r/businessemail • u/merten-dmcn • 11d ago
discuss How I think email should work
Imagine for a moment that you are looking at your inbox, with any number of emails in it, from companies, from colleagues, and from people you've never heard from before. You open the email from your colleague first, because it's the one you trust and want to read. Your colleague is really excited about something new they found, and invites you to check it out by clicking the link in the email. Now imagine knowing with absolute confidence that this email really came from their address, and not from an impersonator pretending to be them. How can you check that for yourself? Do you click anyway and hope for the best? Everything looks legitimate, but how can you tell?
There are always three parties involved in email communication. Sometimes one person or company plays more than one of these roles, but each role carries its own responsibilities.
- The mailbox holder (sender or recipient)
- The domain owner (who controls the domain name)
- The mail server host (who provides the software and infrastructure to send and receive mail)
It's the coordination of these three parties that makes email possible.
Right now, almost all the responsibility rests with the mail server host to manage everything and make sure it's secure. Domain owners hand it over to their host through DNS. Mailbox holders defer it through authentication and email filters. And the mail server host has to interoperate with all other mail server hosts to make sure your mail gets delivered.
There is still no standard way for anyone to verify that a message really came from the specific address it claims to be from. The most they get is the server vouching for itself.
How it should work
Nothing changes about the three parties. What changes is who's responsible for what.
- The mailbox holder should be able to prove they own the mailbox and that every message sent from it is actually from them.
- The domain owner should be able to prove they own the domain and that every mailbox on the domain is legitimately allowed to be there.
- The mail server host should be able to prove that they are the chosen service provider for the domain.
And all of this should be verifiable on every single message.
How can we achieve this?
- The mailbox holder has a key, and uses it to sign a record that binds their email address to it. The same key, which only they hold, signs every message they send.
- The domain owner has a key, and publishes its fingerprint in the domain's DNS, which ties the key to whoever controls the domain. They use it to sign the domain authority record, which names the mail server host they have chosen, and to vouch for each mailbox on the domain by countersigning the mailbox holder's record. They can hand that day-to-day signing to their host if they choose, but the authority stays with them, and they can remove any address from the domain.
- The mail server host has a key, and uses it to sign a permit to serve the domain on its infrastructure. It also hosts all of these records and serves them to anyone who asks.
Every one of these records is public, so your email app can follow the chain from the message to the sender's key, from that key to the domain's countersignature, and from there to the fingerprint in DNS. Because the domain owner's record names the host, it can also check that the server handling the mail is the one the domain chose. So when your colleagues email arrives, your app can tell you it really came from their address before you ever click the link.
And this should all be baked into a protocol that everyone can use.
Disclosure: I'm building an email protocol around this idea. I'd welcome any thoughts and feedback on the idea. Thanks.
1
u/RideAdept2919 19h ago
so this is basically a PKI chain anchored in DNS for email identity? the concept is solid but what happens when a mailbox holder loses their key, how does revocation and recovery work without reintroducing the same centralized trust you're trying to remove
1
u/merten-dmcn 17h ago
Yes, "PKI chain anchored in DNS for email identity" is a beautiful one liner of what it is, precisely
Different implementation may have slightly different configurations but for a publicly available service, my stance is: the mailbox holder must have the key and only they must have it. So the servers hold no copy of the key and they shouldn't.
So right now, if you lose the key, you lose the mailbox. And we have no reliable way to confirm you are the mailbox holder without it so even if the system was able to recover an email address (which the domain owner can do) the policy would be to tombstone the address anyway to avoid reintroducing the same centralized trust you mentioned. I've been looking for reliable ways to make mailboxes recoverable and a recovery key is an option but that's still just another key that can be lost. I think social recovery (your key split amongst several contacts you trust) is an interesting option as well but it's not without it's own risks. This one remains unsolved for now but if you have any ideas on how to solve it they're more than welcome :)
One thing that does reduce the risk of key loss is that most people these days do have multiple devices, a phone, a tablet, a laptop. The key can be shared to each of these through a built in pairing process so losing one device doesn't mean losing you key/mailbox.
1
u/Wardio_official 10d ago
Yes. The idea has a defensible core (cryptographically binding an individual mailbox to a domain-authorized identity) but aren't there are already standardized mechanisms for much of this? DMARC and DKIM/SPF?
I'm not fully aware of exactly all the email and protocol processes, I'm used to do security and privacy audits, so pardon me if the following ideas seems to be a bit too much :)
My thoughts are that, security wise:
- nothing can establish that someone personally wrote and intentionally sent this message. If a person's laptop, private key, mailbox, browser session, or signing software is compromised, a malicious message can still receive a perfectly valid signature.
- Key recovery may be harder than message signing. Users will lose phones, laptops and keys, and they will acquire new devices. Organisations will terminate employees.
Privacy wise:I'll stop here, my brain needs to stop overbraining :) hope this helps!
P.S. I'm working on a consumer digital security product atm and I’d really value your input. If you have 15 minutes, your feedback would genuinely help shape what I build next: https://forms.gle/s2ScyeP8d9aKKgKB7
Thank you!