaks email" -- no, email has changed, email has evolved, and the old ".forward" method of email forwarding hasn't been very compatible with most large mailbox providers for years. I strongly feel that you have to adapt and evolve if you want continued success.)

BYE: My first impressions

If you recall my recent review of the new HEY email service, you'll remember that I wasn't convinced that it was the right email tool for me. Maybe you felt the same way? Maybe not. But if you didn't feel like HEY was the next big thing, BYE might just be the right email service for you! Clearly inspired by HEY, BYE promises to be "the first email service to automatically respond with an insult, and then delete every email sent to you." I think I'm in love. Read all about it here

Joking aside -- I am struck by another comparison with HEY. That still, this is stuff you can just as easily do with Gmail. How do I know? A couple of years ago, my wife published a particular op-ed in the Washington Post and this is exactly what we ended up having to do just afterward. We configured a Gmail account to auto-reply with a "go away" message and delete everything. We had to. Stop and think about what kind of angry emails you might get in response to political speech. And then double the abuse to account for how jerks treat women online. That mailbox was wholly radioactive -- we could feel the heat all the way from the next room, even with the laptop closed.

Huh, you know, the more I think about it, maybe we do need an email service like BYE.

Quick List: ESP Abuse/Spam Contact List

There are useful tools out there that can help you figure out where to send a spam report to. I use the ARIN Regional Internet Registry and nearly every day to look up spam reporting (abuse) contacts for IP addresses and domains. Some folks use SpamCop (which historically does not play nice with ESPs, so it's not as valuable to me). I don't necessarily have the time or skills to build something as technically complex or useful as these tools, but I did want to try to make it easier for people to find spam/abuse contact information for various sending email platforms (ESPs, email service providers). To that end, I've reached out to various providers and asked them to share contact info so that I can share it with you here.

HEY: My first impressions

HEY is a new email service with webmail and a mobile client, recently launched by the folks behind Basecamp, a web-based project management tool. HEY users receive email at the domain

They're selling email service for $99/year (or more). If you're really just interested in a taste of deliverability and rendering testing, you can get a free trial account that lasts for two weeks (and HEY gets to pick your username). You can initiate that free trial from inside the mobile app or on the web. (I tested the iOS app; YMMV on Android.)

Reporting Spam to Apple from your iCloud Mail account

Apple's iCloud Mail doesn't have an ISP Feedback Loop (the mechanism that sends spam reports back to the sender or sending email platform), but even so, I think it is good to tell them when you believe a particular email message to be spam.

Full headers: What are they and how to access them

Internet email messages have hidden headers (that email technology people commonly call "full headers") that can help you trace the source of a message and these can come in very handy for troubleshooting email delivery issues or reporting spam.

Reporting spam with Outlook on iOS

Good news! The latest version of the Outlook email client for iPhone (version 4.42.0) now supports user submission of spam and phishing reports. TL; DR? When viewing a message in Outlook on your iPhone, open the "more" (three dots) menu and select "report junk" to tell Microsoft that you think a particular email message is spam.

You WANT spam folder delivery?

You don't want your mail to go to the inbox? What? Why would you want that?

But OK, if you truly want to send an email message and ensure that it goes to the spam folder, The Next Web reports on a tool called Straight2Spam, for those times when you want to email somebody but want them to possibly miss the email by having it delivered to the spam folder. It sounds like a fine opportunity to engage in passive aggressive behavior, if you ask me.

You might be wondering, how well does it work? I have no idea. I've got a full time job and no spare cycles to test this kind of nonsense myself. You should try it out and let me know if it gets the job done.

Help! All mail to users is bouncing!

Here's the scenario. You've got "" email addresses on your list. They signed up for your email. But when you try to email them, that email bounces back. What's going wrong? Allow me to explain.

What is the Vade Threat List? How do I request removal?

Vade Secure is "a global leader in predictive email defense, protecting 600 million mailboxes in 76 countries. We help MSPs and SMBs protect their Office 365 users from advanced email threats, including phishing, spear phishing, and malware."

