Facebook not only sends the code to text without asking, but they love to just directly start the reset password procedure.
Now, that’s super weird. Are they assuming that, because last time I logged in was 6 months ago, I must have forgot my password?
I set the mail server to bounce everything that doesn’t match dkim.
I almost don’t receive spam anymore.
The problem is that sometimes some legitimate services didn’t configure their email server correctly