It's worth noting that this thread http://comments.gmane.org/gmane.network.dns.dnsmasq.general/7778 from a couple years ago suggests that there's no mechanism to limit dnsmasq's resolver to specific client addresses/ranges either (unless that's been implemented more recently?), so chances are this will need to be solved with a packet filter somewhere.
It's worth noting that this thread http:// comments. gmane.org/ gmane.network. dns.dnsmasq. general/ 7778 from a couple years ago suggests that there's no mechanism to limit dnsmasq's resolver to specific client addresses/ranges either (unless that's been implemented more recently?), so chances are this will need to be solved with a packet filter somewhere.