Blocked at

On Tuesday, June 9th, 2020, various mail server administrators were reporting that they were now having trouble delivering email messages to large German ISP and mailbox provider (and telecommunications company) T-Online.

ISP Deliverability Guide: 1&1 (, GMX,

1&1 is a large email and web hosting provider headquartered in Germany, but with a large presense throughout Europe and a significant showing in the US. They host mail using the domains,,, as well as many other domains.

New email vendor? Expect your deliverability to plummet… at first

I've worked in Deliverability for a long time now, across multiple sending platforms, and I go to industry events and know a lot of people in the space. One of the things I've learned from talking to colleagues at different companies is how opens and clicks are almost always lower after a sender switches ESPs. Not forever, and not lethally so, but regardless of which platform you used to use, and which one you use now, opens and clicks will be lower on the new platform compared to the old platform. Clients can be confused about it, assuming the new platform must be doing wrong, and deliverability people are invariably stumped when they first run into it, because there's no real handbook or guide to walk you through this.

BIMI: ISP Support as of June 2020

It's been about three months, so time for another BIMI status update. Here's the current status of BIMI and its support by the top ISPs.

Tony Webster: Investigating using domain & SSL info

Minnesota-based freelance journalist Tony Webster is somebody you should follow on Twitter. He's been mining public records and other info to provide additional insight into what's going on in Minneapolis (my home town) right now.

You should check out his website, too. One thing that really caught my eye was this: Using domain registrations, security certificates, and Shodan to break news. He calls it, "A quick guide for journalists: how to spot new domain registrations, recently-issued SSL certificates, and new servers to report on political, business, and government initiatives." It's good stuff! It might need an update, as WHOIS output in a GDPR-compliant world can be limited compared to what it once was (thanks, ICANN), but there's still some very good stuff here.

How to Send a Text Message Via Email

I'm not sure how the website "" ended up being a good resource for this, but that's where I found the most information when I started doing my research. Just to be safe, I'm going to share their same info here just in case that website disappears.

Want to use email to send a text message to your cell phone? Just send an email message to your ten digit phone number + @ + your provider's SMS/MMS gateway domain name. For example, the Verizon Wireless domain for this is If you're a Verizon Wireless customer, and your mobile phone number is 3125551212, you would send email to to send a text message to your mobile phone.

Please hire: Aric McKeown

My friend Aric McKeown is a smart guy on a job hunt. Are you hiring? Got anything suitable for his unique set of skills? He's got very solid deliverability, email operations expertise and more!

Aric writes: I have spent the last 5 years work in email deliverability and the 13 previous years working in email marketing production, website analytics, and website design.

In addition to my work resume, I have a large swath of creative side work I've been involved in and created.

Least Dangerous Game - A urban scavenger hunt created at the outset of Twitter, highlighted by Twitter's Jack Dorsey himself.

Make Me Watch TV - A one-year experiment in web 3.0, allowing users to dictate the TV shows I would watch and live-blog nightly.

The Mustache Rangers - A 250-episode improvised podcast produced, edited, and performed by me. 

Blank It - An abstract and surreal webcomic written by me.

A Talking Cat!?!: The Blog - Examples of extreme critical and humorous writing pertaining to the horribly bad movie A Talking Cat!?!

If you, or somebody you know, needs someone with a large history of email marketing skills, or any of my other myriad of critical and creative skills, please let me know.

Dead domains:,,, and

Back in 2019,  UPC (Liberty Global) sold their Czech Republic holdings to Vodafone. Fast forward to May 2020 and they've just announced that email service to the Czech UPC/Chello domains is being shut down, with service terminating on August 31, 2020.

Finally! A font-based solution to the Scunthorpe problem

I've mentioned the Scunthorpe problem a couple times previously--how computerized attempts to block profanity inevitably result in silly false positives. Today it is with glee I note that a kindly font designer has taken heed of the plight of the town of Scunthorpe and implemented a rather silly font that automatically blocks most swears, but allows the name "Scunthorpe" to remain fully viewable. You'll want to click on through and learn more about this, I am sure.

