Hi, i noticed the following today. Is this part of the standard?
For recipient domain: MX 5 mx1.recipient.com - does not support TLS and refused delivery with temp error MX 10 mx2.recipient.com - does support TLS and took the mail Sep 18 10:36:29 B245080E75: TLS is required, but was not offered by host mx1.recipient.com[1.2.3.4] Sep 18 10:36:29 Untrusted TLS connection established to mx2.recipient.com[5.4.3.2]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits) smtp_delivery_status_filter was in place for above temp error, but it was not mapped to permanent error (which makes sense to me.