← All posts

Postal voting: the convenience, and the controls that have to come with it

A judge found that ballots cast by living people were submitted in the names of the dead — and the remedy was to throw out an entire election.

It is the morning of 23 April 2015, and in a courtroom in London, Commissioner Richard Mawrey QC is reading a verdict that has not happened in British democracy in living memory. Lutfur Rahman, the executive Mayor of the London Borough of Tower Hamlets, elected in May 2014 by more than 3,000 votes, is being removed from office.

Not suspended. Not investigated. Removed.

The election court's judgment — Erlam & Ors v Rahman & Anor [2015] EWHC 1215 (QB) — runs to 217 pages and finds the election tainted by corrupt and illegal practices committed by the Mayor personally and through his agents. Among those practices: personation, postal-vote fraud, bribery, treating, false statements, and undue spiritual influence.

The postal-vote findings are the ones that should keep any election administrator up at night.


A ballot cast a mile from the polling station

When you vote in person, there is a controlled chain of events. A poll worker checks your name. You receive one ballot. You step into a booth. No one watches you mark it. You deposit it yourself in a sealed box. At no point does someone else handle your unmarked ballot, fill it in beside you, or carry it somewhere for you.

Postal voting breaks every one of those steps.

Your ballot travels through the post to an address. It is filled in — somewhere, by someone — away from any official witness. It goes back into an envelope, then another envelope, then a postbox. By the time it reaches the count, it has passed through hands no one has logged.

This is not hypothetical risk. The Tower Hamlets court found evidence that postal ballot forms were being filled in at organised events — multiple ballots completed together, away from the voters' homes, sometimes by people who were not the registered voter at all. It found personation: votes cast in the names of people who had not cast them.

The court did not find these were isolated incidents. It found a pattern extensive enough to affect the result of a mayoral election in one of London's most populous boroughs.

The remedy was not a recount. There was nothing to recount. The election was void.


The problem isn't the envelope — it's what happens inside it

Let's be precise about what went wrong in Tower Hamlets, because the lesson matters.

The vulnerability was not that postal voting exists. It was that the controls around postal voting — the identity checks, the custody of blank ballots, the requirement that a voter personally completes their own form in private — were either inadequate or circumvented.

Postal voting has one fundamental security property that in-person voting does not: the moment a ballot leaves official custody, its chain of custody is broken. The ballot goes to a private address. It is filled in without a witness. It returns sealed in an outer envelope carrying a signature and date-of-birth check that, in 2014, in England, could be forged or coached by anyone standing next to the voter.

A ballot posted is a ballot that has been, for some period, unobserved. That gap — between the point a blank form reaches a household and the point a completed form re-enters official custody — is the attack surface.

And it is an attack surface with a long history of exploitation. In North Carolina's 9th Congressional District in 2018, a coordinated scheme collected absentee ballots from voters — sometimes completing them, sometimes simply taking them — and the State Board of Elections ultimately ordered a new election entirely. The operative at the center, McCrae Dowless, was later indicted on felony charges. A different candidate won the re-run.

The mechanism in both cases is identical: intercept the ballot while it is outside official custody.


Austria 2016: no fraud found, election annulled anyway

Tower Hamlets is the case where something bad demonstrably happened. Austria 2016 is the case where the procedures broke down — and no one could prove it hadn't.

On 1 July 2016, the Austrian Constitutional Court annulled the second round of the federal presidential election — a vote Alexander Van der Bellen had won by roughly 30,000 votes from 4.6 million cast. The court's reasoning was methodical and, in its way, radical.

Austrian law is precise about postal ballots: the district electoral authority, and only the district electoral authority, may handle them. Envelopes may not be opened, votes may not be counted, before 9:00 a.m. on the day after the election. Electoral board members and witnesses must be present.

The court found violations in multiple districts. Envelopes had been opened early. Votes had been counted by unauthorised persons. Required witnesses were absent. Roughly 77,000 votes were affected by proven procedural violations.

The winning margin was 30,000 votes.

