Journal of Applied Epistolary Pedantry · Vol. 1, No. 1 · August 2026

On the Discriminating Power of the Four Canonical Duties Imposed Upon Recipients of Electronic Mail

A Controlled Comparison of 238 Messages

By Jacob . Durham, Independent Researcher, Washington, USA ~10 min read Originally published August 7, 2026.

Abstract

This paper addresses a question that arises whenever an electronic message produces an unwanted outcome: whether the recipient may fairly be said to have failed to exercise reasonable caution. Four duties are ordinarily imposed — verification of sender, inspection of destination, detection of irregularity, and reporting to a competent authority. Each is presented as protective. None appears to have been measured. To test them, the author assembled a controlled corpus of 238 messages drawn from his own accounts: 38 classified as unwanted by the receiving providers, and 200 delivered to an inbox and treated here as the control. Each message was examined for sender-authentication results, for the presence of a destination available to inspection, and for the technique by which any tracking identifier was carried. The results do not support a uniform finding. Sender Policy Framework validation passed on 97.4 percent of unwanted messages and 98.0 percent of control messages, a separation of six-tenths of one percentage point, and is held to carry no discriminating power whatever. DomainKeys Identified Mail and Domain-based Message Authentication separated the groups by 60.5 and 66.9 points respectively and are held to work as designed, subject to a limitation described in § 5.3. The most discriminating measurement identified in this study — the carriage of a tracking identifier within the fragment portion of an address, present in 57.9 percent of unwanted messages and 0.5 percent of controls — appears in none of the four duties. The error underlying the first duty is designated here the Envelope Fallacy.

Keywords: electronic mail, sender authentication, SPF, DKIM, DMARC, fragment identifiers, recipient duty, discriminating power, Envelope Fallacy


§ 1. Issue Presented

Whether a recipient who performs each of the four commonly prescribed verification duties, and who receives from each a result indicating legitimacy, may nonetheless be described as having failed to exercise reasonable caution.


§ 2. Facts Giving Rise to the Dispute

On August 7, 2026, at 18:53 UTC, the author received a message bearing the subject line VINRA TARADO 54. The body consisted of a table of twenty rows under the headings NO, NUMBER, CODE, DATE, VALUE, and GROUP. The values increment. The dates increment. No value in the table refers to any thing.

Forty-seven minutes before the message was sent, a file of one hundred eighty-seven bytes had been uploaded to a commercial object-storage service. That file contained no content. Its sole function was to read a value from its own address and append it to a destination held elsewhere.

The message passed every authentication check applied to it.

The author, being in possession of the message and of an opinion about it, elected to determine whether the checks meant anything.


§ 3. Framing the Question

A duty imposed on a recipient is protective only if discharging it produces different results for messages that should be opened and messages that should not. A check that returns the same answer for both is not a safeguard. It is a ceremony.

The property is measurable and has been measured. Large-scale studies of Sender Policy Framework deployment exist, as do provider reports of authentication pass rates, and the abuse of legitimate platforms to send fully authenticated phishing is documented. See § 9.

What that literature addresses is the configuration of sending domains and the guidance owed to administrators. This paper asks a different question with a different subject: not whether the mechanisms function — they do, and § 5.2 finds them working — but whether the duty imposed on the recipient discriminates. The author found no measurement of that, which is not the same as none existing.


§ 4. Method

4.1 Corpus. The author assembled 238 messages from his own accounts.

Group A, n = 38. Messages classified as unwanted by the receiving providers and held in the spam and junk stores of two independent accounts.

Group B, n = 200. Messages delivered to an inbox and not so classified.

4.2 Group B is a proxy. Inbox delivery indicates that no provider objected. It does not establish legitimacy. The control group is therefore mail treated as legitimate, which is the population against which a recipient’s duty actually operates, and the reader should hold the distinction in mind. § 8 records what was done to test it.

4.3 Measurements. Each message was parsed and examined for the results recorded by the receiving provider for Sender Policy Framework, DomainKeys Identified Mail, and Domain-based Message Authentication; for the presence of any clickable destination; for whether any such destination was accompanied by text a reader could weigh; for the presence of an image map; and for whether any address carried a structured identifier in its fragment portion.

4.4 Handling. No message was executed, rendered, or replied to. No address was requested. The corpus was examined in place.


§ 5. Findings

5.1 The first duty, as to Sender Policy Framework, is inert.

                    Group A      Group B      separation
  SPF pass            97.4%        98.0%          -0.6

Six-tenths of one percentage point, in the wrong direction.

Substantially every unwanted message in the corpus passed. This is not a malfunction. Sender Policy Framework validates the envelope sender — the address given during the delivery transaction — against the sending network’s published record. An operator who controls a domain publishes a record listing the machines that send for it, and then sends from those machines. The check returns pass because the check is correct.

It is answering a question about the envelope. The recipient is asking a question about the letter.

5.2 The second and third mechanisms separate the groups decisively.

                    Group A      Group B      separation
  DKIM pass           39.5%       100.0%         -60.5
  DMARC pass          31.6%        98.5%         -66.9
  all three pass      31.6%        96.5%         -64.9

Every control message carried a valid DomainKeys signature. Fewer than two in five unwanted messages did. These mechanisms work, and the author records that his own prior view — that authentication broadly fails as a signal — was wrong, and was corrected by the measurement rather than by argument.

