That is when it becomes your job (as the administrator or hosting provider) to educate your users on the root cause. Your Support department exists to connect the dots between '602 error' and 'the people you're sending to aren't adhering to standard best practice security requirements.' That said, I do believe strict enforcement should prevent delivery though the help is a bit vague on this front:
Enforce strict certificate validation - This setting prevents the server from connecting to servers over SSL/TLS that have an invalid certificate For example, this prevents SSL/TLS connections to servers with out-of-date certs or domain name mismatches on their certificate.
It doesn't clarify whether or not SmarterMail should then attempt an insecure delivery to ultimately hand off the message. I'm going to do some testing on this and ping our development team on this to get some more details and I'll follow up with you guys here as I find out more.
Kyle Kerst
Lead Internal Network/System Administrator
SmarterTools Inc.
smartertools.com