I believe the secure email issue linked is exploitable by any MailChannels customer, not just Cloudflare Workers.
Since you cannot forge the CF-Worker header in API requests (this header is added by Cloudflare's back end), it is not possible to send email for any domain that hasn't been locked down to your specific Worker.