On Sun, Apr 24, 2022 at 11:20:29AM +0800, "ミユナ (alice)" <al...@coakmail.com> 
wrote:

> 
> 
> raf wrote:
> > I'm fairly sure that's correct. MTAs generally don't
> > care if the MX domain doesn't match the certificate on
> > port 25. But MUAs generally do care if the hostname
> > they are configured to connect to doesn't match the
> > certificate on whatever ports they connect
> 
> that's good. so I can have MX on another server/platform who doesn't need my
> real certificates.

Yes, you can have multiple MX hosts with self-signed certificates.
They don't have to have the same certificate as each other or the
same (CA-signed certificate) as the server that MUAs connect to.

> yes for MUA connections I did setup the correct certs. I didn't use the
> mailinabox, just implementing all by hand.

cheers,
raf

Reply via email to