The court expressly found no evidence of actual fraud. It did not say votes had been changed. It said that because the safeguards against manipulation had been violated at a scale that exceeded the winning margin, it was impossible to confirm the result was what the voters had actually decided. The election was annulled. A re-run was held in December 2016.

This is the harder argument, and it deserves to be heard clearly: verifiability is not only about catching fraud that happened — it is about procedures rigorous enough to prove that fraud could not have happened. When those procedures are breached, the result is unverifiable, regardless of who actually won.


What 'chain of custody' actually means for a postal ballot

Think of chain of custody as a log with no gaps. Every person who touched a ballot, and when, and under what authority.

For an in-person ballot: the chain starts when the ballot paper is issued, continues through your marked ballot entering the box, runs to the moment the sealed box is opened at the count under observation, and ends when the batch is tallied and sealed again. Each link is witnessed, logged, and cross-checked.

For a postal ballot, the chain has a structural gap — the period when the form is at a private address. Procedural law tries to compensate for this gap with:

  1. Identity verification before issuing a postal vote (is this person actually registered and eligible?)
  2. Identity verification when the return envelope is received (does the signature match? Does the stated date of birth match?)
  3. Timely, witnessed opening of returned envelopes under official supervision
  4. Secure, logged storage of received envelopes before opening day

The Tower Hamlets findings suggest that steps 1 and 2 were gamed — through organised completion of forms and, in some cases, personation. The Austria annulment found that step 3 was violated. Both failures point to the same underlying truth: the postal ballot chain of custody is only as strong as its weakest link, and right now some of those links are procedural rules written on paper, not enforced by any mechanism that is independently auditable.

A rule that says "only authorised persons may open envelopes" is not a tamper-evident seal. It is a promise. And a promise, in an adversarial environment, is not the same as a proof.


The secret ballot was invented for exactly this kind of threat

There is a reason the Australian ballot — the state-printed, privately marked ballot — became the global standard in the nineteenth century. Before it, voting was public. You stated your preference aloud or in a visible book. Landlords watched tenants. Employers watched workers. The Ballot Act 1872 ended open voting in the United Kingdom precisely to break the bribery and intimidation that public voting enabled.

The logic is simple: if no one can see how you voted, no one can buy or coerce your vote. Secrecy is a security property, not a courtesy.

Postal voting puts pressure on exactly this property. The ballot is marked at home, where a family member, landlord, employer, or community figure can stand nearby. In Tower Hamlets, the court found evidence that ballots were completed at organised gatherings rather than in the privacy of the voter's own moment.

This is the same pressure the secret ballot was designed to prevent — just relocated from the polling station to the kitchen table.

The U.S. Court of Appeals for the First Circuit articulated the mechanism precisely in Rideout v. Gardner (2016): secret-ballot reforms were adopted to "combat widespread vote buying and voter intimidation," practices that depend on a buyer or coercer being able to verify the vote. Anything that lets a voter prove how they voted — a ballot photograph, a completed form witnessed by someone with an interest in the outcome — reopens the market.

A postal ballot marked under observation is, structurally, a ballot cast in public. The nineteenth century solved this problem for polling stations. We have not yet solved it for the doorstep.


The answer is not to ban postal voting

Postal voting serves real needs. Voters with disabilities. Voters who travel for work. Voters in hospital. Voters in remote areas. Election authorities in many countries — and in most of the fifty U.S. states — have expanded mail voting precisely because making voting accessible increases the legitimacy of the result. Participation matters.

The question is not whether to allow postal voting. The question is whether we have designed its custody chain to be as tamper-evident and independently auditable as the custody chain for ballots cast in person.

Right now, the honest answer is: not reliably.

Here is what genuine tamper-evidence for postal ballots would require:

Trackable, unique ballot identifiers. Every postal ballot should carry a cryptographically unique identifier that lets election authorities — and, crucially, the voter themselves — confirm that the specific ballot issued to them was the one received and counted, without revealing how they voted. This is technically feasible; several countries are experimenting with voter-facing verification codes.

