How to handle a user asking for 2FA reset? (Email sent by their correct @gmail address and is DKIM-signed by gmail.)

I recently upgraded my Mastodon instance to Debian Buster, so I now have both pgsql 9.6 and 11 installed. (Currently, Mastodon still uses 9.6.)
Which one should I use (and why)?

To all instance admins: you should suspend the instance, it advertises itself as leaking private messages.

(CW n-word on that link and the image)

