The Lying Gatekeeper
Email was built in 1971 to move messages, not to prove who anyone is. This report documents what happened when the digital economy made it the identity layer anyway.
What this report covers:
- The four jobs email was never supposed to have
Universal username, account recovery, action approval channel, and persistent proof of identity over time — four critical identity functions email has been pressed into serving, none of which it was designed for.
- The password reset is email's most dangerous feature
64% of services offer email as the sole password recovery option, which makes control of an inbox a skeleton key to everything downstream of it.
- The MFA paradox
Why multi-factor authentication has not solved the underlying problem when most MFA flows are themselves rooted in the same compromised email addresses.
- The disposable address problem
How a $1.36B disposable email industry enables account fraud from the moment of registration, and why standard validation tools cannot detect it.
- The case studies that should have changed everything
Publicly documented failures — Roku, Norton, and a run of business email compromise incidents — showing the predictable cost of trusting email as identity.
- From static trust to continuous intelligence
What replaces one-time validation: continuous risk assessment at every high-stakes moment in the account lifecycle, rather than a single check at signup.
