Again, wouldn't it be easier for the attacker to just buy a domain and use that completely undetected instead of having to use a rate-limited disposable email service?
In this day and age I don't understand why they wouldn't be able to just use a headless browser instead of doing it manually - has labor really become this cheap?