Yes, we did see the thread shortly after it was posted, and we did move the restricted email address validation to the server side. The client-side check is still there in the UX layer, but it is no longer the security boundary. Thank you for bringing it up here.