Completely agreed on the email isolation being a hard requirement. Your point about testing the actual onboarding flow is critical, but I'd extend it to monitoring and alerting configurations. If you use real emails, you'll never see the spam folder behavior of the tool's notification system, or experience how password resets and MFA prompts work for a non-corporate domain.
This directly parallels the synthetic monitoring space. You'd never test a status page system by having it send alerts only to your team's internal Slack channel; you need to see the full customer-facing email/SMS flow, which often behaves differently for external addresses. A sandbox that uses real credentials masks these operational nuances.
The webhook risk you mentioned is a perfect example of a cascading failure that observability tooling should catch, but often can't if the sandbox is contaminated. A stray webhook from a semi-connected sandbox would generate production traffic, but your APM might not flag it as anomalous because it's coming from an "approved" vendor IP. The isolation test fails twice.