Sophos MTA relay as smarthost desination

Reviewing the documentation on using the outbound relay with Exchange and having the outbound mta as a smart host. What prevents unauthorized servers from connecting to it and using it as an open relay and sending e-mail with my domain. I understand there is spf but wouldn't spf allow mail flow it since the sender IP at that point is matching to the Sophos relay IP?

