We're in the process if implementing this solution and when security reviewed the process their comment was that security through obscurity isn't appropriate.
The email address used to update the status is very long, random and unique enough not to be guessed. However, if this email address gets compromised then anyone from any random source address can update the status.
Is there a way to restrict the update to a predefined list of source domains and/or email addresses?