I think the de-facto rationale for a larger network goes like this:
-- You don't want to get your IPs blacklisted because infected clients 
   send spam from within your network.
-- Other sites will allow mail submission on their submission port only 
   after authentication (SASL).
So you block outgoing smtp, but allow outgoing submission.

Reply via email to