CSF is running on my cPanel server and after quite a lot of Googling, it left me even more confused, as a lot of contradicting info is out there.

Problem: Anyone can connect to telnet port 25 and abuse internal mails (Relay access is not authorised) As an example if the server is hosting mails for xyz.tld:
Anyone could send email from jane@xyz.tld to joe@xyz.tld without any authentication.

How do I prevent, secure this? Is it possible to force authentication on port 25, and if yes what is the impact of this?
