This happens at stunning scale; there are probably several billion messages a month sent via malicious form submissions globally, by my rough semi-informed estimate. (That includes other types of abuse than the one you mentioned.)
Perhaps this is bias from dealing with that kind of spam on a regular basis, but my current position is that a captcha needs to be present any web form which can even indirectly or occasionally result in an email being sent.