First of all, dirty ID3s and/or filenames (e.g. “[downloaded from shadymp3.net.cc]”) are a dead giveaway that you are a pirate AND an idiot.
I’m so OCD about my ID3s that keeping them consistent is a significant part of my workflow when expanding my collection.
Assuming they’re clean, there is no “easy” way for them to check whether it’s legit or not, apart from listing all tunes and asking for invoices. Might pick a few tracks at random to check and assume it’s a representative sample.
Can’t claim being a saint about this, still have some illegal mp3s that I’m progressively buying. Priority is audio quality upgrade > play count.