There is probably other ways to archive this, but the solution below is something I have tested, which works.
If you create a new custom public listener on a new virtual gateway, where you can then add a new RAT. In here you can specify which e-mail addresses and or domains that is allowed.
you can then use the new IP interface to deliver e-mail. Since you are using RAT now, the IronPort will only accept
recipients that are in the RAT.