You can charge reasonable administrative fees or refuse to act if the request is "manifestly unfounded or excessive, in particular because of their repetitive character". [1]
I think GDPR intends to protect businesses from "denial of service attacks" through sending many repetitive or bogus requests. A single, legitimate request is definitely not excessive.
How do you automate checking if person requesting the data is the person claims to be.
How do you automate reading an email and giving meaningful response?
I admit I'm not sure how the verification part is supposed to look like. For the rest, I assume that if you have a standardized data flow (and don't randomly resell people to different parties), you could automate the part that writes responses, and only have humans read the original mail and check appropriate checkboxes to generate a standardized reply covering all the relevant points.
[1] https://gdpr-info.eu/art-12-gdpr/