Cannot create SSL Certificate for Virtualmin dashboard

I use this.

Also when ECH (encrypted client hello) becomes a thing, the hostname might need a cert.

That is not what I’m saying doesn’t matter. You’ve just confirmed what I said elsewhere. The PTR does not have to match the system hostname, even if Postfix has that option enabled. If that option is enabled, the sender must have a PTR record and it must resolve back to the IP, which is not the same as “must match the system hostname” (in /etc/hosts, /etc/hostname, whatever).