just to confirm what Viktor_Dukhovni mentioned, for anyone on O365 it's possible already to setup MTA-STS (as long as they keep the certificates valid).
Personally I did setup the mx as:
mx: *.mail.protection.outlook.com
The reason behind this is that Microsoft asks for a MX publication with <domain>-<tld>.mail.protection.outlook.com from their "wizard".
The only issue at this moment is that this works when the G-Suite platform (internet, MTA-STS capable) is communicating with (to) the O365 platform, not the other way around (O365 > G-Suite).
To properly contribute to the email ecosystem internet standards need to be implemented from a sending AND receiving perspective, so both parties (Google & Microsoft and others) need to play ball.