> And looks like it could be done without additional submission port,
> with help of MacroList configuration keyword and "auth_authen" macro
> name...

even you only use the host in question only for submission
it's always good practice to distinguish submissions from
trusted/authenticated/own users
from public inbound mx (for example by using the dedicated submission port)

But that's not related to opendkim...