ISP Deliverability Guide: Apple's iCloud Mail

Apple's iCloud Mail is a top ten consumer email mailbox provider based in the US, hosting consumer mailboxes at the domains, and

Apple may not always make it clear exactly why they may have blocked your mail, but I strongly believe that they look at the typical deliverability and reputation-related data points that most smart ISPs look at. Based on metrics and reputation, do they suspect that the mail you are sending is unwanted? Do they see high spam complaints? Are you blacklisted by Spamhaus or is your mail fingerprinted as spam with a major reputation provider such as Proofpoint? Any of these are likely reasons for being blocked from sending to Apple's consumer mailboxes.

Dead DNSBLs: and

Two anti-spam blocking lists appear to have died or malfunctioned recently.

Your periodic reminder: Please register with

If you're an email marketer, a compliance or deliverability specialist at an ESP, if you work for an email platform, or if you're a marketing manager who manages a lot of outbound email streams, I ask that you register all of your domains with, the Network Abuse Clearinghouse, run by John Levine, is a simple, centralized database of spam contact information for different domains. John, who has managed this serviced for many years, has done the internet community a very good service by helping to make it easier for people and automation to send spam reports to the right place.

Yikes! Cyber-Criminals Increasingly Using CAPTCHA Walls in Phishing Attacks

From Infosecurity Magazine: "New research from Barracuda Networks has revealed that cyber-criminals are increasingly using official reCAPTCHA walls to disguise malicious content from email security systems and trick unsuspecting users." Read more here.

Meaning, if a phishing email's landing page blocks content until and unless a user solves a CAPTCHA or CAPTCHA-like process, the automated systems in use by email security devices and services (such as Barracuda) may not be able to fully review the content to correctly categorize it as malicious. That's pretty scary. I wonder if a long term solution is perhaps for security services to collaborate with CAPTCHA providers to be able to see past these challenges. I've long felt there's a missed opportunity there for those important security services to work more closely with content providers and email platforms to better understand each other and improve threat identification. But what do I know?

In the meantime, it's important that users stay vigilant, as even before this challenge there's always going to be some bad content or other that gets past a filter. Be careful what you click on and be sure to check URLs of any site where you may be entering login credentials. (And a password tool such as LastPass can help with this sort of thing as well; it'd only populate your credentials in a site with the correct domain name, not suggesting a user/password entry on a fake domain name that it doesn't recognize.)

[ H/T: Slashdot ]

Google: Protecting businesses against cyber threats during COVID-19 and beyond

Neil Kumaran and Sam Lugani from Google recently shared staggering statistics regarding the amount of bad stuff that gets aimed at Gmail users daily: "Every day, Gmail blocks more than 100 million phishing emails. During the last week, we saw 18 million daily malware and phishing emails related to COVID-19. This is in addition to more than 240 million COVID-related daily spam messages. Our ML models have evolved to understand and filter these threats, and we continue to block more than 99.9% of spam, phishing, and malware from reaching our users." has tabs now, too?

What? This seems new. Brad Gurley talks about this over on his Delivery Counts blog. He says the tabs that show up include "Focused Inbox, Microsoft’s 'Priority Inbox' clone, along with Promotions, Social, and Newsletters." Find more details and screenshots here.


With so many grocery store shelves running bare during the pandemic, it looks as though people are turning to Spam (the good and salty kind). "The packaged pork product that is Spam has never been more popular," reports the Minneapolis Star-Tribune. Looking for recipes? They've got you covered. I'll be trying the spam fried rice, myself. It sounds like a nice change from my usual spam-and-eggs.

Beware of questionable and/or bad guys trying to take advantage of you in a rough time

You want the country to open up again? Be careful not to let your haste allow you to fall into the astroturf-driven fake news websites, or even worse, get tricked into giving your personal information out to bad actors.

Blocking emails to role accounts: Best practice?

Do you block email signup attempts from role accounts? If not, I think you should consider it.

What's a role account, you might ask? It's an email that has a username part (the part to the left of the @ sign) that is commonly reserved for either a system function or administrative role.

