It is common for spammers to use that. It was not blocked initially, to be able to give users the opportunity who have valid allowable domains to easily be unsuspended given everything checks out.
Actually, DirectAdmin already has mail.mydomain.com as a subdomain, so I'm actually surprised it...