A new mechanism has been developed by Facebook and Yahoo to eliminate the risk of using old email addresses to hijack accounts for services used by the previous owners.
Under certain circumstances, the owner of an email address that was previously used by another user may gain access to accounts registered by the previous owner of that email address. If adequate security measures are not in place, a simple password change request is sufficient to provide access to the services to which the user whose email address has been deactivated was registered.
In general, access to an email account by the actual subscriber to a service is considered trusted and there are no security controls available.
In the case of Yahoo, the email address is deactivated when it has not been logged in for a year, while in the case of Microsoft's email service, the minimum frequency to log in to the account is 270 days.
The RRVS standard prevents sensitive information from leaking to the wrong recipient.
The solution implemented by Facebook to protect against this risk for Yahoo accounts is to insert “a timestamp within an email message to show when ownership of a Yahoo account was last verified,” said Murray Kucherawy, a software engineer at Facebook.
He adds that if the change of ownership of the account is confirmed, Yahoo can simply block the delivery of the message containing details about the password change, thus preventing the account from falling into the hands of another recipient.
The method, called RRVS (Require-Recipient-Valid-Since), is actually an extension of the Simple Mail Transfer Protocol (SMTP), and is a proposed standard, published by the Internet Engineering Task Force.

