Some mail improvement ideas

You can run;
# testssl -t smtp localhost:25
on the shell after installing Debian -- Package Search Results --
and see some things that tend to go wrong. One of the main issues is that when you install hestia on, you’ll probably have LetsEncrypt issues when the has a separate cert. My experience is to install hestia on and add as an alias for that, but that way you will not be able to use the for normal users, which can be quite cumbersome…
A great solution from LetsEncrypt is the option for wildcard domain certs. I’ve been using that for about 6 years now, ever since it was in beta-stage, and it’s been a sigh of relief. Why would you want to create different certs for each and every subdomain, if you’re the owner of the domain anyway? Just use ONE cert for all of * and and you’re done for all server software that needs a cert.

I also noticed that dhparam on my hestiacp server wasn’t all that nice. I recommend generating it using:
# openssl dhparam -dsaparam -out /etc/ssl/dh4096.pem 4096
and then use this dhparam file for nginx, exim, dovecot etc. For the right TLS/security config, I recommend these;

I know, the last two are commercial, but the free advice it gives with their tests is truly priceless.