Back to Blog

When Your ESP Gets Hacked and Outlook Tightens Rules: A Security-Driven Approach to Deliverability

Hero image for When Your ESP Gets Hacked and Outlook Tightens Rules: A Security-Driven Approach to Deliverability

What If Your ESP Gets Hacked and Outlook Starts Rejecting Your Mail in the Same Week?

Two events in September 2026, seemingly unrelated, should keep any email operator up at night. On one side, Brevo — a reputable customer engagement platform used by thousands of businesses — suffered a supply chain attack that injected malware into over 100,000 websites. On the other, Microsoft began enforcing new rules that reject unauthenticated mail from any domain sending more than 5,000 messages a day to Outlook addresses. Both events share a common thread: your sender reputation is no longer just about content or list hygiene. It is now about your infrastructure’s security and your domain’s authentication posture — two things most email marketers treat as separate concerns.

If you rely on an ESP for deliverability, you assume they handle the security plumbing. But the Brevo breach shows that assumption is fragile. If you think Outlook’s new rules are just another checkbox exercise, you risk having your mail rejected outright with a 550 5.7.515 error. The tension is real: your ESP can be compromised, and the mailbox providers are raising the bar simultaneously.

The Brevo Supply Chain Attack: How a Trusted ESP Became a Malware Delivery Vector

On September 10, 2026, a threat actor exploited a vulnerability in Brevo’s handling of SAML SSO. They accessed 138 accounts, including one belonging to cryptocurrency storage provider Trezor. From six of those accounts, they sent phishing emails. They exported contacts from 43 accounts. Brevo closed that initial access, but the attackers came back four days later.

On September 14, they used a compromised long-lived Cloudflare API key to deploy a worker. That worker injected malicious scripts into brevo.com, sibforms.com, and three JavaScript files that Brevo’s customers embed into their websites. For roughly five and a half hours, anyone visiting a site using Brevo’s widget could be shown a fake “Cloudflare, verify you are human” page. The trick, known as ClickFix, instructed visitors to paste and run a command on their computer. On WordPress sites embedding a Brevo widget, the script attempted to deploy and run a plugin if the visitor was logged in as an administrator.

Brevo says the malicious worker was active for about five and a half hours. According to cybersecurity firm Sansec, more than 100,000 websites were likely impacted. That is not a small-scale phishing campaign. That is a supply chain compromise affecting the entire customer base of a major email platform.

For email marketers, the implication is brutal. If your ESP gets compromised, your sender reputation takes the hit. The phishing emails sent from Brevo accounts are attributed to the sender domains, not just Brevo. If your domain was used to send phishing emails — even if the ESP was the vector — mailbox providers see those messages as originating from your domain. Your sender score drops. Your deliverability tanks. Months of warming your domain reputation can be undone in hours.

What You Need to Do About ESP Security

Brevo’s post-mortem says the compromised API key was first misused in late August 2026 — two weeks before the attack was detected. That means unauthorized access existed for weeks. Most email marketers do not monitor their ESP’s API key usage or have any visibility into whether their account has been accessed by an attacker. You cannot fix what you cannot see.

  • Audit API key usage weekly. If your ESP provides access logs or API key activity reports, review them. Look for unusual patterns — new IPs, actions at odd hours, unexpected script deployments.
  • Rotate API keys quarterly. Brevo got hit via a Cloudflare API key that was apparently long-lived. Short-lived keys reduce the blast radius.
  • Check your WordPress site for unauthorized plugins. Sansec explicitly warned that sites using Brevo may have been backdoored. If you run a site that embeds any ESP widget, run a security scan. A compromised plugin on your site can serve malware to your visitors and damage your domain’s reputation.
  • Monitor your sending domains for blacklisting. If any phishing emails were sent from your account during a breach, your domain may appear on blocklists. Set up alerts with tools like MXToolbox or Spamhaus to catch it early.

Outlook’s New High-Volume Sender Requirements: Authentication Now Means Rejection, Not Filtering

Microsoft’s new rules are straightforward: any domain sending more than 5,000 messages per day to Outlook, Hotmail, or Live addresses must pass SPF and DKIM and publish a DMARC record aligned with at least one of them. Mail that fails is rejected outright with a 550 5.7.515 error. It no longer goes to junk. It simply does not get delivered.

