I notice that Jack was the original OP, not you: my apologies for that as I've 
been responding as if he were you...

Paraphrased, Jack asked: "How can I stop the backup MX from accepting mail for 
users that don't exist on the primary server?". He elaborated that LDAP would 
be 'overkill' on a 'small system'.

Arbitrarily and bogusly, I've admined small mail systems for some time. My 
experience has been that backups see very little mail going through them, 
compared to the primary and that backups in small systems deliver mail 
onwards to the primary. This is not to assert this is the only way of 
handling things: it isn't (though I can see how what I wrote might be taken 
that way). It's not to assert that anyone who handles things differently is 
'wrong'; it isn't to suggest that this is how google or hotmail do things -- 
I'm sure they don't. 

It's to say that in my view of his situation, it is acceptable for a backup to 
accept all properly addressed mail on behalf of that unavailable primary (ie, 
act as a mail relay), and that MX order is a viable way of presenting it to 
the world.

Now I'm going to put a sticky note on my screen to read "Always check the 
'from' line". Doh!
