@Douglas Plumley
If I understand correctly, you are asking whether a mail sent from your organization in Office 365 to your on-premises requires a certificate. The scenarios in the blog only apply to messages sent FROM on-premises environment and relayed THROUGH Office 365
to recipients that are not belong to your organization. It does not apply to mails sent from your organization in Office 365 (subdomain.contoso.com) to your on-premises environment (server1.subdomain.contoso.com). That is a different scenario and no change
in that direction. For that direction, Office 365 supports all scenarios: plain SMTP, TLS (via self-signed certificate or CA signed certificate).