>                      ^^^
> Try setting the IPs you want to deny like this:
> Or am I way off here?

Yes, because saying "deny" makes tcpserver to not accept the connection
right away, thus from that host one would not even allowed to send mail
to a local recipient.

The right way is indeed to allow tcp connection, but not supply the
RELAYCLIENT environment variable, so that qmail-smtpd will only accept
mail which are detined to local users.

