See the stars

OpenMail Identity Specification

Home / OpenMail Identity / OpenMail Identity Specification

OpenMail Identity

An Open Infrastructure for Portable Email Addresses


OpenMail Identity is an open infrastructure for portable email addresses based on a simple principle: an email address belongs to the addressee, not the provider. The specification separates persistent email identity from the mailbox, hosting service, and infrastructure used to deliver messages.

OpenMail Identity enables individuals, organizations, and other authorized entities to retain their email addresses while changing providers, hosting services, mailboxes, or delivery infrastructure. The address remains the persistent identity while the provider becomes a replaceable service.

The specification is designed around modularity, interoperability, provider independence, security, trust, continuity, and long-term ownership. Core modules define the essential identity and portability framework, while optional plugin modules extend the system for specialized use cases.


Core Modules

Address Identity Module

The Address Identity Module defines the persistent identity represented by an email address.

Features include:

  • Persistent email address identity
  • Provider-independent address recognition
  • Unique address identification
  • Address ownership association
  • Address lifecycle management
  • Address status management
  • Identity continuity across provider changes
  • Separation of address identity from mailbox infrastructure

Address Ownership Module

The Address Ownership Module establishes that the email address belongs to its authorized addressee rather than to the provider delivering the mail.

Features include:

  • Ownership establishment
  • Ownership verification
  • Ownership records
  • Ownership authorization
  • Ownership transfer
  • Ownership recovery
  • Delegated ownership
  • Ownership history
  • Protection against provider claims of address ownership

Routing Module

The Routing Module determines where messages addressed to a persistent email identity should be delivered.

Features include:

  • Provider-independent routing
  • Routing resolution
  • Destination management
  • Routing updates
  • Routing verification
  • Failover routing
  • Temporary routing
  • Routing continuity
  • Routing history
  • Multi-destination routing support

Portability Module

The Portability Module enables an email address to remain unchanged when its provider changes.

Features include:

  • Provider portability
  • Provider independence
  • Address transfer
  • Transfer authorization
  • Transfer verification
  • Transfer confirmation
  • Transfer status tracking
  • Transfer continuity
  • Provider exit support
  • Address release
  • Protection against portability obstruction

Transfer Authorization Module

The Transfer Authorization Module controls requests to move an address from one provider to another.

Features include:

  • Authorized transfer requests
  • Transfer credentials
  • Transfer authentication
  • Ownership confirmation
  • New provider authorization
  • Existing provider notification
  • Transfer expiration
  • Transfer cancellation
  • Transfer status
  • Protection against unauthorized transfers

Continuity Module

The Continuity Module ensures that an address remains usable during provider changes, service interruptions, or infrastructure transitions.

Features include:

  • Transition routing
  • Temporary forwarding
  • Delivery continuity
  • Provider transition support
  • Service interruption handling
  • Routing preservation
  • Address availability monitoring
  • Recovery routing
  • Continuity status

Provider Independence Module

The Provider Independence Module separates the permanent identity of an email address from the service provider responsible for delivery.

Features include:

  • Provider-neutral identity
  • Replaceable delivery providers
  • Provider-independent ownership
  • Provider-independent routing
  • Provider transition support
  • Provider exit requirements
  • Protection against provider lock-in
  • Separation of identity and infrastructure

Security Module

The Security Module protects address ownership, portability operations, routing changes, and identity records.

Features include:

  • Transfer authentication
  • Multi-factor authorization
  • Ownership credentials
  • Recovery credentials
  • Unauthorized transfer protection
  • Provider compromise protection
  • Security event recording
  • Security notifications
  • Key management
  • Security auditing

Trust Module

The Trust Module establishes mechanisms for determining whether an address, provider, ownership claim, transfer request, or routing change can be trusted.

Features include:

  • Ownership verification
  • Provider verification
  • Transfer verification
  • Cross-provider trust
  • Delegated trust
  • Trust policies
  • Trust records
  • Trust revocation
  • Provider reputation separation
  • Address reputation separation
  • Trust auditing

Interoperability Module

The Interoperability Module defines common behaviors that allow participating providers and services to recognize and process portable email identities.

Features include:

  • Provider interoperability
  • Address portability interoperability
  • Ownership record interoperability
  • Routing interoperability
  • Transfer interoperability
  • Security interoperability
  • Trust interoperability
  • Conformance requirements
  • Compatibility between participating implementations

Audit and Provenance Module

The Audit and Provenance Module provides verifiable records of important changes affecting an email identity.

