MAPS has a great index on what steps you can take to prevent spammers from abusing your mailserver (open relay); click here.
Of note, Microsoft Exchange 5.0 can not be secured against relaying at all. Exchange versions 5.5 and 6.0 will still relay by default, without some configuration changes to secure this issue.
Some users with investments in obsolete/insecure mailservers have reported success through 'hiding' that mailserver behind the firewall, and using a a secure mailserver or mail proxy to manage the incoming connections. This can be a solution to preventing relay abuse.
Copyright 1998-2008, Tzolkin Corporation. All rights reserved.