MarkusOE
yes, from your setup, mail.mydomain.de would match *.mydomain.de in the inbound connector, and the change from O365 in Nov. would not apply to you.
However, if in your on-prem system, you have another certificate that you use for TLS certificate, for example, internet.mydomain.de used for internet mail, then you should NOT use *.mydomain.de in the Inbound connector, because it will match with the inbound connector as well. Instead, you should use mail.mydomain.de in the inbound connector and add the domain as your accepted domain. Or better yet, always use one of your accepted domains as the SMTP envelop sender domain (P1 sender domain) from mails coming from your on-premises if you need to relay (use O365 to send email to external).