Home / OpenMail Identity / OpenMail Identity Specification
OpenMail Identity
An Open Infrastructure for Portable Email Addresses
OpenMail Identity is an open infrastructure for portable email addresses based on a simple principle: an email address belongs to the addressee, not the provider. The specification separates persistent email identity from the mailbox, hosting service, and infrastructure used to deliver messages.
OpenMail Identity enables individuals, organizations, and other authorized entities to retain their email addresses while changing providers, hosting services, mailboxes, or delivery infrastructure. The address remains the persistent identity while the provider becomes a replaceable service.
The specification is designed around modularity, interoperability, provider independence, security, trust, continuity, and long-term ownership. Core modules define the essential identity and portability framework, while optional plugin modules extend the system for specialized use cases.
Core Modules
Address Identity Module
The Address Identity Module defines the persistent identity represented by an email address.
Features include:
- Persistent email address identity
- Provider-independent address recognition
- Unique address identification
- Address ownership association
- Address lifecycle management
- Address status management
- Identity continuity across provider changes
- Separation of address identity from mailbox infrastructure
Address Ownership Module
The Address Ownership Module establishes that the email address belongs to its authorized addressee rather than to the provider delivering the mail.
Features include:
- Ownership establishment
- Ownership verification
- Ownership records
- Ownership authorization
- Ownership transfer
- Ownership recovery
- Delegated ownership
- Ownership history
- Protection against provider claims of address ownership
Routing Module
The Routing Module determines where messages addressed to a persistent email identity should be delivered.
Features include:
- Provider-independent routing
- Routing resolution
- Destination management
- Routing updates
- Routing verification
- Failover routing
- Temporary routing
- Routing continuity
- Routing history
- Multi-destination routing support
Portability Module
The Portability Module enables an email address to remain unchanged when its provider changes.
Features include:
- Provider portability
- Provider independence
- Address transfer
- Transfer authorization
- Transfer verification
- Transfer confirmation
- Transfer status tracking
- Transfer continuity
- Provider exit support
- Address release
- Protection against portability obstruction
Transfer Authorization Module
The Transfer Authorization Module controls requests to move an address from one provider to another.
Features include:
- Authorized transfer requests
- Transfer credentials
- Transfer authentication
- Ownership confirmation
- New provider authorization
- Existing provider notification
- Transfer expiration
- Transfer cancellation
- Transfer status
- Protection against unauthorized transfers
Continuity Module
The Continuity Module ensures that an address remains usable during provider changes, service interruptions, or infrastructure transitions.
Features include:
- Transition routing
- Temporary forwarding
- Delivery continuity
- Provider transition support
- Service interruption handling
- Routing preservation
- Address availability monitoring
- Recovery routing
- Continuity status
Provider Independence Module
The Provider Independence Module separates the permanent identity of an email address from the service provider responsible for delivery.
Features include:
- Provider-neutral identity
- Replaceable delivery providers
- Provider-independent ownership
- Provider-independent routing
- Provider transition support
- Provider exit requirements
- Protection against provider lock-in
- Separation of identity and infrastructure
Security Module
The Security Module protects address ownership, portability operations, routing changes, and identity records.
Features include:
- Transfer authentication
- Multi-factor authorization
- Ownership credentials
- Recovery credentials
- Unauthorized transfer protection
- Provider compromise protection
- Security event recording
- Security notifications
- Key management
- Security auditing
Trust Module
The Trust Module establishes mechanisms for determining whether an address, provider, ownership claim, transfer request, or routing change can be trusted.
Features include:
- Ownership verification
- Provider verification
- Transfer verification
- Cross-provider trust
- Delegated trust
- Trust policies
- Trust records
- Trust revocation
- Provider reputation separation
- Address reputation separation
- Trust auditing
Interoperability Module
The Interoperability Module defines common behaviors that allow participating providers and services to recognize and process portable email identities.
Features include:
- Provider interoperability
- Address portability interoperability
- Ownership record interoperability
- Routing interoperability
- Transfer interoperability
- Security interoperability
- Trust interoperability
- Conformance requirements
- Compatibility between participating implementations
Audit and Provenance Module
The Audit and Provenance Module provides verifiable records of important changes affecting an email identity.
