Earlier quoted context omitted.
This is death. Your email provider absolutely cannot under any circumstances have this vulnerability. Wow. Just the idea that there's a human in the process making subjective decisions about security questions and answers that can, on their own recognizance, change a recovery email address. Forget the immediate mistake that one rep made, and go down a couple levels deeper into the company policy design mistakes at pl…
I've been a fastmail customer for a bit over a year and I agree. The offerings over at https://protonmail.com/signup have been nagging me to give it a try. I now have a reason to try and switch. I'll lose functionality found in fastmail but gain a lot in security.
As a corollary: if you really care, use Signal for stuff you can't say over e-mail. Whatsapp's fine too. But they solve a very different security problem than the one you need e-mail to solve, which is mostly "don't leak my emails" and also "don't reset my password for attackers who ask nicely".