HANTER Corporate Domain & Mail Plan — 2026-08-31

Status: IMPLEMENTED WORKFLOW / EXTERNAL OWNERSHIP VERIFICATION PENDING

Canonical target identity

Display name: HANTER | IMPERIAL Core Role: AI Command Center / Deputy to the Architect Primary free-domain candidate: imperialcore.eu.org Primary public email candidate: hanter@imperialcore.eu.org Fallback free-domain candidate: imperialcore.pp.ua Fallback public email candidate: hanter@imperialcore.pp.ua

Neither candidate is live yet. Never present either address as active before delegation, DNS authentication and end-to-end mail evidence pass.

Why EU.org is primary

EU.org has provided free subdomain registration since 1996 and supports external authoritative nameservers. Its contact-creation form includes a Private option so contact details need not be exposed through public Whois. Validation is manual and can take several days. EU.org is primarily intended for individuals/non-profit use; small commercial sites are accepted but strongly asked to use it only as a last resort. For HANTER, EU.org is therefore used only because the Architect explicitly requires a zero-cost domain path.

Current observation: imperialcore.eu.org is NXDOMAIN / not delegated. This is not the same as an accepted EU.org registration request.

Why PP.UA is fallback only

PP.UA registration and renewal can be free, but the zone requires phone activation and registrant contact information is public with no Whois privacy hiding. Some registrars can add their own identification requirements. Because this creates a privacy cost for the Architect, PP.UA is retained only as a fallback if EU.org is rejected and the Architect explicitly accepts the public-Whois tradeoff.

Primary registration gate — EU.org

Required external steps that cannot be truthfully automated without the owner's real contact/verification:

  1. Create an EU.org contact with truthful registrant information and select Private where allowed.
  2. Validate the contact email. EU.org currently warns that Gmail rejects its validation emails, so use a non-Gmail contact mailbox.
  3. Configure external authoritative nameservers before submitting the requested domain.
  4. Request imperialcore.eu.org.
  5. Wait for manual EU.org validation; it can take several days.

HANTER must never invent address/contact data or bypass validation.

Inbound — Forward Email Free

After primary-domain delegation, planned inbound identity: hanter@imperialcore.eu.org

Planned MX records:

  • MX @ priority 0 -> mx1.forwardemail.net
  • MX @ priority 0 -> mx2.forwardemail.net

Forwarding configuration must use Forward Email's encrypted TXT mechanism so the private destination mailbox is not exposed in public DNS. The encrypted provider-issued TXT value must be generated after the private destination is selected. Never store a plaintext private destination address in this public Val.

Outbound — SMTP2GO Free

Runtime module: smtp2go_transport.ts Target region: EU Target public sender after verification: hanter@imperialcore.eu.org

Required server-side environment variables after external provider/domain verification:

  • SMTP2GO_API_KEY — secret; never log or commit.
  • HANTER_PUBLIC_EMAIL — the live verified public sender.
  • optional HANTER_CORPORATE_DOMAIN — canonical live domain.
  • optional HANTER_DKIM_SELECTOR — only the exact selector issued by the provider.

SMTP2GO sender verification is mandatory. Use the exact SPF/DKIM records issued by SMTP2GO and merge SPF safely with existing policy. Add DMARC after SPF/DKIM are correctly published. Never invent a selector or provider value.

Approval workflow

Architect topic -> 3 HANTER variants -> Architect selects exact variant -> approval ledger fixes recipient + subject + SHA-256(body) -> outbound guard verifies exact bytes -> SMTP transport sends -> provider message id and evidence hash stored.

Rules:

  • standing delegation for external email: DENIED;
  • external send before exact Architect approval: DENIED;
  • changing recipient, subject or body after approval: DENIED;
  • provider HTTP success alone is insufficient; provider result fields must pass;
  • SMTP acceptance != inbox delivery != read != reply.

Server observability

Communications status: https://hanter-comms-status.val.run/ Task journal status: https://hanter-task-journal.val.run/ Domain DNS watchdog: every 15 minutes. Task-journal sync: every 15 minutes.

Current evidence

  • mail_workflow_test.ts: 7/7 PASS.
  • No external email was sent by the workflow test.
  • imperialcore.eu.org: current DNS state NXDOMAIN / not delegated.
  • PP.UA remains fallback due public-Whois privacy risk.

Temporary mailbox

The existing Val Town email-type mailbox remains a temporary inbound evidence endpoint until a custom-domain mailbox passes live verification. It must not be represented as an owned IMPERIAL Core corporate domain.

Truth boundary

FREE_DOMAIN_CANDIDATE != REGISTERED_DOMAIN != DNS_VERIFIED != AUTHENTICATED_OUTBOUND != DELIVERED_MAIL.