{{/* Wide so the .split pairs fill the column rather than the 48rem reading measure (same pattern as Status). */}} {{define "wide"}}wide{{end}} {{define "content"}}
Shown once only and not stored. Copy it now — if it is lost, regenerate a new one.
Publish this TXT for {{.Domain.Name}}. It is not a secret.
Signed with selector {{.Domain.DKIMSelector}}.
Cached a few minutes — use Re-check after publishing.
{{.DNS.DKIM.Detail}}
{{if .DNS.DKIM.Records}}{{range .DNS.DKIM.Records}}{{.}} {{end}}{{end}}{{.DNS.SPF.Detail}}
{{if .DNS.SPF.Records}}{{range .DNS.SPF.Records}}{{.}} {{end}}{{end}}Shallow check: literal address only, no
include: / redirect=.
{{.DNS.DMARC.Detail}}
{{if .DNS.DMARC.Records}}{{range .DNS.DMARC.Records}}{{.}} {{end}}{{end}} {{if .DNS.DMARCReportAuth.Status}}{{.DNS.DMARCReportAuth.Detail}}
{{if .DNS.DMARCReportAuth.Records}}{{range .DNS.DMARCReportAuth.Records}}{{.}} {{end}}{{end}} {{end}}Suggested TXT. If the domain already has SPF, merge this server's mechanism into it — do not add a second record.
Policy TXT. SelfPost is send-only — omit rua=
or point it at a mailbox elsewhere (Settings default
or custom below).
The report address is on this sending domain. SelfPost does not receive inbound mail — use a mailbox elsewhere or wait for in-panel report reception in a future release.
{{end}} {{if .NeedsReportAuth}}p=none does not affect delivery. Tighten to
p=quarantine then p=reject once reports look clean.
Same for every domain. Authenticate with an application login from below.
Auth required on every port. The password is shown once at create or regenerate.
Password shown once. Login unique across domains; letters, digits, '.', '-' and '_'.
SASL logins for this domain — wildcard (*@domain) or a fixed address list.
{{if .Apps}}{{.Login}}
{{if eq .AddressMode $.Wildcard}}Any address of the domain — *@{{$.Domain.Name}} {{else}}Fixed list — {{range $i, $a := .Addresses}}{{if $i}}, {{end}}{{$a}}{{end}}{{end}}
No applications yet. Add one above to get started.
{{end}}Optional level-2 cap across this domain's applications from the listed client IPs. Empty IP list = inactive (level-1 only).
Status: {{if .DomainHasRL}}active{{else}}inactive (level-1 only){{end}}.
{{if .DomainHasRL}} {{end}}DKIM key, selector and application passwords for another SelfPost instance. DNS stays the same on import.
Secret file — transfer securely, or encrypt
below as .spde.
{{.ExportErr}}
{{end}}On this page
{{if .NewCred}}New application password{{end}} DKIM DNS record DNS status SPF record DMARC record Sending server settings Add an application Applications Sending rate limit Export domain Danger zone