The only way I see this working is for paper authors to include their public keys in the paper; preferably as metadata and have them produce a signed message using their private key which allows them to claim the paper.
While the grandparent is understandably disappointed with the current implementation, relying on emails was always doomed from the start.
Given that the paper would have be changed regardless, including the full email address is a relatively easy solution. ORCID is probably easier than requiring public keys and a lot of journals already require them.
While the grandparent is understandably disappointed with the current implementation, relying on emails was always doomed from the start.