If your threat model includes hostile mail relays, you probably shouldn't be using bargain basement VPS providers.
Password-reset emails are also easy for an attacker to generate, and no harder for them to intercept than the welcome email.
Password-reset emails are also easy for an attacker to generate, and no harder for them to intercept than the welcome email.
And yes, password-reset emails may also be a concern (not as severe, though, if reset emails are single-use and have short TTL).