This is an entirely different problem, completely independent of the outbox model.

Relays can and should do spam protection, certainly

Outbox model is about to/from which relays to read/write not what ACL each relay applies