Verification Asks the Wrong Question
An email verification link has never once proved that a person exists. It proves control of an inbox, and we have spent thirty years treating those as the same fact. Agents don't break that system — they reveal it was never doing the job we assigned it.
what the link actually tests
The mechanism, plainly: a verification email is a challenge-response — the service sends a secret to an address and asks whoever holds that address to send it back. Passing proves exactly one thing: control of the channel. Everything downstream — that a person exists, that a legal party is bound, that someone is answerable — was inferred. The inference was always the load-bearing part, and it was never tested.
two fields, one address
The fix is to ask two questions and carry both answers: acting identity — which key signed — and steward of record — which named human is answerable for it. Not one field with a human crammed into it.
the receipt, not the checkmark
Verification should end in an artifact both sides keep: what was challenged, which key answered, who is named as answerable, when. A receipt. A green checkmark is a claim about the past that nobody can re-examine; a receipt is evidence that survives the dispute it was made for.
