Unfortunately, it’s not that simple. It’s extremely common for the same organisation to send emails from different addresses, different domains, and different servers, for many different reasons.
Anyway, I already mentioned a solid incentive for them to use the correct token. Go back and read my earlier comment.
This is the wrong question.
The right question is: what should we do about the fact that the organization has such terrible security practice?
And the answer is: call them on the phone, and tell them that you will not do business with them until they fix their shit.
And who is going to do anything about fixing their stuff when you pay them a mere subscription fee?