After more than 1 year PFS it is still not possible with Sophos SMTP Mail Proxy.
This thread was automatically locked due to age.
In 9.207, the SMTP relay will prefer to use a DHE family algorithm, which does support PFS. This is not directionally dependent, so this will equally support PFS for inbound and outbound connections.
Hey! Great news!
However for me it still doesnt work.
I have tested with: https://ssl-tools.net/mailservers
Which version of UTM are you on?