SMTP Recipient Exception Handling

Hello –  Need some help determining how the system would handle the following:

Have some SMTP policies that have response rules configured to force encrypt based on detected content, but also have some recipient email domains configured as exceptions in the Groups tab since we have forced TLS setup with them. (btw, the exception condition is configured to detect if “any” recipient matches.)

Question:  If a message is sent that includes an exception domain recipient but also has a non-exception domain recipient, does the system process the message and force encrypt it? 

Or discard it because exceptions fire first, and the message would go out unencrypted to the non-excepted domain recipient? (not desired state)

Does this need to have individual exceptions added for each domain that are set to detect only when “all” recipients match?  Is there a better way to handle this when ?

