anti-spam/fake mail in smtp-policy: how?

Ok.. I allow all email from one of my internal mail hosts. BUT.. 

One of my users is "faking" email from work to look like it is his home
ISP account.

How can I from the smtp-policy rules stipulate the "@domain"
part that I will accept from his host.

I.E.: connect from valid-internal-ip
     MAIL From:<homeuser@homedomain>
     RCPT To:<homeuser@homedomain>

I would like to block this just after the MAIL From line.
@homedomain is invalid coming from the valid internal mail server ip.

Can I say something like: if you are connecting from IP A.B.C.D, then
you must
look like you are from one of the following domains: