As it stands, there is no 2FA, which would be ideal. But since there is no 2FA, the email change process is very flawed. If someone accesses my account, they can change the email (which will take effect immediately). I will not be able to recover my password or log in. There needs to be a validation process. The new email needs to be verified for validity and the current email needs to be notified that the change has been made, with the option to revert.