My email for spotify login is unique, and of the form *+spotify@gmail.com

I assume that’s checked for. For simple SaaS projects compared to Spotify at least, things like that were checked.

more or less everyone analyzing email addresses knows that pattern, so it's easily ignored.

