I had the same problem some days ago.
I do not trust any CA, so no CA is in my truststore. However, some days
ago, I posted to lists.gentoo.org. They have a valid TLSA entry but exim
told me that it can't be validated so the mail stuck in queue.
After I enabled (themporarily) the random CA they use, I got a
successfull delivery with the log file saying that it was validated via
- --
Klaus Ethgen http://www.ethgen.ch/
pub 4096R/4E20AF1C 2011-05-16 Klaus Ethgen <Klaus@???>
Fingerprint: 85D4 CA42 952C 949B 1753 62B3 79D0 B06F 4E20 AF1C