Hi ! I found that logging into ftp account (with proftpd) shows "Maildir" mail storage with the full rights to delete anything. Is this correct behavior?
Sure. The mail user is identical to the ftp user. If a user deletes a email trough pop3, imap or ftp makes no difference.