I have seen times where usually a firewall might be blocking this type of traffic. There could be a few things to do on this issue. First option enable debug logging for Domain (if only one domain is the problem) or delivery logs (this will increase...
What the HAT is being triggered, go to the MAIL FLOW policy for that for that sender is triggered on, and scroll down to Sender Verification. See if this is enabled.
Can you verify the HAT sender group its hitting, then verify the Sender group settings for this IP/hostname. In those settings if the 'Connecting host PTR record does not exist in DNS.' is checked, it might be dropping it there.
Andrii, That is bouncing because that domain does not exist. '4.1.8 <iwogpood@bhoxporg.cn>: Sender address rejected: Domain not found'] https://www.whatsmydns.net/#A/bhoxporg.cnhttps://talosintelligence.com/reputation_center/lookup?search=bhoxporg.cn...
First off the Manual info is here to start.https://www.cisco.com/c/en/us/td/docs/security/esa/esa13-5-1/user_guide/b_ESA_Admin_Guide_13-5-1/b_ESA_Admin_Guide_12_1_chapter_011001.html?bookSearch=true Check out what your current certificate is using a ...