SMTP security - disallowing unwanted connections?

Basic question : what mechanisms are in place to ensure that some remote party does not use my SMTP server to send out emails? Is the connection just validated with username and password, or are there other mechanisms in place?

If there are sufficient failures of a particular IP address to authenticate, that IP address is blocked using the firewall via Fail2Ban.

