<i>Email has identity built in. Email is identity.</i><p>I'm no security expert, but my understanding is that email is pretty flawed when it comes to establishing the true identity of the sender. I guess you could use something like DKIM or SPF, but plenty of people don't have that set up.<p>If you use obfuscated inbound email addresses then it's not really a problem. But, if you're identifying people by their FROM address on a very public inbound address, be aware that it's trivially easy to spoof that.