UNA Email setup

ronaldhenriquez.com · server 65.20.98.56 · generated Wed Sep 16 20:07:28 UTC 2026
This page is served over plain HTTP from your server's IP, because none of it works until the DNS below exists. Everything on it is public information you are about to publish in DNS. Once your certificate is issued it is also at https://webmail.ronaldhenriquez.com/setup.

1 DNS records

Add these at your domain registrar (Cloudflare, Namecheap, GoDaddy…).

TypeHostValue
MX@
mail.ronaldhenriquez.com
Priority 10
Amail
65.20.98.56
Mail server. The MX above points here, so mail cannot be delivered until this resolves.
Awebmail
65.20.98.56
Web interface. Both names are validated when the certificate is issued.
TXT@
v=spf1 a:mail.ronaldhenriquez.com ip4:65.20.98.56 mx ~all
SPF
TXTuna._domainkey
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqEtp0Lswia1j09cMzfGygXVZOw1/2BH2Zr0PlUYpR+Ohl4r9iCOw0qPYwWXLcVE5Q8Ic3RaItqggFxIFOqRD2gWYaMFTSLD7aMYMY50TLEOyISap4502PtfDWR55P5mmjFi+aoY91FsokTP3x0nadx3a3R4ry1XujUMi/clRD0uS+WrnJzjt90I8tr3V8Zo+PPp8IXCvtFp8F00ow/nDCy3Bp2oAR79sJqzhFnOmNG9yAnWGr57dAAW4vnsm3tvxSvjZG2kJDTrteUNmIrFkBXynk7/s/6M8RfEojNLbA4kU6zgtNum6EG9N3/49KqRoWEIvhCPM+YbUAKE3OWK0kwIDAQAB
DKIM
TXTuna._domainkey.mail
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqEtp0Lswia1j09cMzfGygXVZOw1/2BH2Zr0PlUYpR+Ohl4r9iCOw0qPYwWXLcVE5Q8Ic3RaItqggFxIFOqRD2gWYaMFTSLD7aMYMY50TLEOyISap4502PtfDWR55P5mmjFi+aoY91FsokTP3x0nadx3a3R4ry1XujUMi/clRD0uS+WrnJzjt90I8tr3V8Zo+PPp8IXCvtFp8F00ow/nDCy3Bp2oAR79sJqzhFnOmNG9yAnWGr57dAAW4vnsm3tvxSvjZG2kJDTrteUNmIrFkBXynk7/s/6M8RfEojNLbA4kU6zgtNum6EG9N3/49KqRoWEIvhCPM+YbUAKE3OWK0kwIDAQAB
The same value again. Bounce messages are sent from mail.ronaldhenriquez.com and are signed with this key.
TXT_dmarc
v=DMARC1; p=none; adkim=s; aspf=s; rua=mailto:postmaster@ronaldhenriquez.com; ruf=mailto:postmaster@ronaldhenriquez.com; fo=1; pct=100
DMARC

2 Reverse DNS (PTR)

Set at your VPS provider, not your registrar. Without it most large providers will treat your mail as suspect.

Server IPPTR value
65.20.98.56
mail.ronaldhenriquez.com

3 Verify propagation

Wait 5–30 minutes, then run these from any machine.

dig MX ronaldhenriquez.com +short           # expect: 10 mail.ronaldhenriquez.com.
dig A mail.ronaldhenriquez.com +short    # expect: 65.20.98.56
dig A webmail.ronaldhenriquez.com +short     # expect: 65.20.98.56
dig TXT ronaldhenriquez.com +short | grep spf
dig TXT una._domainkey.ronaldhenriquez.com +short
dig -x 65.20.98.56 +short         # expect: mail.ronaldhenriquez.com.
copy all checks

4 SSL certificate

Once the A records resolve, run this on the server:

cd ~/una.email-install && ./renew-ssl.sh

One certificate is issued covering webmail.ronaldhenriquez.com and mail.ronaldhenriquez.com. Both names are validated over port 80, and the same certificate is used by Nginx on 443 and by Postfix for STARTTLS on 25. Let's Encrypt allows 5 certificates per domain per week.

5 DANE / TLSA (optional)

./renew-ssl.sh prints your TLSA hash when it finishes. Add it as:

TypeHostValue
TLSA
_25._tcp.mail
3 1 1 <hash from renew-ssl.sh>

The hash is the certificate's public key and survives renewals (--reuse-key). You only replace it after a full reinstall.

6 Sign in and test

Open https://webmail.ronaldhenriquez.com, create your account, then add your first address under Settings.

Then send a message to mail-tester.com — a few sentences of ordinary text, not one word — and check the score. SPF, DKIM, DMARC, PTR and blacklists should all be green. Below 8, the report names the record that is wrong. You get 3 free tests a day.