Photographed, logged envelope handling. Every return envelope received should be logged and time-stamped on arrival, in a format that is publicly auditable and machine-readable. The Austria case hinged on the absence of logs proving who opened what, when. If every envelope's receipt and opening were photographed and the hash of those photographs published in a public ledger, the kind of procedural violation the Austrian court found would be immediately detectable — not reconstructed months later through witness testimony.

Signature verification that is independently auditable. Current signature-matching processes are mostly human judgment applied to paper. A rejected or accepted envelope should generate a reviewable record that any party can inspect. In close elections, the adjudication of borderline signatures is an invisible, unverifiable process. It should not be.

Real-time custody logs. At every stage from printing to dispatch to receipt to opening, a postal ballot's location and handler should be logged in a system that produces a tamper-evident trail. Not a paper form locked in an office. A machine-readable audit log that any accredited observer — candidate agent, journalist, independent researcher — can check against the final count.


What 'the audit confirmed it' does not mean

Officials, after close elections, frequently tell us the process was checked and everything was fine. This is usually sincere. It is not the same as proof.

Georgia's 2020 statewide hand recount confirmed the machine-tabulated outcome to within about a tenth of one percent across roughly five million ballots — a significant achievement. Colorado's risk-limiting audit framework provides statistical confidence calibrated to the margin of each race. These are real improvements.

But they audit the counting of ballots that are already in the box. They cannot audit whether the ballots in the box are the ballots voters intended to submit. If a postal ballot was completed under duress, or filled in by someone other than the registered voter, it enters the count indistinguishable from a legitimate vote. A hand recount will count it again, faithfully. A risk-limiting audit will sample it. Neither method will flag it.

The Tower Hamlets problem was not in the count. It was in the ballots. And the Austrian problem was not in the result — it was in the inability to prove the result was untampered with, once the custody rules were broken.

These are different failure modes from anything a post-count audit catches. They require controls at a different stage of the process: before and during the handling of the ballot, not after it has been tallied.

An official statement that "the count was accurate" does not speak to whether the inputs to the count were legitimate. That gap is the one that has to close.


What would make this checkable by anyone

The standard we should hold postal voting to is the same standard the German Constitutional Court set for electronic voting in 2009: the essential steps must be examinable by the citizen, reliably, without specialist knowledge. (Bundesverfassungsgericht, 2 BvC 3/07.)

For postal ballots, those essential steps are: Was my ballot issued only to me? Did it reach the electoral authority sealed and intact? Was it opened only by authorised persons, at the lawful time, with witnesses? Was the vote inside attributed to my ballot and only my ballot?

Today, a voter who used a postal ballot in most jurisdictions cannot independently verify any of these steps. They cast their ballot into what is, from their perspective, a closed process and trust that the officials followed the rules.

Trust is not verification.

A result no one can independently check is a reassurance. A result anyone can independently check is a proof.

The technology to make postal ballot custody tamper-evident and publicly auditable exists. Cryptographic logging, voter-facing confirmation codes, machine-readable public ledgers of ballot receipt — none of this requires replacing postal voting. It requires treating the postal ballot chain of custody with the same engineering discipline we would demand of any other security-critical system.

The Tower Hamlets election was voided. A new election was held. Lutfur Rahman was not on the ballot. The voters of Tower Hamlets voted again, and the result was different.

That is what happens when a system fails and a court catches it. But courts are retrospective, slow, and adversarial. They are a last resort, not a design principle.

The right question is not "what do we do after fraud or procedural failure is discovered?" The right question is: what would make fraud or procedural failure impossible to hide in the first place?

That question does not have a satisfying answer in most postal voting systems operating today. It should.


The chain-of-custody gap in postal voting is one instance of a broader problem we track across voting systems worldwide. See how this gap appears across different election types and jurisdictions or read the 2-minute version of the verifiability problem. For a full picture of where custody chains break down — and what independently auditable alternatives look like — explore the TrustVoting Atlas.


Sources