It was never allowed. Microsoft just started doing it in their email client and obnoxiously made it default. There was no standards process where anyone spent time considering the potential downsides with the aim of making HTML email practical and secure.
HTML email is just something that people semi-randomly do. It should be rejected/ignored if you are at all concerned about privacy and/or security.