@tedu @cjd That's not a defined-in-AP behavior. I'd argue the reason that's happening is because we haven't gotten convergence on the ability to sign submitted posts themselves and Pleroma doesn't "trust" the content unless it can retrieve it in general IIUC. This wouldn't need to happen if we had authenticated messages.
Datashards can help too, but this also illustrates why we'll want to add authentication to messages for Datashards to take off too (checking the "origin" won't be enough).