The issue with this is that Lemmy doesn't allow accounts with duplicate emails. So If I want three accounts, I need three email addresses. As Lemmy doesn't currently support push notifications, email is the only way to get notified about anything. Checking three different addresses is impractical.
I agree that this is best practice, but until Lemmy allows admins to remove the uniqueness requirement for email addresses, or sets up a decent push notifications API, it's not going to happen over most instances.
Fortunately, we were in no danger around the recent issues. Not only did we not use the feature in question, we have cross-site scripting policies set up correctly so scripts from other domains won't run.