Andres-Bohren
Answer to your questions below:
"
We have an OnPrem Inbound Connector mail.domain.tld with a certificate mail.domain.tld.
TlsSenderCertificateName is set to mail.domain.tld.
Do we need to change the TLSSenderCertificate to *.domain.tld?
We have multiple domains. Can we also relay with domainAAA.com through this connector?
Or in other words, does the certificate domain need to match the used P1 Senderdomain?
"
No, you do not need to change the certificate domain to be a wildcard domain. So long it matches with what is set in the Inbound OnPremises connector. In addition, so long the certificate domain is an accepted domain, you can use it for O365 to accept email sent from other domains.