Clumsy, perhaps, but secure.
The primary difference between your PBEM helper and the server is that server doesn't know who people are by glancing at e-mails. And, e-mail can be forged easily. So... PBW can require a username and password before letting a user upload a turn.
For e-mail, PBW requires that the player submit his e-mail with the same subject as the turn was sent to him; this subject contains a code uniquely identifying him, so that even if someone could forge the user's e-mail, they would have to have intercepted the new turn mail message as well. Not impossible by any stretch, just in many instances significantly more difficult.
Cheers,
Admiral
------------------
Space Empires IV Play by Web