Hello Dreher,
Please do the following on the CLI of the appliance to check if there is any connection attempts from the exchange to the appliance and then to find out the mail flow (as you said its not appearing in the message tracking logs something may be happening at connection level, or perhaps the email is not going through the appliance)
CLI > grep "exchange IP" -t mail_logs
Run a few test emails.
Monitor this log once you see some data you will see the connecting server to the appliance also what sendergroup it's matching after which if the email is accepted, an MID should appear where you will be able to review the message details as it goes through the appliance and the injected information.
do a findevent > search by MID and enter this MID
Or CLI > grep "MID XXX" mail_logs