Deliverability briefing, Monday, 10 August 2026

A Klaviyo sign-up bug may have shown saved passwords to advertisers

TechCrunch reported today that a bug in Klaviyo's sign-up forms may have handed saved passwords to advertisers, and four more outlets carried it within hours. Nothing here changes how your mail is authenticated. It is worth ten minutes anyway, because the forms in question sit on ordinary company websites, and one of them may be yours.

Inbox Rules Index

498 of 499 companies checked, Monday, 10 August 2026

On each measurement we look up the published email settings of the same 499 real companies, the kind you send cold email to. This is what they have set up, not a score on your own sending.

88%
block forged mailthey tell mail servers to junk or bounce anything faking their addressDMARC at quarantine or reject
70.3%
at the strictest settingbounce it outright rather than putting it in spamDMARC p=reject
43.2%
keep a locked sender listmail sent from anywhere off that list fails the checkSPF -all
5.8%
ask for encryptionsome of these refuse mail unless your server has a valid security certificateMTA-STS record published

Today's panel reading: 88% of the 499 business domains measured publish a DMARC policy that tells mailbox providers to act on a failure, and 70.3% are at the strictest setting. Strict SPF is a long way behind at 43.2%. If you send on a client's behalf, assume the receiving side is enforcing and that a misaligned record will cost you the inbox.

What this means for your sending

Proofpoint screens more of these companies than anything else, at 33.9%, so it is the filter most of your cold email actually meets. 5.8% ask senders for an encrypted connection, so an expired or mismatched certificate on your sending server can stop mail reaching them at all. 2.4% cannot receive email at all, which is dead weight on any list that includes them. The rest is about how these companies stop others forging their address. It is a good sign of how seriously they run email security, but it is not what decides where your mail lands: that is judged against your own domain's records.

Whose spam filter your email meets

Proofpoint33.9%
Microsoft 36525.9%
Google Workspace18.7%
Their own servers, or unknown9.8%
Cisco Secure Email4%
Mimecast3.8%

Proofpoint screens about one in every 3 of these companies, more than any other filter. This is the software that reads your email before a person does. It says nothing about how any one of them treats your mail.

Which industries guard their name hardest (companies checked)

Software (126)97.6%
Finance (54)94.4%
Services (28)92.9%
Logistics (17)88.2%
Travel (25)88%
Healthcare (47)87.2%
Retail (50)86%
Media (26)84.6%
Energy (24)83.3%
Telecoms (30)80%
Industrial (44)79.5%
Schools and universities (27)59.3%

Software guards its name hardest: 97.6% block mail faking their address. Schools and universities least, at 59.3%, a gap of 38.3 points. A high number means that industry runs email security tightly, so expect your own setup to be looked at more closely there.

498 of the 499 companies we check answered on this measurement. A fixed panel of real business domains, measured every day over public DNS. This is a measurement of the domains a sender emails, not of Emailchaser customer sending data.

What happened

Klaviyo sign-up forms may have leaked saved passwords

TechCrunch reported that a bug in Klaviyo's sign-up forms could put a password saved in the browser into a field that advertisers were able to read. TechRepublic described the same bug as exposing passwords to ad trackers. Klaviyo is a marketing platform, so those forms are embedded on ordinary company websites rather than on Klaviyo's own, which is what makes this bigger than one vendor's bug. For a cold email sender there is nothing to fix in SPF, DKIM or DMARC over this. The question it does raise is what every third-party form on your own site is collecting, and who else can read it once a browser fills the fields in automatically.

5 outlets: TechCrunchZamin.uzМежа. Новини України.whalesbook.comTechRepublic

What these numbers mean

Does the Klaviyo bug affect my email deliverability?

No. This is a web form problem, not a sending or authentication one. Your SPF, DKIM and DMARC records are untouched by it, and no mailbox provider scores your sending on what a form on your website leaked.

How many business domains enforce DMARC right now?

88% of the 499 domains on the panel publish a DMARC policy of quarantine or reject, measured today, and 70.3% are at reject, the strictest setting. Only 1.2% publish no DMARC record at all, so an unauthenticated sender is now the visible exception rather than one of the crowd.

Is a strict SPF record still worth setting up?

Yes, and it is where most domains are still weak. Only 43.2% of the panel publishes a strict SPF record, against 88% that enforce DMARC. Tightening SPF is the cheaper of the two to fix and it is the one your sending is most likely to be failing on.

Get each briefing in your inbox the morning it publishes

One email per briefing: what changed in mailbox provider rules, and the latest measurement from the Inbox Rules Index. Free, and one click to stop.

We use your address to send this briefing and nothing else. Unsubscribe from any email.

Check your own sending