There are a lot of ways to go about it. One I like is to limit their outbound. Let's take [email protected] and say I want to limit that sender to only be able to send 1 email a day. This will do it:
Does using the blacklist_senders file not prevent also mailing via php? I know the question was to limit SMTP. But I was just wondering if his account owners would start using php mail, he might still better use the blacklist_senders to prevent that too.
Personally I would warn them and then suspend them if they don't obey the rules from contract.