5.3 The specimen falls within the minority that passes.

The message described in § 2 passed all three checks. It belongs to the 31.6 percent of Group A that does.

The reason is instructive. The mechanisms detect forgery. The specimen was not forged. It was sent by a party holding valid credentials to a legitimate account at an educational institution, signed with that institution’s own key, and relayed through its authorized infrastructure. Every check was correct.

A compromised account is not a forgery. It is an account. The duty operates exactly until the adversary stops pretending and simply signs in, at which point it operates in his favour.

5.4 The most discriminating measurement identified is not among the duties.

                              Group A     Group B     separation
  tracking id in fragment       57.9%        0.5%        +57.4
  clickable, none inspectable    5.3%        0.0%         +5.3
  image map present              2.6%        0.0%         +2.6

A fragment is the portion of an address following the number sign. Fragments are not transmitted to servers; the requesting client retains them and removes them before transmission. An identifier placed there is therefore invisible to the host being reported, and available only to script running in the reader’s own browser.

The measurement separates the corpus by 57.4 points, which invited the objection that it might record a single operator sending repeatedly. It does not.

The 22 messages exhibiting the technique arrived from 22 distinct sending domains — one apiece. Most are disposable, being strings generated in order to be discarded.

The hosts carrying the identifier are not disposable. There were three:

  storage.googleapis.com          40
  s3.ap-south-1.amazonaws.com      2
  us.list-manage.com               2

Google Cloud Storage, Amazon S3, and a bulk-mail provider’s link domain. Twenty-two unrelated senders, converging on three services no recipient can afford to distrust and no filter can afford to block.

The identifier format recurs across operators sharing nothing else. Two messages from unrelated senders, on unrelated services, carried the same cl and un designators in the same segmented shape. This is not convergent invention. It is a tool being sold.

The finding is therefore narrower and worse than the raw rate suggests. The discriminating signal is not the fragment. It is reputable object storage employed as a redirection layer, with the identifier lodged where that storage provider’s records cannot reach it. The reputation is borrowed from the host, and the evidence is withheld from the same host, by the same design decision.

5.5 The author’s specimen is unrepresentative of the corpus.

The image-map technique described in § 2 was present in 2.6 percent of Group A. That is one message. It is the specimen.

The author records this because the alternative is to generalize from a grievance, which is the error this journal exists to examine.


§ 6. The Envelope Fallacy

6.1 Statement. The Envelope Fallacy is the treatment of a verified envelope as a verified contents.

6.2 Character. The error is not one of reasoning but of scope. Sender Policy Framework answers its question correctly and completely. The fallacy lies in the recipient having been taught that it answers a different one.

6.3 Corollary. Where a check returns pass for 97.4 percent of unwanted messages and 98.0 percent of wanted ones, instruction to perform that check conveys no information to the recipient while transferring responsibility to him.


§ 7. Holding

The four duties are not of uniform value and should not be taught as though they were.

The first duty, as to Sender Policy Framework, conveys nothing. As to DomainKeys and Domain-based Message Authentication it conveys a great deal, and fails precisely in the case of a compromised account, which is the case the recipient is least equipped to detect and the sender’s own institution most.

The second duty presumes a destination rendered for inspection. In 5.3 percent of Group A no such destination existed.

The third duty presumes that irregularity accompanies malice. The specimen’s table was clean; its only irregularity was a Spanish insult in the subject line, which the operator evidently did not read either.

The fourth duty presumes that the reported artifact contains evidence of the conduct reported. Where the identifier is carried in the fragment, it does not.

The author holds that a recipient who performs each duty and receives from each an indication of legitimacy has not failed to exercise reasonable caution, and that the failure is properly attributed to the party issuing instructions whose discriminating power has, on this evidence, not been measured.


§ 8. Limitations

The corpus is one person’s mail. Provider classification was accepted as ground truth and not independently verified. At n = 38, a single message in Group A moves a rate by 2.6 points, and § 5.4 and § 5.5 should be read with that in mind. The destination of the specimen was not rendered.

Group B was independently examined for the indicators found in Group A. None was present: no fragment-borne identifier, no image map, and no failure of all three authentication mechanisms. Sixteen messages carried anchor text naming a host other than the one linked; each resolved to the sender’s own mail provider or to a legal footer, and none is reported as a finding. The control is therefore clean with respect to the measurements taken, which establishes the absence of these indicators and not the absence of malice.

The specimen remains in the author’s spam folder, having been placed there approximately one hour after every mechanism designed to evaluate it returned pass.


§ 9. Prior Measurement

The author records the following as prior art, having located it after drafting rather than before, which is the wrong order and is disclosed here for that reason.

∙ Kaeo et al., Lazy Gatekeepers: A Large-Scale Study on SPF Configuration in the Wild, arXiv:2502.08240 — measurement of Sender Policy Framework deployment at scale.

∙ IronScales, When SPF, DKIM, and DMARC All Pass. And the Email Is Still Phishing — documents authenticated phishing sent through legitimate platforms, which is the mechanism described at § 5.3.

∙ Published Domain-based Message Authentication adoption figures, which record that a majority of domains publishing a policy remain at p=none indefinitely. The institution in § 2 is one of them.

The findings at § 5.1 and § 5.3 are therefore replication, not discovery, and are the stronger for it. The observation at § 5.4 — twenty-two unrelated senders converging on three reputable storage services, carrying a shared identifier grammar — the author has not found stated elsewhere, and offers with the sample size in § 8 firmly in view.