The patterns bit isn't really how this works. There are no real analytics being done on the messages coming in from example.com to check if it's from 'the same place as it normally is' in that manner. It would require enormous resources and that problem was solved by SPF way back in the 00's (or before).
Your Example.com will usually delegate a subdomain (dns) to a big mailer (like mailchimp, sendgrid, j33t-haxx0rz.ru or whoever) if they're going to be doing a lot of mails. The delegate will create/maintain a load TXT record (that's SPF) which is really just a list of hostnames (like 'mailer1.foo_emailcompany.com') which then have sort of proved that they are authorized to send mail as foo.example.com. The mailservers at google or wherever which then recieve these will lookup the txt records for the sender as part of their spam scoring mech during the mail arrival, and will use it as part of the scoring mech (but not the complete one).
Your big mail proivders will be using 1000's of IPs to do a single mailing at times, so there is really no other way this sort of thing can work. DKIM uses a similar approach but utilizes signing to get there..
edit: also, probably <1% of people don't/won't view images in their mails, which is sort of the point here regardless of what we personally do......