Summary

  • RFC 9873 can designate an additional ASCII or SMTPUTF8 contact address as primary, but the base RFC 5733 email remains and neither address gains a delivery receipt.
  • Extension negotiation proves that both EPP peers can process the additional field; disclosure, SMTP transport, forwarding, reply and RDAP presentation remain separate evidence surfaces.

The dangerous word is “primary.” In an operational dashboard it can look like health, authority or a verified destination. In RFC 9873, it is narrower: an optional boolean tells processing systems which of two stored contact addresses should receive primary treatment. The original RFC 5733 address does not vanish. No probe is sent. No recipient acknowledges control.

The extension exists because internationalized email creates a real transition problem. One address can use the traditional ASCII form while the other uses SMTPUTF8. Mail sent to either may be forwarded to the other, and a reply may return from a different address or script. The second field therefore improves reachability options without making the two strings interchangeable identities.

That distinction begins at session setup. EPP clients advertise extension namespaces in login and servers advertise them in the greeting under RFC 5730. When both sides negotiate RFC 9873, they commit to accepting, validating, storing and returning the additional value and to supporting SMTPUTF8 when sending or receiving mail. Without that negotiation, the extended contact data must not be supplied or returned. This is strong evidence of bounded protocol capability—and nothing beyond it.

An empty additional-email element has its own precise meaning: unset the value during update, or report that it is absent during information retrieval. The primary attribute cannot accompany that empty state. These rules create a clean account of configured state. They do not reveal whether DNS has a usable mail route, whether a mailbox was provisioned, whether forwarding points to the right place, whether an SMTP acceptance became final delivery, or whether a human read and answered.

Unicode adds a second control surface. The standard permits a broad SMTPUTF8 local part but recommends disciplined repertoires, IDNA2008-conforming domains and storage tests for difficult combining sequences. RFC 5895 informs user-interface mapping, while the IANA IDNA tables provide registered constraints for domain labels. RFC 6530 and RFC 6531 define the internationalized-mail framework and SMTP extension. Passing those checks establishes syntactic and transport readiness, not human equivalence between visually similar strings.

Privacy is deliberately shared. RFC 9873 requires the base contact disclosure setting for email to apply to every added email. An operator cannot treat the extension as an ungoverned side channel merely because it sits in another namespace. Yet storage and publication are still different decisions. Additional addresses may be processed like base contact emails, including through RDAP, but STD 95 defines the registration-data service rather than ordering verbatim publication of every stored value. ICANN's 2026 communication-form advisory is current policy context: a public mechanism may be a pseudonymized address or web form. It is not evidence that RFC 9873 is deployed.

Heng Lu's reality-layer doctrine supplies the missing ledger: negotiated capability, configured value, normalized representation, stored value, disclosure decision, SMTP attempt, transport result, recipient action and public projection are not synonyms. His minimum-initial-specification argument supports the RFC's narrow interoperable core while leaving repertoire and publication policy local. His running-code test asks for replayable traces at each boundary.

RFC 9873 improves the contact record precisely because it does not pretend to solve the whole communication chain. Leadership risk appears when downstream systems erase that modesty—copying primary=true into a verified-contact badge, treating SMTP acceptance as personal acknowledgement, or publishing a stored internationalized address without the shared disclosure decision.

Sources