Testing a new installation today, I set up a user with just "read" rights - nothing else. (Using User Role Editor plugin)
Logging in as this user, I was amazed to see that I could change the settings in Mail From!
Plugin has been de-activated, of course.
Solution?