What is the main mail server? If it generates a proper DSN, then the the reverse envelope will be null because that is how DSNs work and Domino does not reject MAIL FROM:<>.
In any case, the error message would then be "Mail from <> rejected for policy reasons. Sender is denied in your configuration" and it is not.
I suspect the bounce being generated by the external mail server is broken somehow.
You could post headers of a sample here if you have them. That would help.
Chris Linfoot
http://chris-linfoot.net