Mail protection internal mailserver on different port

our mailserver listens on port 2525 (Exchange, recipient check works on different connector), i fiddled around with a DNAT rule, but it did not work.

On standard frontend connector with port 25 the recipient filter does not work as expected (flaw by design).

We want to do recipient validation should with server request from mail protection, not by ldap query (two issues with that: no ldaps + contacts are not resolved).

How we can do this?

