Checking my logs I see that some senders are trying to fake our domain and use our server to send mails to third parties masquerading as one of our own domains (without authenticating first).
They are stopped by smtpd with response 'Relay access denied', but instead of 5xx permanent rejection smtpd gives 454 4.7.1 temporary rejection, which surely encourages them to keep trying. Why is this, and can I change it?