Do not offer TLS. (This mitigation is not recommended.)
-For a attacking SNI the following ACL snippet should work:
+For a attacking TLS client the following ACL snippet should work:
# to be prepended to your mail acl (the ACL referenced
# by the acl_smtp_mail main config option)