Ok, I understand that. The case which you're saying is different. If anyhow the user doesn't have access to the Admin and just the user account is compromised then he can send emails from that account only and if admin has setup limits over that then the spammer can't go beyond the limits.
Limits should be setup in any case and should be controlled by Admin.
This is a very important and good feature that needs to be implemented.
I hope you understand.
Thanks!