Exchange Online has the problematic behaviour to rename e-mail addresses when somebody sends an E-mail to an alias. This prevents E-mail decryption in many ways, that is the SEPPmail domain encryption, and others. What happens is that the private decryption keys for the re-written alias addresses do not fit any more.
data:image/s3,"s3://crabby-images/f300e/f300e51f8140622cc4200268279ec7376ba625f9" alt="empty empty"
Beginning with 2022, Microsoft has announced a beta-feature for Exchange Online that does not rewrite domains any more. The feature is in public preview and can be activated with the following command:
Set-OrganizationConfig -SendFromAliasEnabled $TRUE
This setting prevents the alias rewrite and allows it for SEPPmail to use the correct keys for decryption.
data:image/s3,"s3://crabby-images/279df/279df8bbbd4ad3e19db0ef2f27287c5c2d9c0ec6" alt="empty empty"
See the original blog from Microsoft for more information.