http://lpoaj76nfopd5lpinbskyqtroppamrzhhay3g4vvjm75st6ger34lbyd.onion/posts/2020/08/email-sucks.html
It would have been simple to just implement some TLS client auth or whatever, but no , that would break compatibility with servers that do not support TLS (which should not be a thing anyway, nowadays, mainly due to how simple Let's Encrypt is). Instead it requires some ugly DNS-level hacks (which is insecure if you do not have DNSSEC, which is not commonplace, unlike you may assume, and it typically only works with paid DNS services), such as SPF, DKIM and DMARC, or even just reverse DNS...