Well, who are the submissions to? are these legit recipients within your org? I'm not sure that this problem is related to "open relay", as this would describe the behavior of a server relaying email from the internet and back out to the internet without authentication.
There is also an option to reject messages to recipients who are not in the GAL. If you enable this, you might reduce the load on your transport servers.
Mike Crowley A+, Network+, Security+, MCT, MCSE, MCTS, MCITP: Enterprise Administrator / Messaging Administrator