Call for Deliverability Monitoring Vendors: ZeroBounce

In my ongoing quest to share info about additional email deliverability testing and monitoring vendors, I've stumbled across this press release from email validation platform ZeroBounce. They say: "The ZeroBounce Inbox Placement Tester gives senders an overview of their future email deliverability. Customers will receive access to more than 20 test email addresses associated with the most popular email providers around the world. The results – inbox, spam or not delivered – give users a chance to revise their emails, troubleshoot issues, and send more confidently."

BIMI: ISP Support as of April 2020

I get asked about this quite often, so I think periodically I'll post a quick update out there showing current status of BIMI and its support by the top ISPs.

More (pointless) fun with double opt-in

For no useful reason, I took my little double opt-in tool and hitched it to a script that sends a daily automated email message. Now if you sign up for this new email list, you'll get a daily email with a link to a song or music video. Different every day, personally selected by me. Some good, some very good, some not so good. If you're bored and need a daily distraction, check it out!

Bounteous explains AMP for Email

What is AMP for Email? Where did it come from, who supports it, what do you do with it, what's its current state, and what does the future likely hold? Caity O'Connor, Campaign Specialist for Bounteous answers most of these questions in what I believe to be the best overview to date. Click here to read.

Ask Al: Help! How best to send to 70 friends at once?

Thierry writes: "For the past 3 days I have been identified by Spamhaus as a spammer, I guess, as I get error 554 when sending to domains that they filter. As you can see I have a address.

"The only change in my recent email activity is that for the past 10 days I have been writing kind of a diary email to all my friends and family (about 70 recipients). The frustrating part is that they write to me and I can't reply to them!

"If you have any advice and time to give it, that would be really really nice."

(Thursday, April 9, 2020 Edit: Updated title to better reflect the likely underlying issue.)

Why coronavirus scammers can send fake emails from real domains

Here's a very simple and straightforward explanation of how "Organizations like the WHO could prevent domain spoofing, but many don’t," by Joss Fong and Cleo Abram for Recode. If you know about DMARC, you already know what's going on here, but it's still an important read. Hopefully it'll drive further DMARC adoption.

[H/T: Brian Westnedge.]

April Fools Day is Cancelled

Please don't email me something fake or "jokey" on Wednesday. And don't do that thing where your company or blog posts a bunch of fake stuff to try to troll people. Tensions are high and people are nervous. Now truly is not the time for failed attempts at being wacky.

Reference:, GMX and Domains

GMX and are two freemail providers based owned by United Internet (1&1) and primarily based in Germany, but providing free email seemingly globally. might be considered the "US edition" of their email service and has nearly 200 different email domains to choose from.

It's been tough to find a published reference list of domains used by them (with the exception of the domains), but here's what I was able to come up with, with help from smart guys Jakub Olexa and Udeme Ukutt.

Spam and reputation

Need a break from the heavier news? Okay, let's talk about spam and reputation. No, not that spam, and not that kind of reputation. Spam, the food product. Julia Press of Business Insider explains "how the makers of Spam stopped worrying about being a global punchline and learned to embrace the joke."

While I'm not planning to hoard Spam during this tough time, I do keep a tin of bacon-flavored Spam in the cupboard, as it makes a good breakfast meat if you find yourself out of bacon or sausage. Slice it thin and it fries up nicely on the stovetop. It also greases the pan well enough that I find that I don't need to oil the pan before frying the eggs.

A few COVID-19 subject lines

The Freecycle Community and COVID-19. COVID-19: How UPS is Responding. Update from Starbucks. Supporting our customers during this critical time. Coronavirus Update. Temporary Change to Store Hours. A travel update from our leadership. COVID-19 Updates From the Illinois Lottery. Our commitment to safety - a message about coronavirus. A message from our CEO. Important information about the coronavirus. A message to our guests from CEO. More Flexibility for Your Travel. Health and Safety Information from WG Restaurants. Caring for the Lyft community. Traveling with Flexibility and Care. We are here for you. Here’s Are New Hours and Closures for Campus Buildings During Coronavirus Outbreak. How we're supporting you during the coronavirus. A message from our CEO. Health & Safety Update from Tire Store. A travel update from leadership. A Letter to our Fans. Our pledge to you during the coronavirus outbreak. A message from E.T. about COVID-19. Updates & Resources for Businesses Impacted by COVID-19. We are still operating at full capacity. A Day of Giving Message for Customers. Message from the Mayor: COVID-19 Updates. Extending Our Support Through COVID-19.

