What would be the difference from normal hotlinking in a standard email?
The vector in both cases would be being able to send a million emails; a reflection attack with spam emails as a vector would be just the same without provider servers doing anything special. MUA opening images would do the attack.
Actually a provider could cache the hotlinked resource and remove almost completely the reflection.