Thanks Carolyn_Liu,
Yes, to guarantee deliver of email to external recipients the correct SPF, DKIM, DMARC records are required to be published for the sender domains. My questions are confined to the scope of how the relay and connector require to be configured.
With certificate authentication we satisfy conditions 1.a and 2 of both the Current and New Requirements. Hence the O35 connector will work with any sender (P1, P2) and recipients domains.
With IP authentication it seems a bit more complicated.
Given the above agreed statement about when recipients are an accepted domain, this doesn’t seem to satisfy the Current or New requirements e.g. it satisfies condition 2. But none of the 1. Conditions (there is no certificate and the P1 and P2 senders are not an accepted domain).
Do these 1. conditions only apply when sending to non-accepted domains internal domains or external recipients?
It does look like changing from IP to certificate authentication would be the best option in out case but want to make sure I better understand how both work as any impact resulting from this change would be very disruptive.
Best regards
Owain