SOVEREIGN SEAL ONLINE
AUDIT PROOF
UNIVERSAL IDENTITY PROTOCOL

The missing identity layer for email.

Sovereign Seal adds a DNS-backed, machine-readable identity layer alongside MX, SPF, DKIM and DMARC. A domain can publish its identity, public verification key and visual mark — allowing compatible infrastructure to discover and verify it.

DNS BACKED
Machine-readable identity
PUBLIC KEY
Verification without disclosure
EMAIL CLIENT
Identity can be surfaced
SOVEREIGN SEAL
VERIFIED

SOVEREIGN SEAL

DOMAIN IDENTITY VERIFIED

PROTOCOL SEAL1
IDENTITY DECLARED
PUBLIC KEY PRESENT
AUTHORIZE.EMAIL / IDENTITY PROTOCOL

Introducing the Sovereign Seal.

A new DNS-backed identity layer for email. Connect a domain to a verifiable identity, public key and visual mark — then let compatible infrastructure recognise it.

DNS IDENTITY RECORD _seal.example.com
LIVE
v SEAL1
l
k MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...
TXT DNS SEAL1
DISCOVER
AUTHORIZE.EMAIL
IDENTITY ENGINE
DNS RECORD
PUBLIC KEY
IDENTITY
SEAL
VERIFY
SOVEREIGN SEAL
SOVEREIGN SEAL VERIFIED

Domain identity recognised and cryptographically associated.

WHAT IT MEANS

Email identity you can actually see.

Email authentication normally lives behind the scenes inside DNS records. SPF, DKIM and DMARC can establish important parts of a sender's identity, but that relationship isn't always visible to the person reading the message.

The Sovereign Seal provides an additional identity signal that can be discovered by software, infrastructure and compatible email clients.

DOMAIN IDENTITY VERIFIED
example.com
MX
SPF
DKIM
DMARC
Sovereign Seal Authentication identity recognised
WHAT THE SEAL ADDS

Authentication tells you what happened. Identity tells you who is behind it.

SPF, DKIM and DMARC provide the established foundation of modern email authentication.

Sovereign Seal adds another machine-readable identity signal that can associate a domain with a declared visual identity and public verification key.

05 EMAIL CLIENT Identity can be surfaced
04 SOVEREIGN SEAL Identity + public key + visual mark
03 DMARC Domain policy
02 DKIM Cryptographic signing
01 SPF / MX Mail infrastructure
COMPATIBLE EMAIL CLIENTS

The identity can travel with the email.

The Authorize.email Roundcube plugin can inspect the sender domain, discover its Sovereign Seal record and surface the identity directly inside the mailbox.

EMAIL DNS SEAL ROUNDcube
Roundcube
● ● ●
Reply Forward More
E
Example Company <hello@example.com>
Sovereign Seal Verified domain identity
VERIFIED
Your account notification
SETUP & PROVISIONING

Get your Sovereign Seal.

Generate your identity keys, publish the public identity record in DNS, and let Authorize.email verify the relationship between your domain and its authentication infrastructure.

DNS PROVISIONING
01

Generate your keys

Authorize.email creates a cryptographic identity pair for your domain.

KEY TYPE RSA-2048
PUBLIC KEY DNS / PUBLIC
PRIVATE KEY HELD SECURELY
🔐

Only the public key belongs in DNS. The private key must remain protected.

02

Add the DNS record

Publish the Sovereign Seal identity record at your domain so it can be discovered and verified.

DNS TXT RECORD
_sovereignseal.example.com v=SEAL1; l=https://authorize.email/assets/logo.png; k=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...
v=SEAL1 Seal protocol version
l= Registered identity resource
k= Public verification key
03

Verify your domain

Authorize.email detects the DNS record and validates the published identity against the domain.

AUTHORIZE.EMAIL VERIFIED
example.com
DNS RECORD
PUBLIC KEY
DOMAIN IDENTITY
SOVEREIGN SEAL VERIFIED Sender identity recognised
DETECTED DNS IDENTITY

Sovereign Seal record

● VERIFIED
RECORD _sovereignseal
VERSION SEAL1
IDENTITY authorize.email/assets/logo.png
PUBLIC KEY MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A...
DNS SETUP

Add the Seal to your domain.

Publish a TXT record under your domain's DNS. Authorize.email and compatible infrastructure can then discover the identity record and use the public key for verification.

TYPE TXT
HOST / NAME _seal
VALUE v=SEAL1; l=https://authorize.email/assets/logo.png; k=YOUR_PUBLIC_KEY
!
Your private key never goes into DNS. DNS publishes the public verification key only. The corresponding private key remains under the control of the domain owner or signing service.
KEY ARCHITECTURE

Public key in DNS. Private key stays private.

DNS PUBLIC KEY MIIBIjANBgkqhki... Safe to publish
SIGNING SYSTEM PRIVATE KEY **************** Never published
VERIFIED IDENTITY EMBED

Put the Sovereign Seal on your website.

Once your domain has a valid Sovereign Seal identity, compatible verification pages and infrastructure can expose the associated identity record.

SOVEREIGN SEAL VERIFIED IDENTITY
<a href="https://sovereignseal.co.uk/verify?target=example.co.uk" target="_blank" rel="noopener"> <img src="https://sovereignseal.co.uk/badge.php?id=SS-ABC123" alt="Sovereign Seal — Verified Domain Identity" style="width:170px;height:auto;"> </a>
An identity layer for email.

The Sovereign Seal is designed to complement existing email identity technologies. Where technologies such as BIMI can help display a brand identity, the Sovereign Seal focuses on making the underlying authentication relationship visible and verifiable.

DOMAIN DNS SEAL1 PUBLIC KEY SOVEREIGN SEAL EMAIL CLIENT
SOVEREIGN INFRASTRUCTURE VERIFICATION

Verify the infrastructure behind a domain.

Sovereign Seal can sit alongside established DNS and mail authentication signals to provide an additional identity record.

STANDARD ROUTING

Conventional Mail Infrastructure

Conventional email infrastructure can depend on external providers, shared environments and third-party routing.

SOVEREIGN INFRASTRUCTURE

Firetip

Firetip provides sovereign outbound messaging infrastructure and can expose its identity through the Sovereign Seal layer.

AUDIT FIRETIP