AP + HTTP Signatures take care of many of the issues that email has, but not all, though most of the attacks I've identified in the Fediverse are still theoretical and not seen in the wild.
I've been hesitant to publish them because it would be too easy to pick up and cause havoc.
Anyway, I welcome experience/ideas and especially help.
2/end