Email MFA - email masking pattern


I’m trying to better understand the masking pattern that is used as part of the Email MFA screen provided out of the box. It appears to me when using my email that everything after the first 4 characters before the @ is masked, and then everything after the domain is masked, however, I would like to confirm if this is correct.

