I'm not sure the point made was as much "use this blanket solution" as "if you're aiming to do this, go all the way".
Obviously, Github and Stripe aren't actually enforcing these messages as part of some larger security policy, or if they are, they're doing it very poorly. But if they were, the email shuffle is what they ought to be doing.