{{define "content"}}

{{.Domain.Name}}

← All domains {{if .Flash}}
{{.Flash}}
{{end}} {{if .RateLimitErr}}
{{.RateLimitErr}}
{{end}} {{if .NewCred}}

New application password

This password is shown once only and is not stored. Copy it now — if it is lost, regenerate a new one.

{{.NewCred.Login}}
{{.NewCred.Password}}
{{end}}

DKIM DNS record

Publish this TXT record in the DNS for {{.Domain.Name}}. It is not a secret and can be viewed at any time.

{{.Record.Name}}
TXT
{{.Record.Value}}

Also configure SPF and DMARC for the domain (see the documentation). Mail is signed with selector {{.Domain.DKIMSelector}}.

Sending server settings

Point the mail client or script at these settings and authenticate with an application login and password from the Applications section below. They are the same for every domain on this server.

{{.Hostname}}
465 — SSL/TLS (implicit){{if .SubmissionEnabled}} 587 — STARTTLS (submission){{end}}

Authentication is required on every port. The username is the application's login (see the table below) and the password is the one shown once when that application was created or its password regenerated — if it was lost, generate a new one.

Applications

Each application is a SASL login/password an app or script uses to send mail as this domain. A login may send from any address of the domain (wildcard) or only from a fixed list of addresses.

{{if .Apps}} {{range .Apps}} {{end}}
LoginModeAddresses
{{.Login}} {{if eq .AddressMode $.Wildcard}}Any address (@{{$.Domain.Name}}){{else}}List{{end}} {{if eq .AddressMode $.Wildcard}}*@{{$.Domain.Name}}{{else}} {{range $i, $a := .Addresses}}{{if $i}}, {{end}}{{$a}}{{end}} {{end}}
Edit mode
Rate limit{{if .HasLimit}} (active){{end}}
{{if .HasLimit}}
{{end}}
{{else}}

No applications yet. Create one below.

{{end}}

Sending rate limit (domain)

Optional level-2 limit (spec 7.4): cap how many messages this domain may send from its expected client IP(s) within a time window, summed across all its applications. It counts messages — one message to many recipients counts once. Leave the IP list empty to disable it and rely only on the global level-1 limit. Applications that send from changing IPs should be left unbound here.

Status: {{if .DomainHasRL}}active{{else}}inactive (level-1 only){{end}}.

{{if .DomainHasRL}}
{{end}}

Add an application

{{if .Error}}

{{.Error}}

{{end}}

A strong password is generated and shown once. The login must be unique across all domains and may contain letters, digits, '.', '-' and '_'.

Export domain

Download this domain to move it to another SelfPost instance: its DKIM key, selector and every application with its working password. On import the DNS record stays the same, so no DNS change is needed.

The export file is a secret — it contains the private DKIM key and application passwords. Transfer it securely and delete it after the import.

Danger zone

Deleting this domain also deletes its DKIM key and every application bound to it.

Delete domain
{{end}}