We did manage to solve part of this issue by following the procedure listed in
Restrict sending to certain domains - Zimbra :: Wiki instead of passing the mydomain.com as allowed we rectricted it and then put a rule to on each and every account to be checked.
I will be posting the entire script and procedure by the end of the week after we have the entire server setup. Its been a pain applying the security on each and every account (750 mail boxes) with management being allowed to send to all domains and groups etc.
Hope this is passed by the IT audit team or else :-( i have no idea what do