In the manual for Mailman there is a function to restrict posting to list members. I have looked at every page in the admin interface and can't find it. Where the heck is it?
"Restrict posting privilege to list members? (member_posting_only) Under nearly all circumstances this should be set to "yes." This restriction will cause Mailman to hold for administrative review all posts to the list that do not originate from a list member. Setting this to yes prevents you from being spammed by people who manage to get a hold of your list address."