We haven't been able to deliver the message yet to the recipient because we can't connect to your organization's on-premises ...

We haven't been able to deliver the message yet to the recipient because we can't connect to your organization's on-premises email server. Either your organization's firewall is blocking messages sent from Office 365 to port 25, or your server isn't running. Please review these details:

Recipient: {Recipient}
Email server name: {DestinationMailServer}
Email server IP address: {DestinationIP}
Connector name: {ConnectorName}
Technical error message: {MessageDetail}

To fix the problem, your firewall administrator needs to open port 25.
For more information, see Network ports for clients and mail flow in Exchange 2013. You need to allow messages from the IP addresses listed in Exchange Online Protection IP addresses.
We'll keep trying to send the message for a total of 48 hours. After that, Office 365 will stop trying to send the message and will return a non-delivery report (NDR) to the sender.