A small company will use a service like SendGrid, or even MailChimp at the higher level.
Those services will do a lot of checking for you and investigating this kind of weirdness/attack is exactly why you pay them money!
If they're sending directly, then they'll definitely be as vigilant as us, or they'd never get emails into people's inboxes!