>One thing that may have prevented this hacking: facebook could have noticed that the primary email for the user was for an expired domain, and proactively notified them to remove it.
Almost any website, app or online activity that requires logging uses email based authentication. Do you think all existing web sites and apps should verify the expiration of mail domains? And what about phone numbers? A user can lose his phone number, should they verify that, too?