Thanks, @Krydos! The mail is working great, including a 10/10 score from mail-tester.com.
Can you share or point me to info to help me get a Let's Encrypt cert for the mail server? Plesk complains that it can't find the authorization token at /.well-known/acme-challenge/ which makes sense because I plan to set up a web server on my vps, but haven't, yet. Is this just a one-time validation that I need to create the text file for or will this be a problem when Plesk/Let's Encrypt attempts to renew the cert(s)?
If it would be easier/optimal to manage the DNS myself, I can do that, but it seems like I'm this close to having things ready to go.