Features include:

  • Ownership history
  • Transfer history
  • Routing history
  • Provider history
  • Authorization records
  • Security event records
  • Provenance verification
  • Audit records
  • Audit export
  • Change verification

Optional Plugin Modules

Mailbox Migration Module

Provides portability for the mailbox associated with a persistent email identity.

Features include:

  • Mailbox migration
  • Message migration
  • Migration validation
  • Migration status
  • Migration continuity
  • Migration verification

Mailbox Export Module

Provides mechanisms for exporting mailbox content independently of the email address.

Features include:

  • Message export
  • Metadata export
  • Folder export
  • Label export
  • Contact export
  • Archive export
  • Export verification

Mailbox Import Module

Provides mechanisms for importing mailbox content into a new provider or service.

Features include:

  • Message import
  • Metadata import
  • Folder import
  • Label import
  • Contact import
  • Archive import
  • Import verification

Alias Module

Provides portable aliases associated with a primary email identity.

Features include:

  • Alias creation
  • Alias ownership
  • Alias portability
  • Alias routing
  • Alias retirement
  • Alias recovery

Delegation Module

Allows an authorized person or organization to act on behalf of an email identity without transferring permanent ownership.

Features include:

  • Delegated access
  • Delegated routing
  • Delegated administration
  • Permission management
  • Delegation expiration
  • Delegation revocation
  • Delegation auditing

Organizational Identity Module

Supports portable email identities owned and managed by organizations.

Features include:

  • Organizational addresses
  • Departmental addresses
  • Role-based addresses
  • Shared addresses
  • Employee transitions
  • Administrative delegation
  • Bulk address management
  • Organizational ownership

Succession Module

Provides mechanisms for managing email identities when an owner becomes unavailable or transfers authority.

Features include:

  • Succession authorization
  • Recovery beneficiaries
  • Estate transfer
  • Ownership succession
  • Succession verification
  • Succession auditing

Privacy Module

Provides privacy-preserving mechanisms for ownership, routing, verification, and portability.

Features include:

  • Minimal disclosure
  • Private ownership verification
  • Private routing
  • Metadata protection
  • Selective disclosure
  • Anonymous verification where appropriate

Cryptographic Ownership Module

Provides cryptographic mechanisms for proving control over an email identity.

Features include:

  • Cryptographic ownership credentials
  • Key-based identity verification
  • Ownership signatures
  • Transfer authorization signatures
  • Key rotation
  • Key recovery
  • Key revocation

Reputation Module

Separates the reputation of a persistent email identity from the reputation of any particular provider.

Features include:

  • Address reputation
  • Provider reputation
  • Reputation history
  • Reputation portability
  • Reputation verification
  • Reputation separation
  • Reputation revocation

Disaster Recovery Module

Provides continuity mechanisms for email identities during major provider or infrastructure failures.

Features include:

  • Disaster recovery routing
  • Emergency provider selection
  • Recovery destinations
  • Redundant routing
  • Recovery verification
  • Address restoration
  • Continuity testing

Provider Failure Module

Provides mechanisms for maintaining address continuity when a provider becomes unavailable, fails, shuts down, or ceases operations.

Features include:

  • Provider failure detection
  • Emergency routing
  • Provider exit procedures
  • Address recovery
  • Ownership recovery
  • Service transition
  • Recovery verification

Specification Branding License (SBL)

Standard

Optional


License & Notice Requirements

OpenMail Identity is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

By contributing to any Open Arsenal project, you agree that your contributions will also be released under this license.

Please note the following:

  • All contributions must comply with the AGPL-3.0+ terms.
  • Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to: Roxanne Ardary and roxanneardary.com.
  • OpenMail Identity specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
  • The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update notice.md.
  • When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
  • Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.

For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.


Notice – OpenMail Identity

Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.

Contributors

This file tracks contributors and their specific contributions to the project.

  • Roxanne Ardary, roxanneardary.com – September 15, 2026
    Created the repository for OpenMail Identity and developed the specification for an open infrastructure for portable email addresses.
  • [Add other contributors here] – [Date]
    [Describe contribution in one sentence]

License – OpenMail Identity

This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

Key Points

  • You are free to use, modify, and distribute the code.
  • All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
  • The software is provided “as is,” without warranty of any kind.

For the full license text, see GNU AGPL-3.0 License.