I think it's difficult to prove, and the only people who care will be the domains owners that are impacted. If you send enough mail, you won't notice a few extra emails going out from another account.
Mailgun should have a way to monitor and block this. We used SMTP to interface with Mailgun and frankly, I didn't even think of this as being a vulnerability until I left the service. The DMARC reports just prove it was happening.