Deliverability briefing, Monday, 10 August 2026
A Klaviyo sign-up bug may have shown saved passwords to advertisers
TechCrunch reported today that a bug in Klaviyo's sign-up forms may have handed saved passwords to advertisers, and four more outlets carried it within hours. Nothing here changes how your mail is authenticated. It is worth ten minutes anyway, because the forms in question sit on ordinary company websites, and one of them may be yours.
Inbox Rules Index
Measured Monday, 10 August 2026
Today's panel reading: 88% of the 499 business domains measured publish a DMARC policy that tells mailbox providers to act on a failure, and 70.3% are at the strictest setting. Strict SPF is a long way behind at 43.2%. If you send on a client's behalf, assume the receiving side is enforcing and that a misaligned record will cost you the inbox.
Who filters their mail: Proofpoint 33.9%, Microsoft 365 25.9%, Google Workspace 18.7%, Self-hosted or other 9.8%.
498 of 499 panel domains resolved today. A fixed panel of real business domains, measured every day over public DNS. This is a measurement of the domains a sender emails, not of Emailchaser customer sending data.
What happened
Klaviyo sign-up forms may have leaked saved passwords
TechCrunch reported that a bug in Klaviyo's sign-up forms could put a password saved in the browser into a field that advertisers were able to read. TechRepublic described the same bug as exposing passwords to ad trackers. Klaviyo is a marketing platform, so those forms are embedded on ordinary company websites rather than on Klaviyo's own, which is what makes this bigger than one vendor's bug. For a cold email sender there is nothing to fix in SPF, DKIM or DMARC over this. The question it does raise is what every third-party form on your own site is collecting, and who else can read it once a browser fills the fields in automatically.
5 outlets: TechCrunchZamin.uzМежа. Новини України.whalesbook.comTechRepublic
Questions senders asked today
Does the Klaviyo bug affect my email deliverability?
No. This is a web form problem, not a sending or authentication one. Your SPF, DKIM and DMARC records are untouched by it, and no mailbox provider scores your sending on what a form on your website leaked.
How many business domains enforce DMARC right now?
88% of the 499 domains on the panel publish a DMARC policy of quarantine or reject, measured today, and 70.3% are at reject, the strictest setting. Only 1.2% publish no DMARC record at all, so an unauthenticated sender is now the visible exception rather than one of the crowd.
Is a strict SPF record still worth setting up?
Yes, and it is where most domains are still weak. Only 43.2% of the panel publishes a strict SPF record, against 88% that enforce DMARC. Tightening SPF is the cheaper of the two to fix and it is the one your sending is most likely to be failing on.
Get this in your inbox every morning
One email a day: what changed in mailbox provider rules overnight, and the day's DMARC measurement. Free, and one click to stop.
We use your address to send this briefing and nothing else. Unsubscribe from any email.