if you assume that anything you send through the internet can be intercepted, then yes, of course they could tell. They'd get the email just like your intended recipient, and when they tried to mount the .dmg, it would ask them for a password.
If you're concerned about sending unsecured email, why not just get yourself set up with PGP or the free version that's already integrated into Panther's Mail.app?