The same domain for website and e-mail

Hi,
Can I use the same domain for the website and email server?
At the moment my website is phonesrescue.co.uk and my email domain is mail.phonesrescue.co.uk. It makes problems with TLS certificates:

Cert VALIDATED: ok
Cert Hostname DOES NOT VERIFY (mail.phonesrescue.co.uk != phonesrescue.co.uk | DNS:phonesrescue.co.uk | DNS:www.phonesrescue.co.uk)
So email is encrypted but the host is not verified

I have my own certificates for the website and mail server, but I am not sure how to install it.

Welcome @phonesrescue Happy you are here

Yes but its best to have separate certificates for both cases.

To issue custom mailserver ssl certificate go to https://SERVER_URL/websites/phonesrescue.co.uk/mail.phonesrescue.co.uk and add ssl

To secure multiple subdomains with same ssl certificate? phonesrescue.co.uk and mail.phonesrescue.co.uk

What you need is a Wildcard ssl certificate.

Check this out to add wildcard ssl certificate for your website.

Hi Joseph,
Thank you for your response.
A wildcard certificate is much more expensive than I expected :roll_eyes: So I bought two certificates separately, for phonesrescue.co.uk and mail.phonesrescue.co.uk
I tried your solution:

  1. Added SSL certificate from mail.phonesrescue. co.uk for mail.phonesrescue.co.uk on https:/MYCYBERPANEL/websites/phonesrescue.co.uk/mail.phonesrescue.co.uk
  2. Restarted Postfix and Dovecot

Issues:

  1. Error on the checktls.com:
    Certificate #1 of 3 (sent by MX):
    Cert VALIDATED: ok
    Cert Hostname DOES NOT VERIFY (mail.phonesrescue.co.uk != phonesrescue.co.uk | DNS:phonesrescue.co.uk | DNS:www.phonesrescue.co.uk)
    So email is encrypted but the host is not verified
  2. When I try to setup SMTP on Mail App on the MacBook:
The identity of “mail.phonesrescue.co.uk” cannot be verified.
The certificate for this server is invalid.
  1. All my sent emails are going to the spam folder.

I do not have any idea how to set up this properly. Can it be a problem with DNS? I use Cloudflare if it is any difference.

Another question: Can I insert the Chain certificate instead of Normal domain certificate in CyberPanel website settings?

Cert Hostname DOES NOT VERIFY (mail.phonesrescue.co.uk != phonesrescue.co.uk | DNS:phonesrescue.co.uk | DNS:www.phonesrescue.co.uk)

The error is clear that you have issued same ssl certificate to phonerescue.co.uk and mail server domain.

Post a screenshot of your CF dns table

My DNS data:

The following records should not be proxied :orange:

mail.phonesrescue.co.uk
phonesrescue.co.uk

it seems that you SSL for mail server is issue but not mapped

run these commands
postmap -F hash:/etc/postfix/vmail_ssl.map
systemctl restart postfix

1 Like

It works!
Thank you so much!