Hi @Mike00
If the certificate does not have an accepted domain as a subject or in the CN, it will be rejected:
https://learn.microsoft.com/en-us/exchange/troubleshoot/connectors/office-365-notice
Beginning July 5, 2017, Office 365 no longer supports relaying email messages if a hybrid environment customer has not configured their environment for either of the step 3 conditions. Such messages are rejected and trigger the following error message:
550 5.7.64 Relay Access Denied ATTR36. For more details please refer to KB 3169958.
Additionally, you must meet the second condition ("certificate-based connector configuration") in step 3 in the "Introduction" section if your organization requires that any of the following scenarios continue to work after July 5, 2017.