Is this someone trying to do something worse than the next example:
Jan 20 14:36:15 77dffe276832 postfix/submission/smtpd[30150]: improper command pipelining after CONNECT from unknown[179.43.185.238]: \022\001\000^\000\000\001\000\000\000$\000\006\001\000*\000\001\002\000+\000\001\003\000,\000\004\004\0000\000\001\005\0001\000$\006\000U\000\001\377\004\a\f\274\000\000\000\000\000\000\025\320\000P\364\337M\373\000\000\0008y\235w\367\177\000\000\000\000\000\000\000\000\000\000\000\000y\265\326\002\000\000\376\377\377\377\001
than this one:
184.189.122.139 matched rule id 3 (warning: wsip-184-189-122-139.oc.oc.cox.net[184.189.122.139]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=shannon.kersh)
netfilter-mailcow-1 | 1 more attempts in the next 600 seconds until 184.189.0.0/16 is banned