That problem is easily solved with client-side whitelists (ala hey.com). However, that would also mean the death of all "legitimate" marketing emails. All the hoops you have to jump through are there either as a form of identity validation (which is fair) or because the industry wants to allow SOME unsolicited emails through.