This policy works: https://gitea.kosmos.org/kosmos/akkounts/src/commit/0daac33915f827494feb4a5d6bb9ba5d49e6b904/extras/strfry/ldap-policy.ts#L18-L40
I think everyone running a members-only relay should do this. Unless I missed something, in which case I'd love to learn why it's a bad idea!