True, but do you just allow them to borrow the reputation of your other customers? If a scammer knows example.com is a customer (DNS records will tell me this quickly) and a scammer decides to open an account and send as example.com through the service. Does Mailgun have no responsibility or ability to stop this behavior?
Seems easy enough to stop from what I know of email. Otherwise DKIM and SPF are worth nothing in systems like this.