This is a significant shift. Previously, unauthenticated mail might land in spam or junk, giving you a chance to diagnose and fix the problem. Now it is blocked at the server level. Google’s equivalent threshold is also 5,000 messages per day, so this is not an isolated move. The industry is converging on a standard: if you send at scale, you must authenticate properly.

Why DKIM Alignment Matters More Than SPF

Microsoft requires DMARC alignment with either SPF or DKIM. But if you are sending cold email, DKIM alignment is the safer bet. SPF breaks when mail is forwarded — the envelope sender changes, and the SPF check on the original domain fails. DKIM survives forwarding because the signature remains attached to the message body. If you rely solely on SPF alignment, your mail can fail DMARC when it goes through mailing lists, forwarders, or even some CRM integrations.

Set up DKIM signing on your sending domain. Publish a DMARC record with p=none at minimum while you test. Once you confirm alignment, move to p=quarantine or p=reject. The goal is not just to pass authentication — it is to prevent spoofing. If your domain lacks a proper DMARC policy, anyone can impersonate you. And a supply chain attack at your ESP could result in your domain being used to send malicious mail that you cannot control.

The 5,000 Threshold Is a Moving Target

Note that the threshold counts messages to Outlook consumer domains specifically — not your total send volume. If you send 10,000 messages a day but only 3,000 go to Outlook, you are below the threshold. But that is only true today. Microsoft could lower the threshold next quarter, or apply it retroactively. And Google’s threshold is already the same. Build your authentication infrastructure as if the threshold were zero.

The Double-Edged Sword: Compliance vs. Security

Here is where the two events intersect. Outlook’s new rules demand strict authentication. The Brevo breach shows that even authenticated domains can be weaponized by attackers. If your domain is properly authenticated with DKIM and DMARC, an attacker who compromises your ESP can send authenticated phishing emails from your domain. The authentication actually works in the attacker’s favor — the mail will pass DMARC and land in inboxes because it is technically legitimate from the infrastructure standpoint.

This is not a contradiction. Authentication prevents domain spoofing by third parties. It does not prevent an attacker who has compromised your sending infrastructure from sending mail that looks legitimate. So the same tools that protect your deliverability against Outlook’s rules can be turned against you if your ESP gets hacked.

The practical implication: you cannot outsource security to your ESP and assume authentication alone protects you. You need both layers — strong authentication and active monitoring of your ESP account and sending domains.

What to Do This Week: A Practical Checklist for Cold Emailers

If you run cold email campaigns, here is what needs to happen now:

  • Check your DMARC record. If you do not have one, publish p=none today. Then align it with your DKIM selector.
  • Verify your DKIM signing. Use a tool like DKIMValidator.com. Ensure the signature covers the From header and the body.
  • Audit your ESP’s API key usage. If you cannot view access logs, ask your provider for them. If they cannot provide them, consider that a risk.
  • Set up domain monitoring. Use Google Postmaster Tools or Microsoft’s SNDS to watch for authentication failures and abuse reports.
  • Have a breach response plan. If your ESP is compromised, you need to know within hours, not weeks. That means automated alerts on your sending volumes, blacklist status, and any sudden spikes in bounce or complaint rates.

The Unresolved Tension

The Brevo attack was active for five and a half hours. Over 100,000 websites were exposed. The attackers used a long-lived API key that had been compromised for weeks before detection. Microsoft’s new rules reject mail from domains that fail authentication — but they do nothing to detect that your domain’s authentication infrastructure is being used by an attacker who compromised your ESP.

How do you build a sending infrastructure that is both compliant with mailbox provider requirements and resilient against supply chain attacks? The answer is not simply “use a better ESP” or “set up DMARC.” It requires continuous monitoring, short-lived credentials, and a willingness to treat your ESP as a potential attack vector, not just a delivery service.

Are you auditing your ESP’s security posture as closely as you monitor your email open rates? If not, the next breach may not just affect your inbox placement — it may compromise your entire domain reputation, and with it, every campaign you run.

Keep building your outbound system