Setup guide
Mail → Setup guide lists what delivery needs, in order, with your servers’ addresses filled in. Every check runs against public DNS, so a green mark means the record is published.

Before you start
Section titled “Before you start”- Access to the DNS of each sending domain, or a Cloudflare token that reaches its zone.
- For direct delivery, access to the control panel where you rent each server.
Work through the guide
Section titled “Work through the guide”- Servers: give each server’s mail hostname an A record. For direct delivery, also set the server’s reverse DNS to that name and get outbound port 25 opened.
- Sending domains: publish SPF, then DKIM, then DMARC, which acts on the other two.
- Prove it works: send a test message from the relay and from a site to a Gmail or Outlook
address. Its headers should show
DKIM-Signature,spf=passanddkim=pass.
Choose Check DNS again after a change. All dev addresses count as one sending domain, since a key at the dev domain signs every site under it. Reverse DNS is set where you rent the server, and Where did you rent this server? gives the steps for common providers.
Let the panel publish the records
Section titled “Let the panel publish the records”With a DNS token, the guide writes the records instead of printing them: Publish on a domain, Publish A record on a mail hostname. It decides from the zone as it is at that moment, and reports what it did.
- SPF is merged into a published record, never replaced.
- Two SPF records, more than 10 DNS lookups, or a record that denies a server stop it. It says why.
- A published DMARC record is never changed, even a broken one.
- Other TXT records at the same name are kept.
- DKIM is published only once its key is on every server.
Add the Cloudflare token
Section titled “Add the Cloudflare token”Edge Add a Cloudflare API token under Settings, then DNS, with Zone → Zone → Read and Zone → DNS → Edit. It is the same token the wildcard certificate and the site records use.
Change the mail hostname
Section titled “Change the mail hostname”Reverse DNS has to match the hostname the relay announces. Each server has its own:
| Server | Default name |
|---|---|
| The panel’s server | mail. and the panel’s domain without panel.: panel.example.com gives mail.example.com |
| A server added from the panel | mail. and the dev domain, the same on every such server |
- Under Servers, pick the server and choose Change hostname.
- Type a name you control and choose Apply. The relay reloads without losing queued mail.
- Point an A record for the name at the server, then change its reverse DNS to match.
Receivers treat a new name as a new sender.
Go back to the default
Section titled “Go back to the default”Edge The dialog shows the default, MAIL_HOSTNAME from deploy/.env. A name
set in the panel wins over it and is kept when the relay restarts. Reset to default removes it,
and so does typing the default name. From a shell, this sets a new default and clears a name set in
the panel:
sudo /opt/wpl7/provision/setup.sh --mail-hostname=smtp.example.comLimits
Section titled “Limits”- Reverse DNS and a smarthost’s SPF value are always set by hand.
- Without a token, or for a zone it cannot reach, you add the records by hand. The panel publishes through Cloudflare only.
- SPF is planned for the delivery mode of the panel’s own server, and checked for IPv4 only.