Hi,
In my opinion, the recipient verification is to reject not known addresses with the utm and not relay to backend SMTP Server.
I tried callout or AD verfication to an Exchange 2013 and get in both ways a NDR-Message from the Exchange and not Sophos…