Add these at your domain registrar (Cloudflare, Namecheap, GoDaddy…).
| Type | Host | Value |
|---|---|---|
| MX | @ | mail.ronaldhenriquez.comPriority 10 |
| A | 65.20.98.56Mail server. The MX above points here, so mail cannot be delivered until this resolves. |
|
| A | webmail | 65.20.98.56Web interface. Both names are validated when the certificate is issued. |
| TXT | @ | v=spf1 a:mail.ronaldhenriquez.com ip4:65.20.98.56 mx ~allSPF |
| TXT | una._domainkey | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqEtp0Lswia1j09cMzfGygXVZOw1/2BH2Zr0PlUYpR+Ohl4r9iCOw0qPYwWXLcVE5Q8Ic3RaItqggFxIFOqRD2gWYaMFTSLD7aMYMY50TLEOyISap4502PtfDWR55P5mmjFi+aoY91FsokTP3x0nadx3a3R4ry1XujUMi/clRD0uS+WrnJzjt90I8tr3V8Zo+PPp8IXCvtFp8F00ow/nDCy3Bp2oAR79sJqzhFnOmNG9yAnWGr57dAAW4vnsm3tvxSvjZG2kJDTrteUNmIrFkBXynk7/s/6M8RfEojNLbA4kU6zgtNum6EG9N3/49KqRoWEIvhCPM+YbUAKE3OWK0kwIDAQABDKIM |
| TXT | una._domainkey.mail | v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqEtp0Lswia1j09cMzfGygXVZOw1/2BH2Zr0PlUYpR+Ohl4r9iCOw0qPYwWXLcVE5Q8Ic3RaItqggFxIFOqRD2gWYaMFTSLD7aMYMY50TLEOyISap4502PtfDWR55P5mmjFi+aoY91FsokTP3x0nadx3a3R4ry1XujUMi/clRD0uS+WrnJzjt90I8tr3V8Zo+PPp8IXCvtFp8F00ow/nDCy3Bp2oAR79sJqzhFnOmNG9yAnWGr57dAAW4vnsm3tvxSvjZG2kJDTrteUNmIrFkBXynk7/s/6M8RfEojNLbA4kU6zgtNum6EG9N3/49KqRoWEIvhCPM+YbUAKE3OWK0kwIDAQABThe same value again. Bounce messages are sent from mail.ronaldhenriquez.com and are signed with this key. |
| TXT | _dmarc | v=DMARC1; p=none; adkim=s; aspf=s; rua=mailto:postmaster@ronaldhenriquez.com; ruf=mailto:postmaster@ronaldhenriquez.com; fo=1; pct=100DMARC |
Set at your VPS provider, not your registrar. Without it most large providers will treat your mail as suspect.
| Server IP | PTR value |
|---|---|
65.20.98.56 |
mail.ronaldhenriquez.com |
Wait 5–30 minutes, then run these from any machine.
dig MX ronaldhenriquez.com +short # expect: 10 mail.ronaldhenriquez.com. dig A mail.ronaldhenriquez.com +short # expect: 65.20.98.56 dig A webmail.ronaldhenriquez.com +short # expect: 65.20.98.56 dig TXT ronaldhenriquez.com +short | grep spf dig TXT una._domainkey.ronaldhenriquez.com +short dig -x 65.20.98.56 +short # expect: mail.ronaldhenriquez.com.
Once the A records resolve, run this on the server:
cd ~/una.email-install && ./renew-ssl.shOne certificate is issued covering webmail.ronaldhenriquez.com and mail.ronaldhenriquez.com. Both names are validated over port 80, and the same certificate is used by Nginx on 443 and by Postfix for STARTTLS on 25. Let's Encrypt allows 5 certificates per domain per week.
./renew-ssl.sh prints your TLSA hash when it finishes. Add it as:
| Type | Host | Value |
|---|---|---|
| TLSA | _25._tcp.mail |
3 1 1 <hash from renew-ssl.sh> |
The hash is the certificate's public key and survives renewals
(--reuse-key). You only replace it after a full reinstall.
Open https://webmail.ronaldhenriquez.com, create your account, then add your first address under Settings.
Then send a message to mail-tester.com — a few sentences of ordinary text, not one word — and check the score. SPF, DKIM, DMARC, PTR and blacklists should all be green. Below 8, the report names the record that is wrong. You get 3 free tests a day.