
Explanation

For the requirement that all email messages from the internet must first be filtered by a third-party cloud service before being delivered to Exchange Online, you should use an MX record1. An MX record specifies the mail server that is responsible for accepting email messages on behalf of your domain1
. You need to configure your MX record to point to the third-party cloud service's mail server, and then configure the third-party cloud service to forward email messages to Exchange Online1.
For the requirement that recipient email systems must validate the messaging server for contoso.com, you should use an SPF TXT record . An SPF TXT record is a type of DNS record that identifies which mail servers are authorized to send email on behalf of your domain . It helps prevent spoofing and phishing by verifying the sender's IP address against the list of authorized IP addresses in your SPF TXT record2. You need to configure your SPF TXT record to include both the third-party cloud service and Exchange Online as authorized senders for your domain2.