To trust the TLS connection with an external party using its own internal CA, the engineer must enable a custom list on the Network > Certificates page and upload the external CA's certificates. This allows the Cisco Secure Email Gateway to validate and trust certificates signed by that internal CA.