How's that going to work with forwarding, virtual user tables, and
alias expansions?
(a) recipient has to know (and tell the system) which addresses he expects forwarded e-mail from--just like with today's spam filters.
(b), (c) receiving MTA has to take its aliases and virtual user tables into account when checking the signatures on e-postage.
And how will it avoid leaking information when
someone is BCC'd?
Use a one-way hash.
mathew