6. Built-in full whitelist / greylist / blacklist capabilities. This is almost certainly going to be required generally of networked infrastructure, not just email. As an example: I'm finding I am making increased uses of extensive blocklists for general network and web traffic. Mechanisms for doing this on a generally straightforward, useable, trustable, and effective basis will almost certainly be required.
This includes the ability to selectively-though-intentionally bypass such filters on an occasional basis.The ability to restrict general messaging access to known trusted and vouched sources, to provide for bypass on an occasional basis, to allow third-party vetting (and to specify the trust/distrust level of same), etc., all strike me as necessary. Keep in mind that this applies to any messaging and comms channel, inclusive of postal mail and voice telecoms, both of which are also increasingly subject to nuisance attacks. I see the imminent death of conventional phone systems within a few years if the junk call problem isn't addressed, and most likely the solution to that being a disposal of number-dial-based systems as a resolution, also within a few years. Already, the abandonment of all phone-based comms by Millennials and many Gen-Xers is fairly widely reported.
7. The alternative, generally, to points 3-6 above, is the emergence of one or more exclusive messaging networks, following generally the selective and aspirational founder cohort as mentioned above. Note again that early comms systems tended to reflect this. Letter-writers, in the early 19th century, reflected the 5-25% of populations which were educated and literate. Telegraphs were limited in access to companies and wealthy individuals (historical note: president U.S. Grant learned of his electoral victory in the home of a neighbour in rural Galena, IL, who had a personal telegraph line installed). Telephones were initially uncommon, found in upscale households, a fact still pervasive enough in 1948 to lead to the famous "Dewey Beats Truman" Chicago Tribune headline based on the misleading sampling error of a teleophone-based survey. Long-distance and international dialing were limited through the 1950s and 1960s respectively. Long-distance charges were high through the 1990s (see above: marginal vs. fixed-rate pricing). Email was initially limited to a restricted set of college undergraduate and graduate students, faculty and staff, government departments, and technology-company professionals. The Blackberry was, for a time, a badge of membership amongst a professional elite. Each of these was a selective and aspirational cohort at its founding. The popularity of the media eventually, in virtually every case, killed the appeal of the addressible community, and did so most especially amongst the highly-valued members.
(One of the recurring themes of science fiction authors' essays of the 1960s - 1980s was the issue of postal mail, and the burdens this imposed on various authors. Arthur C. Clarke wrote on this several times, noting that eventually he'd be reduced to having to send only a pre-printed postcard, "Arthur C. Clarke regrets ...".
Attention is fundamentally limited. Rivality is the counterpoint to virality. The greater the reach of a medium, the more intrusive and annoying it is, axiomatically.
8. Standardisation of formats. I've long strongly favoured simple ASCII email. It's been ... amusing and validating to watch this issue be re-hashed with succeeding generations of messaging systems and devices. HTML allows far too many sins, ASCII not quite enough, but the balance seems to be toward simpler. I'd like to see a semantically structured message format emerge that has the concept of headers, emphasis, possibly even links, and perhaps images, but nothing more. I use the term "STML" (structured text markup language), though there's an extant concept of "POSH" (Plain-old Semantic HTML). The products of simple markup languages such as Markdown would generally work, though experience suggests that any markdown format is too much for the masses.
The ability of recipients to specify what messaging formats they are willing to accept, and have this occur as a negotiation at delivery time, strikes me as especially useful. "This recipient accepts only 7-bit ASCII unencoded messages", for example. Or lists of specifically whitelisted file formats, or encoding formats, by sender or sender category (family, friends, business, vendors, government, strangers, etc.). This serves to impose a complexity constraint on what a sender might attempt to deliver. Yes, you can try to send some highly-complex, highly-formatted newsletter, but 99.98% of recipients will reject it at delivery time, after all other checks have been completed.
Note that standardisation also might include the concept of forms-based email, something that's been ... exceedingly poorly supported to date. This is a concept addressed at length in the Kathy Yates article above about business correspondence standardisation. The ability to send an email that structures responses into a specific format (with, perhaps, a catch-all free-form field required) could be immensely useful.
Standardisation might also include calendar, lightweight messaging, voice/video, and other types of exchanges, all of which current messaging systems ... more or less completely fail at.
9. A re-thinking of authentication and validation. The ability to have the sender's identity be locally verified, and potentially cross-checked against multiple third-party systems could be highly useful. Presently, email quite literally allows anybody to claim to be anyone, simply by filling out the appropriate headers or text. A local identity validation would rely on local PKI validation, whist a third-party validation would send credentials to one or more third-party sites for confirmation. This would tremendously reduce the attack vector for misrepresentation, though of course it also produces risks of metadata leakage -- means for validating without divulging who is requesting the validation would help.
Creating one-off identities triggering validations might be an attack on this though -- the validation could only come from a specific recipient, or someone capable of accessign that party's messages. At the same time, one-off identities and their validation might be used as canaries indicating disclosure of private information, contacts lists, or other data.
Attacking the motives for phishing through improved authentication systems would of course also be useful.
I could continue, but let's end here.
(2/end)