Now we need a system for associating emails with openids (an email header?). Something like: I provide you my OpenID in the header of my email. You can go to my openid enabled page where I have hashes (or something) of the messages sent to all email addresses. Logging in returns the hashes for the email address connected with your openid. If the hash isn't there the message didn't come from me (or is too old). Has something like this already been done? Is this a bad idea? Could it significantly reduce unwanted email?