but if some baddies have logged into your server and sending messages as you, then DKIM can't save you
so say social media companies want a higher standard of proof that emails are coming from a particular institution, what mechanisms are available that doesn't involve onboarding every individual officer to the subtleties of public key crpyotgraphy?
Network fax systems are more convenient to use than traditional, but still more secure than email because they’ve been designed to be so.
How is that different from techbros trying to claim a loophole for their illegal business, because it's on the internet/through an app/'is a gig job'/on a blockchain?
When legislature hasn't kept up with technology, the only way to fight that behaviour is through lawsuits. Lawsuits have made some headway in dealing with both private, and government malfeasance, here.
but maybe you're right and this problem won't be solved because the person being harmed has no power and the institution in power sees no harm
I am wondering how they get the data back though, unless they demand it is faxed, or sent to another email address. (Or the person replying doesn't notice the different reply-to address.)
Urban legend says people have been fired after forged harassment emails were delivered this way.
Google claims this is a feature, and the sent “label” isn’t meant to mean that it came from your gmail account.
For instance, there could be a corporate service firehosing spam at coworkers on your behalf, and obviously you don’t want to notice that, so it puts it in the sent box.
Is this documented anywhere?
There is, unfortunately, no way to get every police force on the globe to agree to some authentication scheme.