The clear-or-private group acts just like the clear group for outgoing packets.
However, should a remote system attempt to attempt OpportunisticEncryption, it will be permitted.
A busy server should probably put 0.0.0.0/0 into the clear-or-private group, and list a TXT record. That will permit systems that have OpportunisticEncryption enabled to establish private connections, while not impeding any flow for other users.