You should have Grey listing on for all domains. Then Enable users to override greylisting , They can Use Trusted sender to bypass all checks, yes Greylisting also.
Skipping spam filtering: Trusted Sender (system level)
System administrators should note that the following cases are exempt from greylisting:
- Whitelisted IPs for SMTP or Greylisting
- Anyone who authenticates (includes SMTP Auth Bypass list)
- Trusted senders
- Anyone who has already sent you an email
- Any IP in the greylistBypass.xml file