How would you verify that? Anyone can put someone else's nip-05 user in their profile. The client just checks if .well-known/nostr.json?name=username is present, right?

Reply to this note

Please Login to reply.

Discussion

And it will find a mismatching public key.

Of course! You're right. So, if relies were to verify the accounts npub matches that in the JSON, it should be fine, right?

Yes, it's what clients currently do.

t-y