Earlier quoted context omitted.
> It's pretty shameful that these large companies have no real way to contact them. Along the same lines, I think organizations shouldn't be allowed to send out email but not receive email at the same address, e.g. noreply@. That's just hostile in general.
I fully agree that it is shameful that we can't contact these companies, but suppose you want to send 2fa tokens as a startup. Should you not be allowed to offer 2fa through email unless you're at a scale where you can answer every reply email?
It could even be quite high, like $100 million or $1 billion in annual revenue.