<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Microsoft on Daily DMARC News</title><link>https://news.excello.email/tags/microsoft/</link><description>Recent content in Microsoft on Daily DMARC News</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 21 Jun 2026 08:00:00 +0000</lastBuildDate><atom:link href="https://news.excello.email/tags/microsoft/index.xml" rel="self" type="application/rss+xml"/><item><title>All Three Inbox Giants Now Enforce One-Click Unsubscribe -- and the Deliverability Penalty for Getting It Wrong Is a 3x to 7x Inbox Hit</title><link>https://news.excello.email/posts/2026-06-21-one-click-unsubscribe-rfc-8058-microsoft-enforcement-deliverability-gap/</link><pubDate>Sun, 21 Jun 2026 08:00:00 +0000</pubDate><guid>https://news.excello.email/posts/2026-06-21-one-click-unsubscribe-rfc-8058-microsoft-enforcement-deliverability-gap/</guid><description>&lt;p&gt;In February 2024, Google and Yahoo told bulk senders that one-click unsubscribe was no longer optional. Most senders treated it as a Google-and-Yahoo problem and updated their templates accordingly &amp;ndash; or believed they already had it covered because their emails contained an unsubscribe link somewhere in the footer.&lt;/p&gt;
&lt;p&gt;In May 2026, Microsoft completed its own enforcement rollout. The requirement is now active across all three dominant inbox providers. Google, Yahoo, and Microsoft collectively handle the vast majority of personal and business email inboxes in the world. There is no major provider left to wait for.&lt;/p&gt;</description></item><item><title>Ghost-Sender: Why DMARC Cannot Stop Spoofing When Exchange Online Is Misconfigured</title><link>https://news.excello.email/posts/2026-06-18-ghost-sender-exchange-online-dmarc-bypass-hybrid-spoofing/</link><pubDate>Thu, 18 Jun 2026 08:00:00 +0000</pubDate><guid>https://news.excello.email/posts/2026-06-18-ghost-sender-exchange-online-dmarc-bypass-hybrid-spoofing/</guid><description>&lt;p&gt;In early June 2026, Swiss cybersecurity firm InfoGuard Labs disclosed a vulnerability they named Ghost-Sender: a misconfiguration in Microsoft Exchange Online that allows an attacker to deliver email impersonating any sender &amp;ndash; internal or external &amp;ndash; directly to a target organization&amp;rsquo;s inbox while bypassing SPF, DKIM, and DMARC authentication entirely.&lt;/p&gt;
&lt;p&gt;Microsoft was notified on April 21, 2026. By May 29, 2026, the company&amp;rsquo;s Security Response Center had classified the issue as a known architectural limitation rather than a product vulnerability. No platform-level fix has been issued. The responsibility for remediation sits entirely with Exchange Online administrators.&lt;/p&gt;</description></item><item><title>8.3 Billion Phishing Threats in Q1 2026: Why CAPTCHA-Gated Attacks and ClickFix Are Reshaping the Email Security Equation</title><link>https://news.excello.email/posts/2026-05-29-captcha-clickfix-phishing-microsoft-q1-2026-dmarc/</link><pubDate>Fri, 29 May 2026 09:00:00 +0000</pubDate><guid>https://news.excello.email/posts/2026-05-29-captcha-clickfix-phishing-microsoft-q1-2026-dmarc/</guid><description>&lt;p&gt;Microsoft Threat Intelligence published its Q1 2026 Email Threat Landscape Report in late April, and the headline figure is difficult to absorb: 8.3 billion email-based phishing threats detected in the first three months of 2026. That is roughly 92 million per day, every day of the quarter. The raw volume matters less than what the report reveals about how those threats are being delivered and why the delivery methods are changing so rapidly.&lt;/p&gt;</description></item></channel></rss>