@Carolyn Liu
We have an organization that's a subdomain of our primary domain, for example we are contoso.com, they are subdomain.contoso.com. We have configured their domain in O365 and have them setup as an accepted domain in Exchange of type "internal relay".
We receive messages on their behalf, perform message hygiene and then pass the email to their server server1.subdomain.contoso.com. The emails are typically to lists, so server1 expands the email and sends it to each expanded recipient. This would be very similar
to your forwarding scenario above.
Server1 is also using O365 as a smarthost with an IP based connector. Would we need to use certificate authentication?
Thanks!