Earlier quoted context omitted.
I can't tell if people are being deliberately dense as a way of punishing me for having a critical opinion, not reading the rest of the comments before responding to me, or genuinely do not understand what I am getting at. A hallmark of a nefarious email (particularly scams but some sales attempts) is that they aim to deceive you. Humans famously have the capability of lying. Someone telling me they are _not_ selling…
FWIW, I get several of these emails per week, as the first-reader of security@ emails, and they're almost always scams, sales pitches, or poorly-disguised bounty sniffers. I can't even count the number of times I've been informed that Wordpress.com (.com, not self-hosted) has severe vulnerabilities. And those are the plausible reports. But I always respond professionally and with civility, obviously, because if they…
That is also the reason there is no direct link to my publications on the actual emails, another link to add suspicion of phishing that leads to being ignored. I do provide a link to my index with all my public finds on the signature of the email though.
Also a google search of my handle which I sign and mention on the email would get multiple hits for reputable news websites such as Databreaches.net, TechCrunch, The Register, Publimetro, but doesn't seem companies do much vetting at all before ignoring the alerts.