Would it be possible to handle incoming mail from trusted systems different from incoming mail from untrusted systems?
Try (untested): match ! from src <allowed_ip_addresses> for any mail-from <domains> rejector any other action. But I am still pretty new here, so let's hope for some advice from the experienced postmasters.
-- Vladas (a.k.a. Uolys) https://on.lt/opensmtpd
