If it were me, I'd set up a proxy server at the network edge that can trap protocol traffic and log it. You can *see* what Exchange is sending as it sends it at that point. If you don't see BCC addresses in the SMTP envelope (which I suspect you won't) then you can push back on AuthSMTP.
-Cliff