They probably should validate a somewhat matching commit with the same e-mail address ending up in a branch or something. Few if any projects modify those.
That's my point :) Arguing that because this would exclude some small number of projects does not make sense if from the get go you exclude a large number of open source projects.
Just a piece of anecdata in regards to this, last year in my first Hacktoberfest I made a PR for an open issue on a project that got no response from the maintainer until a week later, where he said something along the lines of "Oh sorry, I missed this one, I'll get to it soon", and then he just never reviewed it or anything else on the project ever again.
They probably should validate a somewhat matching commit with the same e-mail address ending up in a branch or something. Few if any projects modify those.