Reference: All Virgin Media (UK) domains

I'm working to add to my list of ISP resource pages, including new information on domains used by various ISPs. Here's information for UK broadband provider Virgin Media.

Call for Deliverability Monitoring Vendors: Postmastery

Hey, deliverability monitoring vendors! I know you're out there, and I don't know a lot about many of you. Do you manage a service that does inbox deliverability testing, seedlist testing, inbox monitoring, or similar functionality? Feel free to drop me a line and let me know a little bit about your product or service, and I'll publish it here. 

First up -- Willem Stam has kindly provided the following information about Postmastery:

Everything marketers need to know about BIMI: The latest email standard

Jennifer Cannon from Martech Today just posted a solid overview of where BIMI is at today. If you don't recall what BIMI is, she explains: "BIMI is a way for brands to publish their logos in their customers’ inboxes and allows logos to be easily incorporated into messaging."

Amazon Web Services (AWS) now blocking block port 25

Amazon recently made a change affecting AWS/EC2 users. As of January 27, 2020, new EC2 instances will no longer have port 25 access to the world. This means that by default, they won't be able to send email.

Other Deliverability Monitoring Vendors?

Besides Return Path and 250ok (now both owned by Validity), and eDataSource (now owned by SparkPost), here are three other deliverability monitoring vendors, as shared by kind commenters on my previous post:

Validity to Acquire 250ok

When I ask myself, what vendors are there in the deliverability monitoring tools space, I think of three primary vendors: Return Path, 250ok and eDataSource.

Then I ask myself, what will this vendor landscape look like in a year from now?

Fun with Double Opt-in

Here's a link to the source of my new double opt-in sign up tool, if you'd like to check it out or install it for your own use. (It is now called WombatMail.) Of course, feel free to go ahead and submit your address if you'd like to receive email updates from Spam Resource.

Some considerations related to the double opt-in signup script:
  • This is written in Bash, a common linux/unix scripting language.
  • There are variables near the top that you will need to edit to specify things like the name of your list, the email address to send from, etc.
  • You can block various domains, usernames and email addresses using the BADDOMS, BADUSERS and BADEMAILS variables.
  • There are a few lines you can comment out to disable things like the unsub notification email, DNS checks, and the new subscriber notification email. Search for the word "comment" to find these points.
  • Email authentication is a function of your mail server and DNS configuration in this context, not my script. Meaning my script does not add SPF or DKIM or DMARC -- you add these by way of configuring DNS and your mail server for your domain.
  • You can look at the gen_code subroutine if you want to modify the way the opt-in link looks. Be careful not to make it so simple that anybody could manipulate a URL to cause a forged opt-in subscription.
  • To export subscribers, use this script. It reads the log, exporting every person whose current status is "subscribed." 
  • I think this process of using a log file and finding status via the log file is a clunky-but-good-enough way to manage a database without actually using a database. You could implement a SQL database to track active subscriptions and logs if you like, but I wanted to minimize my reliance on additional tools for this particular project.
Some thoughts on this opt-in process and double opt-in best practices in general:
  • The script generates fairly long/random opt-in URL codes. This is to prevent opt-in forgeries. You don't want people to be able to "hack" URLs to cause forged subscriptions or even forged unsubscribes. For this reason, you should never expose the email address in the opt-in URL.
  • My opt-in URLs don't expire. Maybe they should, and maybe they will in a future update.
  • To prevent "opt-in confirmation bombing," this tool allows a user to re-request an opt-in confirmation twice, for a total of three opt-in confirmation emails. After that it won't send you another. If you subscribe, then later unsubscribe, the counter is reset and you could receive three more. That way it allows re-sends for users who might resubscribe in the future.
  • The script checks subscriber domain validity by matching the TLD against a fixed list of TLDs. This will eventually go out of date as somebody adds the latest new, weird TLD to the world, but is probably good enough for government work. It is unlikely that anyone with an email address of bob@chicago.squirrelunderpants is going to try to sign up for your list, even if "dot squirrelunderpants" ends up being a valid TLD in the future. I suppose I could do a live call out to the IANA TLD list, but why add the network noise?
  • The script also requires that the sending domain have a valid MX record or A record. If it doesn't, mail won't be accepted anyway, so why bother sending a confirmation mail? Similarly, it looks for an SPF record that suggests that a domain sends no mail. A domain configured like that isn't likely to have valid users who want to receive your mail. A lot of spamtrap domains are configured this way; let's not bother them with confirmation requests.
By the way, it turns out that the opt-in confirmation emails for my list are delivering to the spam folder at Microsoft/Hotmail, even though my IP address has a Sender Score of 100, 5+ years of history sending good mail, and I authenticate mail with DKIM and SPF. Perhaps that says more about Microsoft than me. I suppose I'll open a mitigation request ticket at some point.

