No manual do Exim (seção 38.1). Espero que isso ajude:
You can insist that any client that uses the AUTH command for authentication must start a TLS session first, by setting auth_over_tls_hosts. For example,
auth_over_tls_hosts = *
means that all authentication must take place over secure sessions. This setting does not force the matching hosts to use AUTH, but if they do, they must issue STARTTLS first. The availability of the AUTH command is advertised to such hosts only after a TLS session has been started.