At the time of the exploit, there was only one check, the MX record. Also once I claimed the domain, another user cannot claim it from their account. So this could be exploited silently as well because the victimized company won't know about it for a while.
Hi thank you for the post. If anyone has question, feel free to reach out to me here or at [email protected]. As a writer of this blog, I will be able to provide the feedback necessary and clear any misunderstanding/false positives regarding this.