Restriction to localhost relaying only doesn't work in default configuration.
vulners.com/securityvulns/securityvulns:doc:9650