Apple's Mail.app does not support TLSv1.2 until OS 10.12 Sierra. Yes, I know that is only one version back. So we all have to continue to run TLSv1.0 even after the PCI deadline of June 30th this year. It sucks, and it make anybody who does not have their mail server totally isolated both on the logical network and the the physical network in violation of PCI 3.1, but Apple is not the only ones at fault (as much as I wish I could point that finger.) If you turn off TLSv1.0 in your cipher suites you will find even the newer versions of Outlook also fail.
John C. Reid / Technology Director
John@prime42.net / (530) 691-0042
1300 West Street, Suite 206, Redding, CA 96001