When domains are unable to negotiate an acceptable cipher with the Symantec Messaging Gateway, the message is bounced instead of delivering it without TLS.
Symantec has resolved this issue in version 10.6.0.
To work around this issue until you can perform the upgrade, opportunistic TLS can be disabled for that domain, allowing the messages to send properly.