ZCS is the default MTA postfix OpenRelay server.
Telnet from outside the network:
Half OpenRelay sample:

TELNET myzimbrahost.foo.bar 25
EHLO helo.com
MAIL FROM:<user@mydomain.foo.bar>
RCPT TO:<user2@mydomain.foo.bar>
DATA.
FullOpenRelay sample - default zimbra config.

TELNET myzimbrahost.foo.bar 25
EHLO helo.com
MAIL FROM:<user@notmydomain.foo.bar>
RCPT TO:<user2@notmydomain2foo.bar>
DATA.
FullOpenRelay sample - default zimbra config.

TELNET myzimbrahost.foo.bar 25
EHLO helo.com
MAIL FROM:<user@notmydomain.foo.bar>
RCPT TO:<user@mydomain.foo.bar>
DATA.
Solution:
Modify (zimbra user) postconf -e restriction (eg. sender, reciptioen, helo and data) and zmprov mc default postfix restrition paremeters. See also /opt/zimbra/postfix/conf/master.cf.in
Default postfix restrictions (sample):
smtpd_client_restrictions = permit_sasl_authenticated, permit
smtpd_data_restrictions =
smtpd_end_of_data_restrictions =
smtpd_etrn_restrictions =
smtpd_helo_restrictions = permit_mynetworks, permit_sasl_authenticated, permit
smtpd_recipient_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination, check_sender_access dbm:/opt/csw/etc/postfix/sender_checks_my, reject_non_fqdn_sender, reject_unknown_recipient_domain, permit
smtpd_restriction_classes =
smtpd_sender_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unverified_sender, reject_non_fqdn_sender, reject_unknown_sender_domain, reject_unknown_address, reject_sender_login_mismatch, reject_unauth_pipelining, reject_rbl_client sbl.spamhaus.org, reject_rbl_client sbl.spamhaus.org=127.0.0.2, reject_rbl_client xbl.spamhaus.org, reject_rbl_client xbl.spamhaus.org=127.0.0.4, reject_rbl_client xbl.spamhaus.org=127.0.0.5, reject_rbl_client xbl.spamhaus.org=127.0.0.6, reject_rbl_client pbl.spamhaus.org, reject_rbl_client pbl.spamhaus.org=127.0.0.10, reject_rbl_client pbl.spamhaus.org=127.0.0.11, reject_rbl_client zen.spamhaus.org, reject_rbl_client zen.spamhaus.org=127.0.0.2, reject_rbl_client zen.spamhaus.org=127.0.0.4, reject_rbl_client zen.spamhaus.org=127.0.0.5, reject_rbl_client zen.spamhaus.org=127.0.0.6, reject_rbl_client zen.spamhaus.org=127.0.0.7, reject_rbl_client zen.spamhaus.org=127.0.0.8, reject_rbl_client zen.spamhaus.org=127.0.0.10, reject_rbl_client zen.spamhaus.org=127.0.0.11, reject_rbl_client dnsbl.sorbs.net, reject_rbl_client dnsbl.sorbs.net=127.0.0.2, permit
RBL is too restrictive.
