Sometimes when you reset an email account password it will tell you a part of the recovery email if there is one. This could be a clue.
Send an email to one of the emails used by the perpetrator while in a meeting and see if any of your staff reacts.
If you have access to the routers, compare device names of people logged on while the emails are sent out (if they’re sending in the building).
Are any of your staff using protonmail as their main email provider? Search slack for any discussion or snippets with proton emails.
Does downloading the parent email list cause a log to trigger?
While in a meeting speak as normal and then when you mention something that is slightly gossipy, observe whose eyes widen or body language changes.
Simply speak to your staff and determine whether they are happy in their positions. This is good practice anyway.
Don’t be obvious.