Hello,
Yes, the VRFY command would be enabled only for the relays (I don't know how

)
Humm...the antispam gateways check the inbound messages and then deliver these to the CPanel servers (I think that using the word "gateway" you've thought that was for the outgoing mail). The problem is that these relays/gateways accept the email without check if the email account exists on CPanel server so then, can generate the misdirected bounces.
The best solution would be a LDAP server with all users, domains or anything similar...but I don't know if this is possible with Cpanel.
Thanks!
Regards,
Alvaro.