Hacker News new | ask | show | jobs
by MicahWedemeyer 4830 days ago
Email has identity built in. Email is identity.

I'm no security expert, but my understanding is that email is pretty flawed when it comes to establishing the true identity of the sender. I guess you could use something like DKIM or SPF, but plenty of people don't have that set up.

If you use obfuscated inbound email addresses then it's not really a problem. But, if you're identifying people by their FROM address on a very public inbound address, be aware that it's trivially easy to spoof that.