For the email settings in the GUI for a RAQ4: POP Before SMTP Relaying Relay Window (in minutes) If the relay window is open, does that mean pretty much *anyone* can send/receive mail through the server if they fake the A record in their email program (like mail.suchandsuch.com as a setting in Outlook POP server without needing a user/pass)?
Not just anyone can relay. They have to have a valid username and password. poprelayd looks for the authentication string in /var/log/maillog. Then IP address is then added to the auth database for the duration of the window. Each successive authentication resets the "timer"...