Why Email-Based Age Verification Falls Short of Real Security

As the CEO of Sedicii, a company committed to privacy-preserving digital identity solutions, I’ve watched with interest as some organisations begin to promote email address-based age estimation as a method of verifying a user’s age. While I appreciate the intent to reduce friction in the user experience, I must highlight the serious limitations of this approach—particularly in contexts where trust, compliance, and the protection of minors are non-negotiable. 

Email ≠ Identity or Age 

 

Email addresses are fundamentally poor indicators of a person’s age. They were never designed to reflect the user’s date of birth or identity in any meaningful way. Estimating age based on metadata—such as account creation date or linked services—is speculative at best. 

A 12-year-old can easily create an email account and claim they are 20. Worse still, they could borrow or purchase an older email address to appear compliant with age restrictions. There is already evidence of email accounts with older digital footprints being traded—a practice that further undermines this method as a trustworthy means of age verification. 

Easy to Manipulate, Difficult to Trust
 

Let’s be clear: creating a new email address takes minutes and costs nothing. There are no real safeguards at sign-up to ensure that the age entered is genuine. A teenager who is blocked from one service could simply create a new email address and try again. This isn’t a loophole—it’s a fundamental flaw. 

Moreover, email ownership doesn’t confirm the identity or age of the user. A child could be using a parent’s or sibling’s account, or a shared school email. In each of these cases, a system based on email data could easily return a false positive for age verification. 

Regulatory Risk and Unsuitability for High-Risk Contexts 

 

Even providers of this method acknowledge that it is only appropriate for low-risk scenarios. For sectors such as online gambling, adult content, age-restricted e-commerce, or financial services, regulators require higher levels of assurance. Guesswork won’t suffice when the legal, ethical, and reputational stakes are this high. 

Using a weak method like email estimation exposes organisations to the risk of non-compliance, litigation, and—most worryingly—harm to vulnerable users. 

Age Verification vs. Age Assurance: Why the Difference Matters 

When discussing how to restrict access to age-sensitive services, it’s essential to distinguish between age verification and age assurance—two terms that are often mistakenly used interchangeably but carry very different implications. I’ve often seen companies claiming to provide age verification using email addresses when they are actually offering age assurance. 

Age verification typically refers to a binary check: confirming someone’s age against official records or trusted identity documents, such as a passport or driving licence. It provides high assurance that the person is who they say they are, and that their date of birth is genuine. This method is especially important in high-risk contexts, such as online gambling, alcohol sales, or adult content. Combined with an additional check such as biometric data, it is particularly effective. 

Age assurance, on the other hand, refers to broader techniques that estimate or infer a person’s age range without always needing to know their exact date of birth as in the case of email metadata. While age assurance can be appropriate for low-risk environments, it does not provide the level of certainty regulators demand in sectors where underage access can lead to serious harm or liability. 

In the case of email address-based estimation, we are firmly in the realm of low-assurance age assurance. It offers a weak signal that is easy to manipulate and provides no reliable protection against underage misuse—especially when children can access older email accounts or use aliases. 

Regulators, including Ofcom in the UK, are increasingly drawing this distinction and expect businesses to choose the appropriate level of assurance based on the risks involved. Ignoring this can lead to inadequate protection, non-compliance, and erosion of trust. 

A Better Way: Privacy-Respecting Age Assurance 

 

At Sedicii, we are committed to helping organisations achieve accurate and compliant age verification without infringing on user privacy. Using technologies like zero-knowledge proofs, we can verify whether someone meets an age threshold—without exposing their date of birth or any other personal data. 

This approach delivers: 

  • High assurance: Confirms age directly, not through inference. 
  • Privacy by design: No unnecessary data exposure. 
  • Regulatory compliance: Aligned with UK, EU, and international standards. 

Email addresses were designed for communication—not identification, and certainly not for age verification. They are far too easy to falsify, borrow, or recycle. In serious contexts, the stakes are too high to rely on guesswork. 

At Sedicii, we urge organisations to adopt responsible, privacy-first methods of age assurance. It’s not just about ticking boxes—it’s about building trust, protecting users, and doing the right thing. Please do Contact Us to find out more about our Age Verification solution. 

This article is part of Sedicii’s ongoing thought leadership in support of Project PHACKS, an initiative focused on building collaborative communities to address complex cybersecurity and data privacy challenges. PHACKS is funded by the European Union and brings together organisations to explore new approaches to secure data collaboration utilising privacy enhancing technologies. Through this work, Sedicii contributes its expertise in advanced cryptography, secure data collaboration and digital identity to promote safer, more transparent digital ecosystems across Europe. The views expressed herein reflect the author’s perspective and do not necessarily represent those of the European Union. Learn more about Project PHACKS.

Scroll to Top