Features include:
- Ownership history
- Transfer history
- Routing history
- Provider history
- Authorization records
- Security event records
- Provenance verification
- Audit records
- Audit export
- Change verification
Optional Plugin Modules
Mailbox Migration Module
Provides portability for the mailbox associated with a persistent email identity.
Features include:
- Mailbox migration
- Message migration
- Migration validation
- Migration status
- Migration continuity
- Migration verification
Mailbox Export Module
Provides mechanisms for exporting mailbox content independently of the email address.
Features include:
- Message export
- Metadata export
- Folder export
- Label export
- Contact export
- Archive export
- Export verification
Mailbox Import Module
Provides mechanisms for importing mailbox content into a new provider or service.
Features include:
- Message import
- Metadata import
- Folder import
- Label import
- Contact import
- Archive import
- Import verification
Alias Module
Provides portable aliases associated with a primary email identity.
Features include:
- Alias creation
- Alias ownership
- Alias portability
- Alias routing
- Alias retirement
- Alias recovery
Delegation Module
Allows an authorized person or organization to act on behalf of an email identity without transferring permanent ownership.
Features include:
- Delegated access
- Delegated routing
- Delegated administration
- Permission management
- Delegation expiration
- Delegation revocation
- Delegation auditing
Organizational Identity Module
Supports portable email identities owned and managed by organizations.
Features include:
- Organizational addresses
- Departmental addresses
- Role-based addresses
- Shared addresses
- Employee transitions
- Administrative delegation
- Bulk address management
- Organizational ownership
Succession Module
Provides mechanisms for managing email identities when an owner becomes unavailable or transfers authority.
Features include:
- Succession authorization
- Recovery beneficiaries
- Estate transfer
- Ownership succession
- Succession verification
- Succession auditing
Privacy Module
Provides privacy-preserving mechanisms for ownership, routing, verification, and portability.
Features include:
- Minimal disclosure
- Private ownership verification
- Private routing
- Metadata protection
- Selective disclosure
- Anonymous verification where appropriate
Cryptographic Ownership Module
Provides cryptographic mechanisms for proving control over an email identity.
Features include:
- Cryptographic ownership credentials
- Key-based identity verification
- Ownership signatures
- Transfer authorization signatures
- Key rotation
- Key recovery
- Key revocation
Reputation Module
Separates the reputation of a persistent email identity from the reputation of any particular provider.
Features include:
- Address reputation
- Provider reputation
- Reputation history
- Reputation portability
- Reputation verification
- Reputation separation
- Reputation revocation
Disaster Recovery Module
Provides continuity mechanisms for email identities during major provider or infrastructure failures.
Features include:
- Disaster recovery routing
- Emergency provider selection
- Recovery destinations
- Redundant routing
- Recovery verification
- Address restoration
- Continuity testing
Provider Failure Module
Provides mechanisms for maintaining address continuity when a provider becomes unavailable, fails, shuts down, or ceases operations.
Features include:
- Provider failure detection
- Emergency routing
- Provider exit procedures
- Address recovery
- Ownership recovery
- Service transition
- Recovery verification
Specification Branding License (SBL)
Standard
- Fully AGPL-3.0+ compliant system
- Copyleft enforced for network deployments
- Required attribution:
- Roxanne Ardary
- https://www.roxanneardary.com/
Optional
- Specification Branding License (SBL)
- Attribution-free commercial deployment
- Pricing based on scale, usage, and deployment scope
- https://roxanneardary.com/openmail-identity/
License & Notice Requirements
OpenMail Identity is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
By contributing to any Open Arsenal project, you agree that your contributions will also be released under this license.
Please note the following:
- All contributions must comply with the AGPL-3.0+ terms.
- Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to: Roxanne Ardary and roxanneardary.com.
- OpenMail Identity specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
- The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update
notice.md. - When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
- Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.
For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.
Notice – OpenMail Identity
Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.
Contributors
This file tracks contributors and their specific contributions to the project.
- Roxanne Ardary, roxanneardary.com – September 15, 2026
Created the repository for OpenMail Identity and developed the specification for an open infrastructure for portable email addresses. - [Add other contributors here] – [Date]
[Describe contribution in one sentence]
License – OpenMail Identity
This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
Key Points
- You are free to use, modify, and distribute the code.
- All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
- The software is provided “as is,” without warranty of any kind.
For the full license text, see GNU AGPL-3.0 License.
