Page 27: Candidate address format

Page 27

This is still rather sketchy, but from the security point of view it
covers the important features.

This assumes that we're re-keying fairly frequently and using expiry
of keys to expire addresses.

The Exim message-ID guarantees uniqueness per message. We'll
probably hash it instead of using it directly.

There's minimal framing, since the extra data added to the address
is only of use to the sending site. With a public key format we'd
need an explicit expiry timestamp, an algorithm tag, and maybe more
(e.g. message data hash).

