Connecting an analyzer on the network cable reveals that it seems to send the same authentication strings as my Exim and the server responds with the same "535 5.7.8"-failed message, then the client starts sending a "MAIL FROM: <[EMAIL PROTECTED]>" message which becomes OK'd by the server! The dialogue continues and eventually the mail becomes delivered properly.
This suggests the server also permits relaying either from your IP, either from your FROM field or both.
smime.p7s
Description: S/MIME Cryptographic Signature
-- ## List details at http://www.exim.org/mailman/listinfo/exim-users ## Exim details at http://www.exim.org/ ## Please use the Wiki with this list - http://www.exim.org/eximwiki/
