There are already preexisting systems for solving this sort of problem. For example the FBI could set up a PGP based certificate authority[1] for email. Then the FBI signs the identities of the podunk police departments ahead of time. All the service providers would need would be the FBI identity (PGP public key) which they would sign once to authorize it and then they would be able to verify emails coming from any of the podunk police departments with no extra work on their part. This example comes with a revocation system that actually would work in this case.
All secret key material would remain under the control of the specific FBI department acting as the certificate authority. No third party involvement would be required.
[1] https://sequoia-pgp.org/blog/2021/05/12/202105-hello-openpgp...