Heres the way I see it...
If you're an ISP, allow access to the box from the ip range that you give to customers
If this is for a school or business, they shouldn't need remote access. Make them email you, and of course if you want remote access then allow access to the box from your network
If you're simply offering an email service, don't know why you would, but make them email you to reset it.
just some thoughts, It might be easier to provide a solution if you tell us what you're using the sme server for and etc.
Thanks