Posted on

Email authentication as an identity check rather than proof of consent

A perfectly authenticated email can still be unwanted.

That sounds obvious until the green lights start appearing in the headers.

SPF passes. DKIM passes. DMARC passes. The domain aligns correctly. The message came through TLS. Technically, the sender has done a lot right.

What those checks establish is mostly identity and authorization at the domain level.

They do not establish permission from the recipient.

Google’s current Gmail requirements make this distinction visible. Bulk senders must authenticate mail with SPF and DKIM, publish DMARC, and align the visible From domain with authenticated domains. Google separately tells senders to avoid unwanted mail, keep complaint rates low, and provide one-click unsubscribe for promotional messages. See Gmail’s email sender guidelines FAQ.

Those are separate requirements because they answer separate questions.

Authentication asks who is speaking

SPF checks whether the sending server is authorized for a domain.

DKIM verifies a cryptographic signature attached by the sending domain.

DMARC ties authentication to the domain shown to the user and lets domain owners publish handling policies for failures.

These systems are enormously useful against spoofing and impersonation.

If an attacker sends a fake bank message from infrastructure the bank never authorized, authentication can help a receiving system detect the mismatch.

But suppose the real bank sends a promotional message from its real servers using its real domain.

Authentication can correctly say: yes, this really came from the bank.

It cannot say: yes, Leo asked for this offer.

A verified nuisance is still a nuisance

This matters because sender reputation can be mistaken for recipient consent.

A large company can authenticate every message flawlessly and still mail an old address, over-message an inactive customer, misunderstand a signup, or keep sending categories of promotion the recipient no longer wants.

The inverse is also possible. A small legitimate sender can make an authentication mistake while sending mail that subscribers genuinely requested.

Identity and desirability are correlated only indirectly.

To establish permission, investigators need a different evidence trail: where the address was collected, what wording appeared beside the form, whether the person confirmed the subscription, what categories of messages were described, when the permission was recorded, and whether the person later opted out.

The FTC’s CAN-SPAM guidance also makes a useful legal distinction. U.S. federal law generally does not require prior opt-in consent for commercial email, provided the sender follows the law’s requirements and honors opt-outs. See the FTC’s Candid answers to CAN-SPAM questions.

So even lawful, authenticated, and wanted are three different properties.

Spam Empires become easier to study when those properties are not collapsed into one another.

Authentication can tell you a great deal about who sent the message.

It cannot tell you whether the human receiving it ever wanted to hear from them.

Posted on

Purchased mailing lists and the trade in uncertain consent

An email address is easy to sell.

The history attached to that address is much harder to package.

A purchased mailing list may arrive as a tidy spreadsheet containing names, companies, job titles, locations, interests, or demographic labels. What it often does not make obvious is the exact chain of events that supposedly authorized the buyer to contact each person.

That distinction matters because possession of an address and permission to use it are different facts.

The Federal Trade Commission makes an important U.S. legal distinction here. Its CAN-SPAM guidance says the federal law generally does not require prior opt-in consent before sending commercial email, provided the sender follows the law’s requirements and honors opt-outs. But the FTC also warns that purchased lists can be risky because addresses may belong to people who already opted out or may have been collected through unlawful harvesting or dictionary attacks. See the FTC’s Candid answers to CAN-SPAM questions.

So legal ability to send one kind of commercial message is not the same thing as evidence that the recipient asked for it.

The list loses its story as it changes hands

Suppose a person enters an email address to download a report from Company A.

Did the form clearly say Company A would email them? Did it say their address would be sold? Did it identify the eventual buyer? Did it authorize unrelated marketing? Was the permission limited to one topic? Was the box pre-checked? When did this happen?

A CSV containing person@example.com answers none of those questions.

That is why large email platforms often impose standards stricter than the minimum federal rule. Mailchimp, for example, prohibits purchased, rented, and scraped third-party lists under its current audience requirements. See Mailchimp’s audience requirements.

The platform is protecting more than etiquette. Recipients who do not recognize a sender are more likely to ignore, unsubscribe from, or report the message, damaging delivery reputation for everybody sharing the infrastructure.

Consent needs provenance

A meaningful consent claim needs evidence.

Useful records might include the original collection page, the wording shown beside the form, the date and time of signup, what categories of communication were described, whether third-party sharing was disclosed, the identity of the entity collecting the address, and any later opt-out.

Without that provenance, “they were on a marketing list” is circular reasoning.

The Spam Empires problem is not merely that lists became large.

It is that addresses became tradable inventory while the expectations of the humans attached to them were often reduced to a column nobody bothered to include.

Posted on

Deceased people’s simulated personas and posthumous online presence

The internet already contains enormous amounts of the dead.

Photographs remain on social networks. Email archives sit on old drives. Videos preserve voices and gestures. Blogs preserve habits of phrase. Text messages record private jokes and arguments. For a sufficiently documented person, those fragments can now be used to build a system that appears to continue the relationship.

Researchers use names such as griefbot, deadbot, and ghostbot for systems that simulate a deceased person using material left behind during life. A 2026 review in the Journal of Responsible Technology describes deadbots as chatbots whose behavior and appearance are based on a real person who has died. Another 2026 paper argues that consent should cover the creation, operation, and deletion of these systems as well as use of the deceased person’s image and personal information. See “Principles of consent and non-addiction in AI grief bots”.

The technology creates a peculiar kind of online presence: a person can stop producing new testimony while a representation of them continues producing new sentences.

The raw material is evidence; the reply is a simulation

A model trained or prompted with somebody’s letters, recordings, posts, and photographs may reproduce recognizable vocabulary and recurring opinions.

That does not mean the deceased person answered the new question.

The system is generating a response based on surviving material and its own model behavior. It may confidently address events that happened after the person’s death or combine fragments in ways the person never would have chosen.

That boundary matters for historical evidence. An original email is evidence that somebody wrote those words. A recording is evidence that they said something. A generated posthumous reply is evidence about the simulation and its source material, not direct testimony from the dead.

Consent becomes unusually complicated

Living users can stop using an AI product or object to how they are portrayed. A deceased person cannot correct a bad simulation.

Families may also disagree. One relative may experience a griefbot as comforting while another sees it as an unauthorized performance of somebody they loved. The underlying dataset can contain private material involving living people who never agreed to have their messages folded into a posthumous persona.

This is why recent scholarship emphasizes consent, labeling, control, and the ability to delete such systems.

Online population can outlive biological population

Posthumous personas expose a strange problem for any attempt to count “people” online.

An account can continue speaking after the human life that supposedly anchors it has ended. The replies may be interactive, personalized, and stylistically consistent enough to feel like continuing presence.

For Dead Internet Theory, that is more interesting than simply calling the account a bot.

The important distinction is temporal. The human being contributed the archive. The machine contributes the new speech.

A digital afterlife can preserve memory. It can also manufacture statements that look like memory continuing to talk. Those are two very different things, even when they occupy the same profile.