Thanks for your comments, Benny. The file was a bad mix of old configuration remnants :\ Does the following make more sense now?
smtpd_helo_required = yes smtpd_recipient_restrictions = reject_non_fqdn_sender, permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination, reject_unverified_recipient, reject_unknown_recipient_domain, reject_non_fqdn_recipient, reject_unknown_sender_domain, check_sender_access hash:/etc/postfix/sender_access, check_recipient_access hash:/etc/postfix/roleaccount_exceptions, check_helo_access hash:/etc/postfix/helo_checks, reject_non_fqdn_hostname, reject_invalid_hostname, check_sender_mx_access hash:/etc/postfix/bogus_mx, reject_rbl_client zen.spamhaus.org, reject_rhsbl_sender dsn.bl.rfc-ignorant.de smtpd_data_restrictions = reject_multi_recipient_bounce, reject_unauth_pipelining smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, defer_unauth_destination