> I'm not sure how that makes much of a difference since the usual spam  
> vector is malware that has  (almost) complete control of the machine  
> in the first place.

Well, that depends on MUA design, of course, but it's just been pointed
out to me that the RFC says MAY, not MUST. 


Does anyone bother to run an MSA on 587 and *not* require authentication?

