DavecUK hi, yes this is unfortunately a known issue (and not only present at FreeFlarum). I did not want to discuss this publicly yet because I was busy and also because I wanted to setup hCaptcha for all forums with unified API key today (turns out, I would need to create a script that appends the hCaptcha extension ID to enabled extensions' IDs for all forums, so it's not as simple as it seemed at the first glance).
Another question is whether its appropriate to forcefully enable hCaptcha for all forums? I was thinking that I could send out an e-mail for all forum owners and encourage them to turn on anti-spam extensions too, which is probably better, but this wouldn't ensure 100 % anti-spam coverage, as not everyone would enable the extensions. I will make a decision today, and honestly I am leaning towards sending out an informational e-mail...
Anyways, as for what I know about this now that it was brought up... There was a discussion about this earlier, so your forum is not the only one with this issue: https://discuss.flarum.org/d/32766. I spotted it on one other forum as well. The way I noticed this is that I have recently signed up FreeFlarum for Yahoo (and others') e-mail feedback loops (it basically allows me to receive a notification every time a user reports an e-mail sent from FreeFlarum as "spam"). And, the way this particular spam works is that once a password reset e-mail is sent, the bot/human/whatever behind it marks it as "spam", most likely to lower down our mail server/IP reputation:
FYI I discussed with @luceos, and an update for Spam Prevention will be prepared that will hopefully mitigate this kind of spam in the future. Until then, I will look into ways to integrate as much anti-spam features into FreeFlarum as possible, with the current extensions that are available