Writing

How I think email should work

26 Sep 2026

Imagine you're looking at your inbox, with emails from companies, from friends, and from people you've never heard from before. You open the one from your friend first, because it's the one you trust. They're excited about something new they found and want you to check it out, so there's a link. Everything looks legitimate. But how do you know it really came from your friend's address, and not from someone pretending to be them?

If you know email, your answer is probably SPF, DKIM and DMARC. They're widely deployed, and they do prove that the message was sent with the permission of your friend's domain. What they don't prove is which mailbox on that domain sent it. That part is left to your friend's provider, and your email app takes the provider's word for it. Gmail won't let one user send as another, so for a Gmail address that's a safe bet. For a domain whose server lets any account send as any address, the message passes exactly the same checks with nothing behind them.

PGP and S/MIME can sign a message from the mailbox itself, and have been able to for decades, so the signing was never the hard part. What they never had is a dependable way to find the right key for an address, one the domain stands behind, and signing that's on without anyone having to think about it. So almost nobody uses them, and a signature nobody checks doesn't protect anyone.

That gap, between the domain and the person, is what I want to close. I think it can be done with pieces email already has, by changing who is responsible for what.

There are always three parties involved in email communication. Sometimes one person or company plays more than one of these roles, but each role carries its own responsibilities.

  1. The mailbox holder (sender or recipient)
  2. The domain owner (who controls the domain name)
  3. The mail server host (who provides the software and infrastructure to send and receive mail)

It's the coordination of these three parties that makes email possible.

Right now, almost all the responsibility rests with the mail server host to manage everything and make sure it's secure. Domain owners hand it over to their host through DNS. Mailbox holders defer it through authentication and email filters. And the mail server host has to interoperate with all other mail server hosts to make sure your mail gets delivered.

So there's still no standard way for the person reading a message to check that it came from the specific address it claims. The most they get is the domain vouching for it, and every mailbox on that domain looks the same.

How it should work

Nothing changes about the three parties. What changes is who's responsible for what.

  1. The mailbox holder should be able to prove they own the mailbox and that every message sent from it is actually from them.
  2. The domain owner should be able to prove they own the domain and that every mailbox on the domain is legitimately allowed to be there.
  3. The mail server host should be able to prove that they are the chosen service provider for the domain.

And all of this should be verifiable on every single message.

How can we achieve this?

  1. The mailbox holder has a key, and uses it to sign a record that binds their email address to it. The same key, which only they hold, signs every message they send.
  2. The domain owner has a key, and publishes its fingerprint in the domain's DNS, which ties the key to whoever controls the domain. They use it to sign the domain authority record, which names the mail server host they have chosen, and to vouch for each mailbox on the domain by countersigning the mailbox holder's record. They can hand that day-to-day signing to their host if they choose, but the authority stays with them, and they can remove any address from the domain.
  3. The mail server host has a key, and uses it to sign a permit to serve the domain on its infrastructure. It also hosts all of these records and serves them to anyone who asks.

Every one of these records is public, so your email app can follow the chain from the message to the sender's key, from that key to the domain's countersignature, and from there to the fingerprint in DNS. Because the domain owner's record names the host, it can also check that the server handling the mail is the one the domain chose. So when your friend's email arrives, your app can tell you it really came from their address before you ever click the link.

And this should all be baked into a protocol that everyone can use.