I have both "Enable authentication" and "TLS authentication only" enabled on my server, but users are still able to send e-mail through smtp without a username and password.
here's the output of "zmprov gs zimbra.mydomain.com"
cn: zimbra.mydomain.com
description: E-mail Server
objectClass: zimbraServer
zimbraAdminPort: 7071
zimbraAdminURL: /zimbraAdmin
zimbraAttachmentsIndexedTextLimit: 1048576
zimbraBackupAutoGroupedInterval: 1d
zimbraBackupAutoGroupedNumGroups: 7
zimbraBackupAutoGroupedThrottled: FALSE
zimbraBackupMode: Standard
zimbraBackupReportEmailSubjectPrefix: ZCS Backup Report
zimbraBackupTarget: /opt/zimbra/backup
zimbraClusterType: none
zimbraFileUploadMaxSize: 10485760
zimbraHsmAge: 30d
zimbraHttpNumThreads: 250
zimbraHttpSSLNumThreads: 50
zimbraImapBindOnStartup: TRUE
zimbraImapBindPort: 143
zimbraImapCleartextLoginEnabled: TRUE
zimbraImapNumThreads: 200
zimbraImapProxyBindPort: 7143
zimbraImapSSLBindOnStartup: TRUE
zimbraImapSSLBindPort: 993
zimbraImapSSLProxyBindPort: 7993
zimbraImapSSLServerEnabled: TRUE
zimbraImapSaslGssapiEnabled: FALSE
zimbraImapServerEnabled: TRUE
zimbraLmtpBindOnStartup: FALSE
zimbraLmtpBindPort: 7025
zimbraLmtpNumThreads: 20
zimbraLogToSyslog: FALSE
zimbraMailDiskStreamingThreshold: 1048576
zimbraMailMode: redirect
zimbraMailPort: 80
zimbraMailPurgeSleepInterval: 0
zimbraMailSSLPort: 443
zimbraMailURL: /zimbra
zimbraMemcachedBindPort: 11211
zimbraMessageCacheSize: 1671168
zimbraMtaAuthEnabled: TRUE
zimbraMtaAuthHost: zimbra.mydomain.com
zimbraMtaAuthTarget: TRUE
zimbraMtaAuthURL: https://zimbra.mydomain.com/service/soap/
zimbraMtaDnsLookupsEnabled: TRUE
zimbraMtaMyDestination: localhost
zimbraMtaMyNetworks: 127.0.0.0/8 (external IP)/24 (internal IP)/24
zimbraMtaTlsAuthOnly: TRUE
zimbraNotebookFolderCacheSize: 1024
zimbraNotebookMaxCachedTemplatesPerFolder: 256
zimbraNotebookPageCacheSize: 10240
zimbraNotifyBindPort: 7035
zimbraNotifySSLBindPort: 7036
zimbraNotifySSLServerEnabled: TRUE
zimbraNotifyServerEnabled: TRUE
zimbraPop3BindOnStartup: TRUE
zimbraPop3BindPort: 110
zimbraPop3CleartextLoginEnabled: FALSE
zimbraPop3NumThreads: 100
zimbraPop3ProxyBindPort: 7110
zimbraPop3SSLBindOnStartup: TRUE
zimbraPop3SSLBindPort: 995
zimbraPop3SSLProxyBindPort: 7995
zimbraPop3SSLServerEnabled: FALSE
zimbraPop3SaslGssapiEnabled: FALSE
zimbraPop3ServerEnabled: FALSE
zimbraRedoLogArchiveDir: redolog/archive
zimbraRedoLogDeleteOnRollover: TRUE
zimbraRedoLogEnabled: TRUE
zimbraRedoLogFsyncIntervalMS: 10
zimbraRedoLogLogPath: redolog/redo.log
zimbraRedoLogRolloverFileSizeKB: 102400
zimbraRemoteManagementCommand: /opt/zimbra/libexec/zmrcd
zimbraRemoteManagementPort: 22
zimbraRemoteManagementPrivateKeyPath: /opt/zimbra/.ssh/zimbra_identity
zimbraRemoteManagementUser: zimbra
zimbraReverseProxyLookupTarget: TRUE
zimbraScheduledTaskNumThreads: 20
zimbraServiceEnabled: antivirus
zimbraServiceEnabled: antispam
zimbraServiceEnabled: logger
zimbraServiceEnabled: mailbox
zimbraServiceEnabled: mta
zimbraServiceEnabled: stats
zimbraServiceEnabled: snmp
zimbraServiceEnabled: ldap
zimbraServiceEnabled: spell
zimbraServiceHostname: zimbra.mydomain.com
zimbraServiceInstalled: antivirus
zimbraServiceInstalled: antispam
zimbraServiceInstalled: logger
zimbraServiceInstalled: mailbox
zimbraServiceInstalled: mta
zimbraServiceInstalled: stats
zimbraServiceInstalled: snmp
zimbraServiceInstalled: ldap
zimbraServiceInstalled: spell
zimbraSmtpHostname: zimbra.mydomain.com
zimbraSmtpPort: 25
zimbraSmtpSendPartial: FALSE
zimbraSmtpTimeout: 60
zimbraSoapRequestMaxSize: 15360000
zimbraSpellCheckURL: http://zimbra.mydomain.com:7780/aspell.php
zimbraTableMaintenanceGrowthFactor: 10
zimbraTableMaintenanceMaxRows: 1000000
zimbraTableMaintenanceMinRows: 10000
zimbraTableMaintenanceOperation: ANALYZE
zimbraVirusDefinitionsUpdateFrequency: 2h
zimbraXMPPEnabled: TRUE
SMTP Auth not working
SMTP Auth not working
This is most likely because your users are in the zimbraMTAMyNetworks. Whoever sits in those subnets are considered trusted and do not have to authenticate.