Block Brute Force in SMTP

H
I need to block excess brute force in SMTP with access denied. By sniffer identified that the package receives the return 554 5.7.1 <mail@domain.com>: Relay access denied. I tried to place the lock through Firewall Filters using the “Content”, but without success. Anyone have any suggestions or example?

Tks

You can use the same technique used to prevent SSH brute forcing, dynamic address lists.