This has existed for a long time and has been abused by quite a few people. I've seen some cc nodes using a random known cloudflare site and spoofing hostname to a temporary cloudflare site. IMO this should require a login at bare minimum.
if you think people won't abuse it because you're making them log in with a free email address...
This requires zero effort and you can deploy hundreds to thousands while maintaining 1000 gmail, proton etc takes resources and money.
They already do this. the email accounts already exist
It's the same reason that exists for PoW captcha, it's just way more annoying. Also accounts offer traceability versus a new identity every time you want to do something unless you want to go through hundreds of accounts a day.