To follow the below steps, you must have at least one domain in your Plan Manager, and mail.<domain> must be pointing to the correct SMTP Zen server.
To learn how to setup custom hostnames, see Custom Mail Hostnames.
Every domain you add inside the Plan Manager automatically exposes mail services via the mail.<domain> host. The Mail SSL manager secures those hosts in one batch so that IMAP, POP and SMTP clients never warn about untrusted certificates. The modal lives at the top-right of the Domains tab beside the other quick actions.
Only the Ready domains become “eligible” for SSL issuance - the rest are skipped automatically.
If every eligible domain succeeds you will also see a success alert confirming the batch run. Failures retain the raw response internally so support can diagnose them - re-running the action after fixing DNS is safe.
mail.<domain> DNS to us.No other controls are needed - the feature only affects mail.<domain> hosts that already exist in your Plan Manager and never touches unrelated DNS or certificates.