There aren't really any significant security implications. The SMTP authentication uses CRAM-MD5, so your password isn't visable, and SMTP is gong to be relayed onwards without SSL in any case.
