The problem: authenticated user can supply any "FROM".
The mail server is used as a smarthost. The server cluster.xx send a letter via mail.xx, authorizing as no-reply@mail.xx - this is correct. Next, I remove all Received, that would not be seen, that the letter formed cluster.xx , but the sender's address local_user@clus...