Anyway, the reason I put all this together was just to remind myself that double opt-in isn't hard. I hacked this script together over a few hours here and there last weekend, and somebody putting more time, effort and planning into it could do a better job than I do. You could take this script and use it to manage signups for your list, and know that every signed up address has been properly validated, accurate and truly opted-in, without spending a dime on an external vendor.

(Updated 3/2/2020: I've renamed the list management tool "WombatMail," since it's a domain name I've had forever but do very little with.)

You should check out: Really Good Emails

Fellow Director of Deliverability Jen Nespola Lantz reached out to me to share a link to Really Good Emails.

She writes:"I often get asked, "Okay, you want me to do X, but what would that look like? Can you send me ideas?" I am not always able to send client examples, so I used to either have to mock them up or pull from personal examples. Although this is not necessarily a deliverability tool, it is a great source of ideas for emails and messaging for this very case (and many more). If you think about it, ultimately, if you send content that looks great and functions well, you may drive more customers to look for it and then interact with it. If you drive a better experience you'll likely end up improving deliverability maybe it is a tool, just an indirect one. The examples stored here are clean and beautiful and demonstrate very creative ways to message successfully once you get those eyeballs. Hope you find it useful!"

This is a cool site and I think folks will find it very helpful! Thanks, Jen! DMARC Policies Increase 300% over 2019

Wow, DMARC continues to spread like wildfire! Data from Farsight Security shows that DMARC adoption increased significantly in 2019. Up from 630,000 domains with DMARC in 2018, they now have observed 1.89 million domains publishing a DMARC policy over the past year.

DMARC is a very useful security tool to help prevent malicious and unauthorized use of your domain name in email. You should implement DMARC if you haven't already. And if you have, you're in good company!

Verizon announces new Email Deliverability and Performance Feeds

Sean McWilliams of Verizon (aka AOL and Yahoo) just announced something that they are referring to as "Email Deliverability and Performance Feeds." Click here to read the announcement.

What does it look like? Don't quite know yet. I am hoping it will be a sort of Google Postmaster Tools-like or Microsoft SNDS-like dashboard where one can log in and view engagement-based sender reputation metrics for a given domain name. We will see.

Their new Verizon Postmaster page on the topic suggests that there will be two types of "feeds":
  • "The Placement Feed provides metrics on how many emails from a sender domain are delivered to the inbox, spam, and folders. It also provides metrics for error and complaint counts.
  • "The Campaign Performance Feed provides key metrics such as delivers, opens, reads, glances, skims, deletes, and clicks for a sender domain. Metrics are broken down by sender domain and campaign."
Inbox versus spam folder placement data is a nice touch. Until now, folks needed a tool like 250ok, eDataSource, or Inbox Monitor to denote spam folder placement.

This looks really interesting and I'm really looking forward to learning more about it. Stay tuned!

Receive Email Updates from Spam Resource

People periodically ask me if there is a way that they can receive an email notification whenever a new blog post is posted on Spam Resource. Never really thought much about it, as my focus was on blogging about emails and not sending them, but enough people have asked that I decided it was time to put something together.

