Deliverability briefing, Friday, 4 September 2026

Exchange servers face more throttling and blocking

Microsoft says it will keep throttling and blocking mail from Exchange servers running vulnerable software, tightening the cutoff as it moves toward what it calls the final public update baseline. If your own outbound server is an on-premises Exchange install that's behind on security updates, mail heading to Microsoft 365 inboxes can get slowed or blocked before it lands.

Inbox Rules Index

499 of 499 companies checked, Friday, 4 September 2026

Every morning we look up the published email settings of the same 499 real companies, the kind you send cold email to. This is what they have set up, not a score on your own sending.

88.4%no change
block forged mailthey tell mail servers to junk or bounce anything faking their addressDMARC at quarantine or reject
70.3%
at the strictest settingbounce it outright rather than putting it in spamDMARC p=reject
42.7%
keep a locked sender listmail sent from anywhere off that list fails the checkSPF -all
6.4%
ask for encryptionsome of these refuse mail unless your server has a valid security certificateMTA-STS record published

Today's panel of 499 companies shows 88.4% now block mail that fakes their own address, unchanged from yesterday and up 0.6 percentage points from the 2026-08-10 baseline. That measures how seriously these companies guard their own name, not whether your unauthenticated mail gets through to them.

What this means for your sending

Proofpoint screens more of these companies than anything else, at 33.9%, so it is the filter most of your cold email actually meets. 6.4% ask senders for an encrypted connection, so an expired or mismatched certificate on your sending server can stop mail reaching them at all. 2.4% cannot receive email at all, which is dead weight on any list that includes them. The rest is about how these companies stop others forging their address. It is a good sign of how seriously they run email security, but it is not what decides where your mail lands: that is judged against your own domain's records.

Whose spam filter your email meets

Proofpoint33.9%
Microsoft 36526.1%
Google Workspace18.8%
Their own servers, or unknown9.6%
Mimecast4%
Cisco Secure Email3.8%

Proofpoint screens about one in every 3 of these companies, more than any other filter. This is the software that reads your email before a person does, and it is the part of this briefing that most directly decides whether you land.

Which industries guard their name hardest (companies checked)

Software (126)97.6%
Finance (54)94.4%
Services (28)92.9%
Healthcare (47)89.4%
Logistics (17)88.2%
Retail (50)88%
Travel (25)88%
Energy (24)87.5%
Media (26)84.6%
Telecoms (30)80%
Industrial (44)79.5%
Schools and universities (28)57.1%

Software guards its name hardest: 97.6% block mail faking their address. Schools and universities least, at 57.1%, a gap of 40.5 points. A high number means that industry runs email security tightly, so expect your own setup to be looked at more closely there.

All 499 of the 499 companies we check answered today. The same real companies every morning, looked up in public DNS. This is what the people you email have set up, not a score on your own sending.

What happened

Microsoft extends throttling for vulnerable Exchange serversAnnounced by the provider

The Microsoft Exchange Team Blog confirms the company keeps tightening which Exchange Server versions are allowed to send into Exchange Online, moving now toward what it calls the final public update baseline. Servers running older, unpatched builds get throttled or blocked, a policy that's been in place for several years already. If your outbound cold email goes out through an on-premises Exchange server, get it patched. Microsoft 365 fronts 26.1% of the 499 companies we measure, so a throttled sending server can quietly choke off a real share of your reach into their inboxes.

Source: Microsoft Exchange Team Blog

Outlook and Teams keep crashing on Arm-based Windows PCs

The Register and BleepingComputer both report that updates issued since August's Patch Tuesday are crashing Teams and the New Outlook app, and in some cases stopping them from launching at all, on Arm-based Windows PCs. BleepingComputer says Microsoft is working on a fix. If a prospect on an Arm-based Windows machine doesn't open your message today, this bug is a more likely explanation than a problem with your sending.

2 outlets: The RegisterBleepingComputer

What these numbers mean

Will the Exchange update block my cold email to Microsoft 365 companies?

Only if your own outbound server is a vulnerable, unpatched on-premises Exchange install, according to the Microsoft Exchange Team Blog. Companies sending from other setups aren't affected. Microsoft 365 fronts 26.1% of the 499 companies we measure, so it's worth checking your server's patch level.

Why isn't Outlook opening for my prospect today?

The Register and BleepingComputer report that updates since August's Patch Tuesday are crashing Teams and the New Outlook app on Arm-based Windows PCs. Microsoft is working on a fix, per BleepingComputer. It's a client-side bug, not a sign your email failed to deliver.

What does today's 88.4% figure actually tell me?

It shows 88.4% of the 499 companies we track now block mail that fakes their own address, unchanged from yesterday and up 0.6 percentage points from the 2026-08-10 baseline. That measures how they protect their own name, not whether your unauthenticated cold email gets through to them.

Get this in your inbox every morning

One email a day: what changed in mailbox provider rules overnight, and the day's DMARC measurement. Free, and one click to stop.

We use your address to send this briefing and nothing else. Unsubscribe from any email.

Check your own sending