OTOH - before email existed, the critical "how do we contact the real you?" identifiers were phone numbers and mailing addresses.
And if you failed to pay your phone bill, or rent, or property taxes...the exact same problem - someone else would get "your" identifier.
Traditionally, for anything that's even slightly important, either your physical presence ultimately acted as your identity, or significant legal liability protected the non-physical identity (that is, if a court sends an important letter to you at some address, someone else who moved in to that address faces significant legal penalties if they open that letter).
In contrast, many domain providers will resell your domain in a heartbeat once you miss a payment deadline. And then the buyer can do whatever they want with emails sent to that domain, since there's no such thing as identity theft when your domain is your identity. In the case of a mailing address, it's not an identity at all, which is why non-junk mail will also have a recipient line.
and passport.com, which was their SSO login system