But SPAM should be resolved with strict adherence to standards like SPF, DKIM, etc. and where those fail it should be improved
Today many companies, large and small, as well as government agencies, large and small do SPF and DKIM very very very wrong.
Unless we can get this right I fail to see how regulations would do anything other than make things worse
Some of the biggest SPAM abusers are not the small providers but the Large companies like Gmail and Microsoft who do not vet their customers very well
It could be any email service that allows the librarian-administer to reset the password for an account. If I mess up my exchange email, the helpdesk can verify my identity and reset my password.
I suspect that most going down this approach would find it easier to use a large hosting service that they provision and administer (along with allowing password resets) than to try to have an underfunded library IT staff stand up an arbitrarily large email service and manage all parts of it.