The risk factor falls onto the end user who've been sent the keys. What's their OpSec like. Is their email secure? Will the email be deleted responsibly after they've sufficiently saved the keys? No different expectations from self-custody wallet.
I'm not following the part about DMs? How would they be viewable to me if I don't know their privkey?