@publictorsten this *could* be solved with end-to-end signatures.
GnuPG sign every email, at mailservers accept properly signed emails from recipients your users authorized by sending an email to you (the subscription email) which contains a one-time secret your mailserver checks (provided in the mailto:link as subject).
If the different GnuPG frontends were actually compatible.
@devtrash @molly0xfff