hi Carolyn_Liu , thank you for the reply.
"Use the cert domain myorg.emailservice.com and keep everything else already setup (accepted domain and connector). and this is recommended. You should always use a specific domain, if possible, to avoid ambiguity."
-If my understanding is correct, can we mention the domain name myorg.emailservice.com as Subject alternative name of the certificate? Would that work?
2. 2nd option is not viable as the service would relay to other exchange tenants as well. In this case can we mention each of the tenant's unique domain name in the SAN like below:?
Example certificate-
CN = emailservice.com
Subject Alternative Name:
DNS:myorg1.emailservice.com, DNS:myorg2.emailservice.com, .....