Why Email Engagement Is the Holy Grail of Email Deliverability

ActiveCampaign's Robert Colomberti's explains.

This is REALLY good stuff. The date range guidance might change depending on your industry or differences in sales pipeline, and the segmentation guidance gets a bit platform specific, but the core of this is solid.

As far as the bit at the end about using an email validation vendor, that's a whole other discussion. Upfront verification that somebody isn't submitting an invalid address into a form is a good thing, but don't forget that it's not the same as verifying permission. Data validation isn't going to fix a non-permissioned list, for example. That kind of thing is still deliverability killing. (I don't mean to imply that ActiveCampaign says otherwise. I am just making my own voice heard here.)

Apache SpamAssassin 3.4.4 now available

The Apache SpamAssassin Project has just announced the release of version 3.4.4 of the popular spam filter SpamAssassin.

Apache SpamAssassin 3.4.4 is "primarily a security release," but includes various fixes for things like improved carriage return handling for DKIM checks and re-implementing Perl 5.8.x compatibility. Click here to learn more about it and/or download the updated version.

Following best practices for sending to Gmail

Google has updated the Gmail "Bulk Sender Guidelines" page, and it is now called, "Prevent mail to Gmail users from being blocked or sent to spam." Check it out!

(Thanks to the smart folks at Postmark for the tip!)

Is 2020 the year of BIMI?

You might notice that in my "2020: What's next?" post, I didn't mention BIMI.

BIMI, aka Brand Indicators for Message Identification, is the new way to specify what logo or brand avatar a sender wants shown alongside their email messages. (Learn more about BIMI here.)

Showing a logo, avatar or little graphic along side an email message isn't a new thing. Gmail, Yahoo Mail and others have supported some form of logo display for a long time now. But where that logo was sourced from, how it was populated, this wasn't always clear or obvious. Gmail would pull the graphic from a Google Plus profile or Google account. Yahoo Mail would do the same, I found, but it also could pull the logo from other places. It had some sort of internal process that I wasn't privy to.  And there's Gravatar, which is still out there and still (modestly) supported. (And at some point, Microsoft announced something called Brand Cards that never seems to have launched. So I have no idea if anybody ever set up or observed a "brand card" logo in the wild.)

Mashable's wrong (sort of) -- empty your inbox!

Mashable's Alex Perry wrote just the other day that one should never bother to clean out your email inbox. Sort of right, sort of wrong. Me, I'd go crazy if I left 250,000 email messages in my email inbox. His point, though, is that you might as well save everything forever in email, and have it available to search through as needed. That's something I completely agree with. But he misses the point-- you don't have to "leave it in the inbox" to do that. In Gmail, for example, just "archive" it all at some point, and it is still there for you, in "All Mail," and available to be searched, without specifically cluttering up your inbox. So keep all that mail, but empty the inbox out periodically.

Got placed in the Gmail promo tab? You're not alone.

Apparently it happens to Seth Godin, too (click here).

He's got a fix for it, see, but those big meanies at Google won't let him implement it. He's even encouraging you to yell at Google on his behalf. (It turns out, Google is a bit shy about letting third parties have access to fiddle with your Gmail inbox settings. Can't say I blame them for that.)

Europe is different and why this matters for US-based companies

Here's an article from Mailkit's Jakub Olexa explaining how the ISP landscape is different in Europe. This is useful stuff for US-based senders to learn. That chart is especially insightful. Thanks, Jakub!

2020: What's next?

Well, the new year is here. (Along with a new blog template and updated ISP deliverability guides.) What do you think will happen in the deliverability realm in 2020? Here are my first thoughts.

First, DMARC is finally reaching critical mass. No longer an edge-case security feature that your marketing teams ignore, more and more senders finally start to understand that supporting DMARC is easy and should be considered a best practice. DMARC adds complexity to email forwarding, reply handling and mailing list management, so look to experts for assistance if your email use cases would run into any of those realms. But outside of those, DMARC can actually be pretty easy to set up.

