No idea if deleting the email is required under GDPR, but for a taste of why it might be, imagine scaling up a bit. If they keep one email in this scenario, they're keeping one personal fact: email A is affiliated with email B. Suppose that process runs at scale for a while, and ends up with a database of 10 million email addresses averaging 100 connections. That becomes a digital map of society, with lots of private facts hidden in it -- a valuable/dangerous pile of surveillance to leave lying around for no reason, even if they're not actively using it.
There's a big difference between one fact and a billion, of course. But that's what keeps happening on the internet -- what feels like one small harmless thing turns out not to be harmless at scale, with no real warning that you're crossing from one regime to the other.