There are a few solutions here, but its important to understand that messaging gateway is not a general purpose MTA, so you are going to be limited to some extent.
1) SMTP Auth. You can use SMTP Auth to lock down all hosts that can send with the exception of authenticated senders.
2) You can use the envelope conditions within content filtering to setup filters to delete/bounce mail based on conditiosn such as which sender or which domain is contained in the envelope sender/recipient.