Sorry for starting the discussion.
If I set up an script that generates mail from one adress in the rcpthost to
Another adress in rcpthost I can fill every mailbox on the server ...

I thought that smtp auth should prevent that anyone could send messages
through the
Server without being authenticated ... But I you do it this way you can
RELAY without
Being smtp authenticated

By definition, mail for domains in your rcpthosts file (and morercpthosts.cdb) isn't relayed.

An open relay is a server that will accept mail for any domain, and then forward it on.

If your server didn't accept mail for domains in the rcpthosts file, it would be impossible for anyone to send you email.

