We have all sorts of protection: rate limiting, crippling non-paid accounts, detecting if a trial signup comes from a VPN/Tor (+5 to "suspicious" score!) etc... But they still manage to find ways. It's a never-ending battle. And the saddest part is - all this hard work is completely invisible to our existing paying customers :(
If your app has an email-sending module of some sort it WILL be abused. Even a trivial "reset password" form is a target.
My support goes to the GitLab team. Good luck and no hard feelings.
[1] https://www.jitbit.com/news/5354-spammer-attack-post-mortem/