[Secdispatch] SECDISPATCH agenda request (IETF 126): Email Verification Protocol — dispatch guidance on venue
Dick Hardt <dick.hardt@gmail.com> Wed, 17 June 2026 11:34 UTC
Return-Path: <dick.hardt@gmail.com>
X-Original-To: secdispatch@mail2.ietf.org
Delivered-To: secdispatch@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6ABE1102B2F74 for <secdispatch@mail2.ietf.org>; Wed, 17 Jun 2026 04:34:10 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1781696050; bh=J33DOjZda2BScZeogofplnO2WoWGftMSJg0E83zAXZo=; h=Reply-To:From:Date:Subject:To:Cc; b=TeCdnemuJNF6zj3IxmWu2b5MfmI/DRh8lP8zRvVvtSyS8ACNR7NzafDayM40XwvnF obbhfAidr/A0xy6tYv0Q5h7QxCUrbbXkm4/0X7UZsr9MHWIsQFNFbTFXUbkKVKkJ6z iqc0Gw9+baT2MActW1bHFbHIXzAWsgfI7HlMQZtQ=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id t7q2AOkrgIzI for <secdispatch@mail2.ietf.org>; Wed, 17 Jun 2026 04:34:08 -0700 (PDT)
Received: from mail-ot1-x335.google.com (mail-ot1-x335.google.com [IPv6:2607:f8b0:4864:20::335]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 98E67102B2F6D for <secdispatch@ietf.org>; Wed, 17 Jun 2026 04:34:08 -0700 (PDT)
Received: by mail-ot1-x335.google.com with SMTP id 46e09a7af769-7e701435806so4937391a34.0 for <secdispatch@ietf.org>; Wed, 17 Jun 2026 04:34:08 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1781696048; cv=none; d=google.com; s=arc-20240605; b=Rihd98TlaXLZCU/9L/it2rfFdYXiaUddrIc/n8i0tXSl3rTcEjpnm9f6Wwdi82WQh3 6S1UO1MCEgM61AbmOM4s1arfI/CMXKAt/0blzgg5ZBscMFI+Lg1Lnyy5fFPFYe5rdD1K kCtqFqIwl3JTiLQf/28wVCYXTowwUmemL04j2N22AEFa0nVVr+wfmU9u70k5z1XbVWxs tAkIkQIIls9Ugwtoe3BaGc4DhQH4BuG54RdCJxv4xUNwKNB4phwGkgfW1WB40ajk7BCE rvoCMMTClIfSNnD2VpuQIXik6gjF8Uurw5Y7NGOGVDjb3kzbs4guJAIUiBDJ1B/1/Kff 2X0A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:reply-to:mime-version :dkim-signature; bh=s5aJHnYb7H6nb1XCl0KFwRhH17Py4xtsqNdgU9q1s54=; fh=bj8JiVhuSpac2Rtze2pfRiMKcjfZD7kJpQ5dO67Gpc8=; b=SxwJoB2qiV1B1d9Uc4rU8QWY0jyVuk+OX9H5MYZWRYK0HyVIsqlGa1/iTh7OaOP4bf EQGEfYzja4DhWuMSDzC4CUsGAPfiVrCk7s2SuX3CAzlrOSVgkH0FcGGPoDV8SJIljudu /nQY/p1GdfjdnNrUsVbQwQCSnE1gBT4Mk7rE409Z6DKNCHqT9Z+kRzWxgOzCrNtugAbs GU8tMEgKyXUU1uAXWfc4aE9Bq68iBPLQMtPVzRXZdBfrufTLnUDgcbr/PVcbvhTQFNdM h8G9DTOWZ+7lyht+tk0PemydgfqWXrE1Pam1YzixzeycESKEhNW56/X/dEwkG7VuTn8m Fncg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781696048; x=1782300848; darn=ietf.org; h=cc:to:subject:message-id:date:from:reply-to:mime-version:from:to:cc :subject:date:message-id:reply-to; bh=s5aJHnYb7H6nb1XCl0KFwRhH17Py4xtsqNdgU9q1s54=; b=sLUPydfzrTfKUUs/R/gY4RDgm0cqBsQuAzUPC8QDRjbFX4CxePaqwSG55NFnFb8STc BIp32FVkdp8OVNlcCgJBvt3R97RvDP3nHV8DPLHWt3ugbhWlsY0ATsx6BkFfoZql7iuF UFNyBCSIa+sU7QOsgE1e3gT3CvKitVRJQioT8vx8uwtqIh5iNmJfeDDVtXfTHKJZIX8s hV7Ctq2l2E24+BL1wmAvR3eLPrKPRgtcczEJ++aIldpoZ99LOvasH/dRVsnpiYuFvTNJ EQOgvK9Ww/BdkFvJlL90lwVbIlZC56mA1TcIUE65ygLp0FXvcQt7TYZWwpRIH+Cmg/mv nDuA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781696048; x=1782300848; h=cc:to:subject:message-id:date:from:reply-to:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=s5aJHnYb7H6nb1XCl0KFwRhH17Py4xtsqNdgU9q1s54=; b=dG+ZxYH3DDIyF6yeU5SiF99xAp4HjiDQJ8RexoAr4TaRe6NBoB3M/JAYOsY7TLpovO 2MuPfvQ69c+sSbIj6m8ABIQJ5XQ7qDeHgWr5c61JZUpN0V71uGCZSKz3lMw98q6MYa/a 9HszgYYpPjraLJKR3mgDAQ0bPqaI6YaD2/+HWjk+t77TPeU6Vqb6BSRs1wgRFNMAwUAE JApgg2fwtzQ7rD0frdWUIKJ/j94WxM8qV46NqGiFJzWn4ztYMHhQNTM08I5XTLvgnD+0 hFx1SsEDtyOFBIXWRoL0RdUV4oEMLn/vSYVAZjjKkt2+0suxWPTQ/T/o1cXEH0+x0dcG ROjA==
X-Gm-Message-State: AOJu0YySb06T67QwtaTHWQncVI2KKvdoUKqharEf8XqFFXS5ElRtzr3t OB8WE9WobQ0M9ivme8Cor8e+C6ZDppJDw2WIotUwTZAvPzEkZVyoiWhaUzWsrlwbthuH2CdAhVW fi1lxhXvz4VKSIKz7L6F/3PDr/cDMoUdqZ2b6
X-Gm-Gg: Acq92OGwh+tWq3QrWtDQnnT8+Pww8GPYgrf/hCU5xU10WYLyo03/HYUsSrE7BSop+2i AqfCaTACKwcO/wz4SGYUrEtYc2hbIVZ00sflY4j1SyIFHCadv+Y8PgdO3z5piq/AMlW+EGJViyw GZPWut5JbSQqUZL56AG3436kR2hne9T3J5L9CxY0csn7nyb2QeAIXtnODow1MfO0T+VfFSXM4r5 CVHvdthAANtveZRRgIWpeo0yOOMl1Q5+WZ6TTFsfNm8B0U24v6QUh2fG8NftRlIqqdle+Nr2LS4 5lzikIGRncGDBoKNzJ5SixX8CcFeo2KFF5rNx4rd
X-Received: by 2002:a05:6830:6a89:b0:7dc:db3c:1d82 with SMTP id 46e09a7af769-7e90b30d07fmr3272029a34.10.1781696047740; Wed, 17 Jun 2026 04:34:07 -0700 (PDT)
