@Carolyn Liu
In this example contoso.com is a domain in an O365 tenant, subdomain.contoso.com is also a domain in the same O365 tenant but the tenant is configured as an internal relay for subdomain.contoso.com. Any messages to @subdomain.contoso.com recipients that cannot
be delivered within O365 will be relayed to server1.subdomain.contoso.com which is authoritative for subdomain.contoso.com.
The sender can be anyone including @contoso.com, O365 would just be used as the ingress/egress points for subdomain.contoso.com so we can provide inbound message hygiene and authenticated email relaying.
The way I read the document we would need a certificate on server1.subdomain.contoso.com.