{{/* Wide so the .split pairs fill the column rather than the 48rem reading measure (same pattern as Status). */}} {{define "wide"}}wide{{end}} {{/* The Host/name ‖ Type field-pair repeats for every DNS record this page shows (DKIM, SPF, DMARC, report authorization) in both the status card and the publishable-record cards below it — only the host and whether it carries a Copy button change. Two variants rather than one templated Copy flag: the DNS status card never offers Copy (its host is derived, not something to paste), the record cards always do. */}} {{define "host_type"}}
Shown once only and not stored. Copy it now — if it is lost, regenerate a new one.
Cached a few minutes — use Re-check after publishing.
{{.DNS.DKIM.Detail}}
{{end}}{{.DNS.SPF.Detail}}
{{end}}Shallow check: literal address only, no include: /
redirect=.
{{.DNS.DMARC.Detail}}
{{else}}{{.DNS.DMARC.Detail}}
{{end}}{{.DNS.DMARCReportAuth.Detail}}
{{else}}Not required (no external rua=).
DKIM
{{template "host_type_copy" .Record.Name}} {{template "field_value" .Record.Value}}Not a secret. Signed with selector {{.Domain.DKIMSelector}}.
SPF
{{template "host_type_copy" .Domain.Name}} {{template "field_value" .SPFExample}}Merge into an existing SPF if the domain already has one — do not publish a second record.
The report address is on this sending domain.{{if not .DMARCIngestEnabled}} SelfPost does not receive inbound mail — use a mailbox on another domain.{{end}}
{{end}} {{if and .DMARCIngestEnabled .ResolvedDMARCEmail}}View DMARC reports for this domain.
{{end}} {{if .NeedsReportAuth}}Report authorization
{{template "host_type_copy" .ReportAuthName}} {{template "field_value" .ReportAuthValue}} {{end}}p=none does not affect delivery. Tighten to
p=quarantine then p=reject once reports look clean.
Report address is set under Domain settings.
Same for every domain. Authenticate with an application login from below.
Auth required on every port. The password is shown once at create or regenerate.
Password shown once. Login unique across domains; letters, digits, '.', '-' and '_'.
One message = one queue id (many recipients count once). Level-1 refusals are not in the send log — totals under-count strict IP limits.{{if .StatsRetentionWarning}} Send log retention is shorter than 30 days; statistics use the last {{.StatsWindowDays}} days only.{{end}}
SASL logins for this domain — wildcard (*@domain) or a fixed address list.
{{if .Apps}}{{.Login}}
{{if eq .AddressMode $.Wildcard}}Any address of the domain — *@{{$.Domain.Name}} {{else}}Fixed list — {{range $i, $a := .Addresses}}{{if $i}}, {{end}}{{$a}}{{end}}{{end}}
{{.Stats.Total}} msg / {{$.StatsWindowDays}}d · peak {{.Stats.PeakPerHour}} msg/h · avg {{.Stats.AvgPerHour}} msg/h
Address mode
Which From addresses this application may use.
Client IP allow-list {{if .AuthIPRestrict}}active{{else}}off{{end}}
When enabled, only these addresses may authenticate and submit mail as this application. When off, any client IP is allowed.
Level-2 rate limit {{if .HasLimit}}active{{else}}inactive{{end}}
Overrides the domain limit for this application — the ceiling may be higher or lower than the domain setting (≤ level 1). When unset, the domain limit{{if $.DomainHasRL}} ({{$.DomainRLMaxNum}}){{end}} or level 1 applies.
No applications yet. Add one above to get started.
{{end}}Secret file — transfer securely, or encrypt
below as .spde.
{{.ExportErr}}
{{end}}