Tim should read the spec before reacting to it. It proposes that
'mailto:' be extended to allow the URL to specify more 'default'
entries for headers. Clearly part of the 'security considerations' are
that any client that implements this must be aware of -- and deal with
-- all of the various security threats that might arise.