It seems like an easy safeguard to implement to prevent sending unwanted emails/texts would be for Alexa to generate a unique confirmation phrase that the user has to repeat back in order to actually execute the send command.
Something like
Alexa: "Say 'purple people eater' to send email."
Real Person: "Purple people eater."
Alexa: "Email sent."