I am really glad that I do not have one of these email accounts. While I cannot speak firsthand of some of the shenanigans that are mentioned in the article, I have worked in the web hosting industry for 20 years. I have seen some of the horrible security practices in use by customers and, surprisingly, people in the industry. I've seen many people locked out of their hosting accounts because they have their primary…
This is a surprisingly difficult risk to effectively mitigate.
If you have a domain and tie your domain registration and hosting accounts to an email address hosted by the domain, you could get locked out if something goes wrong with the domain registration.
If you tie your registration and hosting accounts to a third-party email account, you could get locked out if the third-party decides to nuke your account for any arbitrary reason (cough, cough, Gmail).
If you tie your registration and hosting accounts to a cell phone number, you could get locked out if someone attacks your phone account (unauthorized porting, SIM swap, etc) or if the cell phone network goes down (think California fire protection blackouts, or hurricanes).
If you tie your registration and hosting accounts to TOTP or Webauthn 2FA, you could get locked out if you lose or damage your 2FA device.
There's no good way to authenticate domain registration and hosting accounts unless your registrar and host have the foresight to allow multiple authentication paths.