MIME-Version: 1.0
From: Dick Hardt <dick.hardt@gmail.com>
Date: Wed, 17 Jun 2026 12:33:31 +0100
X-Gm-Features: AVVi8Cdgvf-t1XygMaD6AHCqSXQBb91uwJKpkn3mkssoO23bRDO31ObLlamhCww
Message-ID: <CAD9ie-s0YMfLtu9LCSxV2qwMn97RPoqsdezVtYMe=5CTNyFbOw@mail.gmail.com>
To: IETF SecDispatch <secdispatch@ietf.org>
Content-Type: multipart/alternative; boundary="00000000000005f9530654717054"
Message-ID-Hash: IEHQGM2UOSDH5OHKVVFXIBBBYYNTXCDH
X-Message-ID-Hash: IEHQGM2UOSDH5OHKVVFXIBBBYYNTXCDH
X-MailFrom: dick.hardt@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-secdispatch.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Daniel Kahn Gillmor <dkg@fifthhorseman.net>, Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Reply-To: Dick.Hardt@gmail.com
Subject: [Secdispatch] SECDISPATCH agenda request (IETF 126): Email Verification Protocol — dispatch guidance on venue
List-Id: Security Dispatch <secdispatch.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdispatch/yDoXHgChc_g0UDf8j2j-g9UR7Rw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdispatch>
List-Help: <mailto:secdispatch-request@ietf.org?subject=help>
List-Owner: <mailto:secdispatch-owner@ietf.org>
List-Post: <mailto:secdispatch@ietf.org>
List-Subscribe: <mailto:secdispatch-join@ietf.org>
List-Unsubscribe: <mailto:secdispatch-leave@ietf.org>
Hi SECDISPATCH chairs, I'd like to request an agenda slot at IETF 126 (Vienna) to dispatch new work: the Email Verification Protocol (EVP). I'm looking for the WG's help identifying the right home (or homes) for it, as it spans several areas. **Problem statement.** Verifying that a user controls an email address today relies on out-of-band OTPs or "magic links." The user has to leave the site, dig the code out of their inbox, and come back. This adds friction and conversion loss, and it is phishable — a malicious site can relay an OTP in real time. **What EVP does.** EVP lets a browser verify email control cryptographically, without sending any email. It uses a three-party model: a verifier (the site), the user agent (browser), and an issuer (the email provider). The browser obtains a signed Email Verification Token from the issuer, binds it to the verifier's origin and a form nonce, and returns it. The verifier checks the signature, origin, and nonce — no inbox round-trip, and the issuer is blinded to which verifier the user is interacting with. **Why now (evidence of interest).** This work started as a W3C incubation and was deployed by Chrome behind a flag and by Google for gmail.com users that were whitelisted. After significant user research, a Google Chrome origin trial is beginning shortly. Based on W3C TAG feedback, the specification has been divided into the W3C Email Verification API that defines the browser APIs, and the IETF Email Verification Protocol that defines the browser and issuer interactions. The Chrome origin trial will last 3 - 6 months, and changes are welcome in that period, and the IETF had an opportunity to provide feedback, which is exactly why I want to engage the community now rather than present a fait accompli. - I-D: draft-hardt-email-verification (Hardt, Goto) https://dickhardt.github.io/email-verification/draft-hardt-email-verification.html - W3C WICG companion (browser API): https://wicg.github.io/email-verification/ **The dispatch question.** EVP deliberately reuses existing building blocks, and that's the crux of where it should live: - The token is an SD-JWT with key binding (EVT + KB-JWT) — credential-format territory that overlaps SPICE / OAuth. - Issuer discovery uses DNS delegation. - Requests are authenticated with HTTP Message Signatures and a Fetch metadata request header — httpbis territory. I am genuinely of the right venue and am not wedded to any single WG, or for it to be adopted by a WG. I'd welcome dispatch's read on whether this belongs in one WG, warrants a BoF, or should be AD-sponsored. The goal is to find the home that gives this the best review on a timeline that can still shape deployment. **Ask.** ~10–15 minutes at IETF 126 for a problem statement and venue discussion. /Dick