SMTP Zen Docs
Getting Started

Mail SSL Certificates

Secure each mail.<domain> host that exists in the Plan Manager

To follow the below steps, you must have at least one domain in your Plan Manager, and mail.<domain> must be pointing to the correct SMTP Zen server. To learn how to setup custom hostnames, see Custom Mail Hostnames.

Why the Mail SSL manager exists

Every domain you add inside the Plan Manager automatically exposes mail services via the mail.<domain> host. The Mail SSL manager secures those hosts in one batch so that IMAP, POP and SMTP clients never warn about untrusted certificates. The modal lives at the top-right of the Domains tab beside the other quick actions.

What happens when you open it

  1. The widget reads the exact list of domains shown in the Plan Manager.
  2. The modal shows each host alongside a status badge:
    • Ready means the host is on our infrastructure and can receive a certificate.
    • Missing means DNS does not currently point to us, so issuance is blocked until the record is corrected.

Only the Ready domains become “eligible” for SSL issuance - the rest are skipped automatically.

Issuing the certificates

  1. Review the eligible host list; fix any DNS issues outside the app if needed.
  2. Click Issue certificates.
  3. As results stream back you will see one row per domain with either Success or Failed. Successful rows mean the new certificate is already live on the mail cluster.

If every eligible domain succeeds you will also see a success alert confirming the batch run. Failures retain the raw response internally so support can diagnose them - re-running the action after fixing DNS is safe.

When to rerun it

  • After adding a new domain inside the Plan Manager.
  • Any time you repoint mail.<domain> DNS to us.
  • Shortly before an expiring certificate date (the modal can reissue early).

No other controls are needed - the feature only affects mail.<domain> hosts that already exist in your Plan Manager and never touches unrelated DNS or certificates.