This might be related to wingmans report https://community.sophos.com/products/unified-threat-management/astaroorg/f/110/t/70665 where his smtp daemon is crashing but in any case here is the bug.
There is a box for skipping TLS negotiation for certain hosts however it doesn't work for the internal mail server. Couldn't test on external server but it might be broken for that too.
Screenshot 1: TLS enabled for every host and skip TLS enabled for my exchange server postmaster (192.168.0.1)
Screenshot 2: Outbound connections from postmaster (192.168.0.1) are lost without any error in the logs. This is a secondary bug, there should be some kind of error in the logs instead of a dropped connection but maybe exim behaves this way.
Screenshot 3 : Inbound connections complain about TLS not being enabled.
Regards
Bill.