You can just filter emails based on their from addresses.
Anyway, I already mentioned a solid incentive for them to use the correct token. Go back and read my earlier comment.
This is the wrong question.
The right question is: what should we do about the fact that the organization has such terrible security practice?
And the answer is: call them on the phone, and tell them that you will not do business with them until they fix their shit.
And who is going to do anything about fixing their stuff when you pay them a mere subscription fee?